nerdexam
Microsoft

AZ-500 · Question #181

Hotspot Question Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the users shown in the following table…

The correct answer is User1 will be prompted to configure MFA registration during the user's next Azure AD authentication. = Yes; User2 must configure MFA during the user's next Azure AD authentication. = No; User3 will be prompted to configure MFA registration during the user's next Azure AD authentication. = Yes. The multi-factor authentication (MFA) registration policy is configured to Include Group1 and Exclude Group2. The policy is enforced and requires Azure MFA registration. When a user is part of both an include and an exclude group for a policy, the exclude rule takes precedence…

Submitted by anjalisingh· Mar 6, 2026Secure identity and access

Question

Hotspot Question Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the users shown in the following table. The tenant contains the groups shown in the following table. You configure a multi-factor authentication (MFA) registration policy that has the following settings: Assignments: - Include: Group1 - Exclude Group2 Controls: Require Azure MFA registration Enforce Policy: On For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #181 exhibit 1
AZ-500 question #181 exhibit 2

Answer Area

  • User1 will be prompted to configure MFA registration during the user's next Azure AD authentication.Yes
  • User2 must configure MFA during the user's next Azure AD authentication.No
  • User3 will be prompted to configure MFA registration during the user's next Azure AD authentication.Yes

Explanation

The multi-factor authentication (MFA) registration policy is configured to Include Group1 and Exclude Group2. The policy is enforced and requires Azure MFA registration. When a user is part of both an include and an exclude group for a policy, the exclude rule takes precedence.

  • User1: Is a member of Group1 (included) but not Group2 (excluded). Therefore, the MFA registration policy applies to User1, and they will be prompted to configure MFA registration.
  • User2: Is a member of both Group1 (included) and Group2 (excluded). Due to the exclusion taking precedence, the MFA registration policy will not apply to User2.
  • User3: Is a member of Group1 (included) but not Group2 (excluded). Therefore, the MFA registration policy applies to User3, and they will be prompted to configure MFA registration.

Topics

#Azure AD MFA#Conditional Access#Identity protection

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice