nerdexam
Microsoft

MD-102 · Question #292

You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1. App1 must only accept modern authentication requests. You plan to create a Conditional Access policy

The correct answer is E. Client apps. The 'Client apps' condition in Conditional Access lets you filter authentication requests based on the protocol used. Legacy authentication protocols (IMAP, POP3, SMTP, Exchange ActiveSync, older Office clients) do not support modern authentication and cannot satisfy MFA or other

Submitted by paula_co· Apr 18, 2026Manage applications

Question

You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1. App1 must only accept modern authentication requests. You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:

  • Assignments
  • Users or workload identities: User1
  • Cloud apps or actions: App1
  • Access controls
  • Grant: Block access

You need to block only legacy authentication requests to App1. Which condition should you add to CAPolicy1?

Options

  • AFilter for devices
  • BDevice platforms
  • CUser risk
  • DSign-in risk
  • EClient apps

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    6% (2)
  • E
    81% (26)

Explanation

The 'Client apps' condition in Conditional Access lets you filter authentication requests based on the protocol used. Legacy authentication protocols (IMAP, POP3, SMTP, Exchange ActiveSync, older Office clients) do not support modern authentication and cannot satisfy MFA or other controls. By adding the 'Client apps' condition and selecting legacy authentication clients, CAPolicy1 will block only those requests while allowing modern authentication through. Filter for devices (A) targets device attributes. Device platforms (B) targets OS type. User risk (C) and Sign-in risk (D) rely on Identity Protection signals - none of these distinguish legacy vs. modern authentication.

Topics

#Conditional Access#Legacy authentication#Client apps condition#Azure AD

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice