nerdexam
Microsoft

MS-900 · Question #435

A company subscribes to Microsoft 365 and uses Azure Active Directory. Users are required to use a corporate computer and the Microsoft Authenticator app. The company wants to protect employee…

The correct answer is B. user risk D. named location. This question tests knowledge of Conditional Access signals used to protect devices when employees travel internationally, requiring identification of location-based and risk-based signals.

Submitted by fatema_kw· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company subscribes to Microsoft 365 and uses Azure Active Directory. Users are required to use a corporate computer and the Microsoft Authenticator app. The company wants to protect employee device when the employees are out of the country/region. You need to identify the conditional access signals the company should use. Which two signals should you identify? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • Acloud apps
  • Buser risk
  • Cgroup membership
  • Dnamed location

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    78% (36)
  • C
    15% (7)

Why each option

This question tests knowledge of Conditional Access signals used to protect devices when employees travel internationally, requiring identification of location-based and risk-based signals.

Acloud apps

Cloud apps are a Conditional Access condition used to target specific applications for policy enforcement, not a signal that detects geographic location or risk associated with employees traveling internationally.

Buser riskCorrect

User risk is an Identity Protection signal integrated with Conditional Access that detects anomalous sign-in behavior, such as impossible travel or unfamiliar locations, which directly addresses protecting employees working outside their home country by flagging potentially compromised accounts.

Cgroup membership

Group membership is used to scope which users a Conditional Access policy applies to, not a signal that detects or responds to the geographic or risk context of a sign-in event.

Dnamed locationCorrect

Named locations allow administrators to define trusted or untrusted geographic regions (countries/regions) as Conditional Access signals, enabling policies that trigger additional controls or block access when users sign in from outside approved countries, directly addressing the international travel protection requirement.

Concept tested: Conditional Access signals for location and user risk

Source: https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-conditions

Topics

#Conditional Access#user risk#named location#Azure AD signals

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice