nerdexam
Microsoft

SC-300 · Question #255

Drag and Drop Question You have an Azure AD tenant that contains a user named Admin1. Admin1 uses the Require password change for high-risk users policy template to create a new Conditional Access…

The correct answer is Include: All users; Exclude: Admin1. When using the 'Require password change for high-risk users' Conditional Access policy template in Azure AD, the policy automatically includes 'All users' in its assignment scope to broadly protect the tenant. By default, the account creating the policy (Admin1 in this case) is…

Submitted by haru.x· Mar 6, 2026Implement and manage identity and access in Azure AD - specifically configuring Conditional Access policies and understanding default policy template behaviors to protect against identity risks while maintaining administrative access.

Question

Drag and Drop Question You have an Azure AD tenant that contains a user named Admin1. Admin1 uses the Require password change for high-risk users policy template to create a new Conditional Access policy. Who is included and excluded by default in the policy assignment? To answer, drag the appropriate options to the correct target. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point Answer:

Exhibit

SC-300 question #255 exhibit

Answer Area

Drag items

Admin1All guest and external usersAll usersDirectory rolesNone

Correct arrangement

  • Include: All users
  • Exclude: Admin1

Explanation

When using the 'Require password change for high-risk users' Conditional Access policy template in Azure AD, the policy automatically includes 'All users' in its assignment scope to broadly protect the tenant. By default, the account creating the policy (Admin1 in this case) is automatically excluded to prevent the administrator from being locked out of the tenant - this is a built-in safeguard Microsoft includes in policy templates to ensure at least one admin retains access.

Topics

#Conditional Access#Azure AD Identity Protection#Risk-based policies#Policy templates

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice