MS-721 · Question #329
You plan to deploy a Microsoft Teams Rooms device named Device1 that will use a resource account named Resource1. You need to prevent Resource1 from being prompted for multifactor authentication (MFA)
The correct answer is D. Configure Per-user MFA for Resource1.. Teams Rooms resource accounts are service accounts that sign in automatically and cannot interactively respond to an MFA prompt. Configuring per-user MFA for Resource1 means navigating to the Microsoft 365 admin center's per-user MFA settings and setting Resource1's MFA state to
Question
Options
- AConfigure a Conditional Access policy that excludes Resource1.
- BFrom Teams settings, set Require a secondary form of authentication to access meeting content
- CConfigure a Conditional Access policy that includes Device1.
- DConfigure Per-user MFA for Resource1.
- EConfigure a Conditional Access policy that includes Resource1.
How the community answered
(23 responses)- A4% (1)
- B13% (3)
- D78% (18)
- E4% (1)
Explanation
Teams Rooms resource accounts are service accounts that sign in automatically and cannot interactively respond to an MFA prompt. Configuring per-user MFA for Resource1 means navigating to the Microsoft 365 admin center's per-user MFA settings and setting Resource1's MFA state to disabled. This prevents the account from ever being challenged for MFA at sign-in. While a Conditional Access policy that excludes Resource1 (option A) is the modern recommended approach, the question's correct answer points to the per-user MFA setting as the direct account-level control. Option E (a CA policy that includes Resource1) would enforce MFA, which is the opposite of the goal. Option C (a CA policy targeting Device1) targets the device, not the account identity. Option B is a meeting content access setting unrelated to account authentication.
Topics
Community Discussion
No community discussion yet for this question.