nerdexam
Microsoft

SC-300 · Question #105

You create the Azure Active Directory (Azure AD) users shown in the following table. On February 1, 2021, you configure the multi-factor authentication (MFA) settings as shown in the following…

The correct answer is B. Name Multi-factor auth status User1 Disabled User2 Enforced User3 Enforced. Answer B is correct because User1 was created after the MFA policy was configured (February 1, 2021) with a 'remember MFA on trusted devices' grace period, but since User1 has not yet authenticated, their status remains Disabled. User2 has authenticated on a trusted device but…

Submitted by carter_n· Mar 6, 2026Manage Azure Active Directory (Azure AD) identities and authentication - specifically configuring and monitoring Multi-Factor Authentication (MFA) policies and understanding MFA status states (Disabled, Enabled, Enforced)

Question

You create the Azure Active Directory (Azure AD) users shown in the following table. On February 1, 2021, you configure the multi-factor authentication (MFA) settings as shown in the following exhibit. The users authentication to Azure AD on their devices as shown in the following table. On February 26, 2021, what will the multi-factor auth status be for each user? A. B. C. D.

Exhibit

SC-300 question #105 exhibit

Options

  • AName Multi-factor auth status User1 Disabled User2 Enabled User3 Enforced
  • BName Multi-factor auth status User1 Disabled User2 Enforced User3 Enforced
  • CName Multi-factor auth status User1 Enforced User2 Enforced User3 Enforced
  • DName Multi-factor auth status User1 Disabled User2 Enforced User3 Enforced

How the community answered

(59 responses)
  • A
    10% (6)
  • B
    47% (28)
  • C
    15% (9)
  • D
    27% (16)

Explanation

Answer B is correct because User1 was created after the MFA policy was configured (February 1, 2021) with a 'remember MFA on trusted devices' grace period, but since User1 has not yet authenticated, their status remains Disabled. User2 has authenticated on a trusted device but the 'remember MFA' period (typically 14 days) has expired by February 26, moving their status to Enforced. User3, who authenticated without a trusted device or whose remember period has lapsed, is also Enforced - reflecting that once the remember period expires, MFA enforcement kicks in automatically.

Topics

#Azure AD MFA#Multi-Factor Authentication Status#Remember MFA on Trusted Devices#Identity Management

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice