nerdexam
Microsoft

MS-900 · Question #224

A company deploys Microsoft 365. The company needs to deploy a solution that meets the following requirements: - allows access to Microsoft 365 only from corporate networks - allows access to…

The correct answer is B. Conditional Access. This question tests knowledge of which Microsoft 365 security feature can enforce multiple access conditions simultaneously, including network location, device compliance, and authentication strength.

Submitted by javi_es· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company deploys Microsoft 365. The company needs to deploy a solution that meets the following requirements: - allows access to Microsoft 365 only from corporate networks - allows access to Microsoft 365 only from corporate-owned devices - requires additional verification during authentication You need to identify a solution that meets the requirements. What should you select?

Options

  • AMulti-factor authentication
  • BConditional Access
  • CAzure Active Directory hybrid identity
  • DSelf-service password reset

How the community answered

(37 responses)
  • A
    14% (5)
  • B
    76% (28)
  • C
    8% (3)
  • D
    3% (1)

Why each option

This question tests knowledge of which Microsoft 365 security feature can enforce multiple access conditions simultaneously, including network location, device compliance, and authentication strength.

AMulti-factor authentication

Multi-factor authentication alone only addresses the additional verification requirement and cannot restrict access based on network location or device ownership.

BConditional AccessCorrect

Conditional Access is a policy-based engine in Azure AD that evaluates signals such as network location (named locations/corporate networks), device compliance state (corporate-owned/Intune-enrolled devices), and can enforce MFA as a grant control - all within a single unified policy. It is the only solution that natively combines all three requirements: location-based restrictions, device-based restrictions, and step-up authentication in one framework.

CAzure Active Directory hybrid identity

Azure Active Directory hybrid identity synchronizes on-premises identities to Azure AD but does not itself enforce network, device, or MFA access controls.

DSelf-service password reset

Self-service password reset allows users to reset their own passwords without IT intervention and does not address access restrictions or step-up authentication policies.

Concept tested: Azure AD Conditional Access policy enforcement for M365

Source: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview

Topics

#Conditional Access#Azure AD#network-based access#device compliance

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice