nerdexam
Microsoft

SC-300 · Question #25

You have an Azure Active Directory (Azure AD) tenant named contoso.com. All users who run applications registered in Azure AD are subject to conditional access policies. You need to prevent the…

The correct answer is C. a client apps condition. Directly blocking legacy authentication The easiest way to block legacy authentication across your entire organization is by configuring a Conditional Access policy that applies specifically to legacy authentication clients and blocks Conditional Access policies apply to all…

Submitted by fatema_kw· Mar 6, 2026Implement authentication and access management solution

Question

You have an Azure Active Directory (Azure AD) tenant named contoso.com. All users who run applications registered in Azure AD are subject to conditional access policies. You need to prevent the users from using legacy authentication. What should you include in the conditional access policies to filter out legacy authentication attempts?

Options

  • Aa cloud apps or actions condition
  • Ba user risk condition
  • Ca client apps condition
  • Da sign-in risk condition

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    74% (17)
  • D
    17% (4)

Explanation

Directly blocking legacy authentication The easiest way to block legacy authentication across your entire organization is by configuring a Conditional Access policy that applies specifically to legacy authentication clients and blocks Conditional Access policies apply to all client apps by default Client apps. By default, all newly created Conditional Access policies will apply to all client app types even if the client apps condition is not configured. https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/block-legacy-

Topics

#Conditional Access#Legacy authentication#Client apps condition#Authentication security

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice