MS-900 · Question #224
A company deploys Microsoft 365. The company needs to deploy a solution that meets the following requirements: - allows access to Microsoft 365 only from corporate networks - allows access to…
The correct answer is B. Conditional Access. This question tests knowledge of which Microsoft 365 security feature can enforce multiple access conditions simultaneously, including network location, device compliance, and authentication strength.
Question
Options
- AMulti-factor authentication
- BConditional Access
- CAzure Active Directory hybrid identity
- DSelf-service password reset
How the community answered
(37 responses)- A14% (5)
- B76% (28)
- C8% (3)
- D3% (1)
Why each option
This question tests knowledge of which Microsoft 365 security feature can enforce multiple access conditions simultaneously, including network location, device compliance, and authentication strength.
Multi-factor authentication alone only addresses the additional verification requirement and cannot restrict access based on network location or device ownership.
Conditional Access is a policy-based engine in Azure AD that evaluates signals such as network location (named locations/corporate networks), device compliance state (corporate-owned/Intune-enrolled devices), and can enforce MFA as a grant control - all within a single unified policy. It is the only solution that natively combines all three requirements: location-based restrictions, device-based restrictions, and step-up authentication in one framework.
Azure Active Directory hybrid identity synchronizes on-premises identities to Azure AD but does not itself enforce network, device, or MFA access controls.
Self-service password reset allows users to reset their own passwords without IT intervention and does not address access restrictions or step-up authentication policies.
Concept tested: Azure AD Conditional Access policy enforcement for M365
Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview
Topics
Community Discussion
No community discussion yet for this question.