MS-102 · Question #97
Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication…
The correct answer is D. Azure AD conditional access. Azure AD Conditional Access should be included in the recommendation to enforce multi-factor authentication specifically for users in the branch office.
Question
Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication. You need to recommend a Microsoft 365 solution to ensure that multi-factor authentication is enforced only for users in the branch office. What should you include in the recommendation?
Options
- AAzure AD password protection
- Ba Microsoft Intune device configuration profile
- Ca Microsoft Intune device compliance policy
- DAzure AD conditional access
How the community answered
(50 responses)- A6% (3)
- B4% (2)
- C12% (6)
- D78% (39)
Why each option
Azure AD Conditional Access should be included in the recommendation to enforce multi-factor authentication specifically for users in the branch office.
Azure AD password protection helps prevent the use of weak passwords but does not provide mechanisms for conditional enforcement of multi-factor authentication based on user location.
A Microsoft Intune device configuration profile manages device settings and features, but it is not designed for enforcing authentication policies like conditional MFA based on user location.
A Microsoft Intune device compliance policy assesses device health and compliance but does not directly control multi-factor authentication enforcement based on user location.
Azure AD Conditional Access policies enable administrators to enforce specific requirements, such as multi-factor authentication, based on various conditions, including user location. By defining a trusted IP range for the main offices and enforcing MFA for sign-ins outside that range or specifically for users signing in from the branch office's IP range, MFA can be applied selectively as required.
Concept tested: Azure AD Conditional Access for location-based MFA
Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview
Topics
Community Discussion
No community discussion yet for this question.