nerdexam
Microsoft

MS-102 · Question #511

You configure a conditional access policy. The locations settings are configured as shown in the Locations exhibit. (Click the Locations tab.) The users and groups settings are configured as shown in

Sign in or unlock MS-102 to reveal the answer and full explanation for question #511. The question stem and answer options stay visible for context.

Submitted by sofia.br· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You configure a conditional access policy. The locations settings are configured as shown in the Locations exhibit. (Click the Locations tab.) The users and groups settings are configured as shown in the Users and Groups exhibit. (Click Users and Groups tab.) Members of the Security reader group report that they cannot sign in to Microsoft Active Directory (Azure AD) on their device while they are in the office. You need to ensure that the members of the Security reader group can sign in in to Azure AD on their device while they are in the office. The solution must use the principle of least privilege. What should you do?

Exhibits

MS-102 question #511 exhibit 1
MS-102 question #511 exhibit 2

Options

  • AFrom the conditional access policy, configure the device state.
  • BFrom the Azure Active Directory admin center, create a custom control.
  • CFrom the Intune admin center, create a device compliance policy.
  • DFrom the Azure Active Directory admin center, create a named location.

Unlock MS-102 to see the answer

You've previewed enough free MS-102 questions. Unlock MS-102 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Conditional Access#Named Locations#Azure Entra ID#Access Control
Full MS-102 Practice