AZ-500 · Question #95
Hotspot Question You have a network security group (NSG) bound to an Azure subnet. You run Get-AzureRmNetworkSecurityRuleConfig and receive the output shown in the following exhibit. Use the…
The correct answer is Users from the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal. = Yes; Users from the Contoso named location must use multi-factor authentication (MFA) to access the web services hosted in the Azure subscription. = No; Users external to the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal. = No. Based on the conditional access policy output, the policy targets the 'Contoso named location' and requires MFA when accessing 'Microsoft Azure Management' (the Azure portal). Users FROM the Contoso named location are included in the policy scope and must use MFA to access the…
Question
Exhibits
Answer Area
- Users from the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal.Yes
- Users from the Contoso named location must use multi-factor authentication (MFA) to access the web services hosted in the Azure subscription.No
- Users external to the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal.No
Explanation
Based on the conditional access policy output, the policy targets the 'Contoso named location' and requires MFA when accessing 'Microsoft Azure Management' (the Azure portal). Users FROM the Contoso named location are included in the policy scope and must use MFA to access the Azure portal (Yes). The policy does NOT apply to web services hosted in the Azure subscription - it only targets Azure Management endpoints, not custom-hosted web services (No). Users EXTERNAL to the Contoso named location are excluded from the policy scope, meaning the policy does not enforce MFA for them accessing the portal (No).
Topics
Community Discussion
No community discussion yet for this question.



