nerdexam
Microsoft

MS-102 · Question #97

Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication…

The correct answer is D. Azure AD conditional access. Azure AD Conditional Access should be included in the recommendation to enforce multi-factor authentication specifically for users in the branch office.

Submitted by rania.sa· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication. You need to recommend a Microsoft 365 solution to ensure that multi-factor authentication is enforced only for users in the branch office. What should you include in the recommendation?

Options

  • AAzure AD password protection
  • Ba Microsoft Intune device configuration profile
  • Ca Microsoft Intune device compliance policy
  • DAzure AD conditional access

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    12% (6)
  • D
    78% (39)

Why each option

Azure AD Conditional Access should be included in the recommendation to enforce multi-factor authentication specifically for users in the branch office.

AAzure AD password protection

Azure AD password protection helps prevent the use of weak passwords but does not provide mechanisms for conditional enforcement of multi-factor authentication based on user location.

Ba Microsoft Intune device configuration profile

A Microsoft Intune device configuration profile manages device settings and features, but it is not designed for enforcing authentication policies like conditional MFA based on user location.

Ca Microsoft Intune device compliance policy

A Microsoft Intune device compliance policy assesses device health and compliance but does not directly control multi-factor authentication enforcement based on user location.

DAzure AD conditional accessCorrect

Azure AD Conditional Access policies enable administrators to enforce specific requirements, such as multi-factor authentication, based on various conditions, including user location. By defining a trusted IP range for the main offices and enforcing MFA for sign-ins outside that range or specifically for users signing in from the branch office's IP range, MFA can be applied selectively as required.

Concept tested: Azure AD Conditional Access for location-based MFA

Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview

Topics

#Conditional Access#Multi-factor authentication#Microsoft Entra ID#Access control

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice