MD-102 · Question #292
You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1. App1 must only accept modern authentication requests. You plan to create a Conditional Access policy
The correct answer is E. Client apps. The 'Client apps' condition in Conditional Access lets you filter authentication requests based on the protocol used. Legacy authentication protocols (IMAP, POP3, SMTP, Exchange ActiveSync, older Office clients) do not support modern authentication and cannot satisfy MFA or other
Question
You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1. App1 must only accept modern authentication requests. You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
- Assignments
- Users or workload identities: User1
- Cloud apps or actions: App1
- Access controls
- Grant: Block access
You need to block only legacy authentication requests to App1. Which condition should you add to CAPolicy1?
Options
- AFilter for devices
- BDevice platforms
- CUser risk
- DSign-in risk
- EClient apps
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C6% (2)
- E81% (26)
Explanation
The 'Client apps' condition in Conditional Access lets you filter authentication requests based on the protocol used. Legacy authentication protocols (IMAP, POP3, SMTP, Exchange ActiveSync, older Office clients) do not support modern authentication and cannot satisfy MFA or other controls. By adding the 'Client apps' condition and selecting legacy authentication clients, CAPolicy1 will block only those requests while allowing modern authentication through. Filter for devices (A) targets device attributes. Device platforms (B) targets OS type. User risk (C) and Sign-in risk (D) rely on Identity Protection signals - none of these distinguish legacy vs. modern authentication.
Topics
Community Discussion
No community discussion yet for this question.