AZ-104 · Question #395
Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that is configured for hybrid coexistence with the on-premises Active Directory domain. The tenant contains the users…
The correct answer is D. User1, User2, User3, and User4. All listed user types, including Azure AD only, synced from on-premises AD, guest users, and cloud-only users, can be enabled for Azure Multi-Factor Authentication.
Question
Exhibits
Options
- AUser1 only
- BUser1, User2, and User3 only
- CUser1 and User2 only
- DUser1, User2, User3, and User4
- EUser2 only
How the community answered
(37 responses)- B5% (2)
- C8% (3)
- D84% (31)
- E3% (1)
Why each option
All listed user types, including Azure AD only, synced from on-premises AD, guest users, and cloud-only users, can be enabled for Azure Multi-Factor Authentication.
This option excludes synced users, guest users, and cloud-only users (like User4), all of whom can use Azure MFA.
This option excludes User4, who is a cloud-only user and can be enabled for Azure MFA.
This option excludes User3 (guest user) and User4 (cloud-only user), both of whom can be enabled for Azure MFA.
Azure Multi-Factor Authentication can be enabled for all user types in an Azure AD tenant, encompassing cloud-only users (User1, User4), users synced from on-premises AD (User2), and guest users (User3).
This option excludes User1, User3, and User4, all of whom can be enabled for Azure MFA.
Concept tested: Azure MFA applicability to different user types
Source: https://learn.microsoft.com/azure/active-directory/authentication/concept-mfa-howitworks#mfa-user-states
Community Discussion
No community discussion yet for this question.

