nerdexam
Microsoft

SC-300 · Question #329

You configure a new Microsoft 365 tenant to use a default domain name of contoso.com. You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies…

The correct answer is A. Disable Security defaults. Explanation Security Defaults must be disabled first because Microsoft enables Security Defaults automatically on all new Microsoft 365 tenants, and Security Defaults includes its own pre-configured baseline security policies (including MFA enforcement) that conflict with and…

Submitted by haruto_sh· Mar 6, 2026Implement authentication and access management

Question

You configure a new Microsoft 365 tenant to use a default domain name of contoso.com. You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies. What should you do first?

Options

  • ADisable Security defaults.
  • BConfigure password protection for the Azure AD tenant.
  • CConfigure a multi-factor authentication (MFA) registration policy.
  • DDisable the User consent settings.

How the community answered

(46 responses)
  • A
    78% (36)
  • B
    4% (2)
  • C
    2% (1)
  • D
    15% (7)

Explanation

Explanation

Security Defaults must be disabled first because Microsoft enables Security Defaults automatically on all new Microsoft 365 tenants, and Security Defaults includes its own pre-configured baseline security policies (including MFA enforcement) that conflict with and cannot coexist with custom Conditional Access policies - you cannot create or enforce Conditional Access policies while Security Defaults are active.

  • Option B is wrong because password protection (blocking weak/banned passwords) is an independent feature unrelated to enabling Conditional Access policies.
  • Option C is wrong because while configuring an MFA registration policy is useful for Conditional Access, it is not the first prerequisite - you must remove the blocking conflict (Security Defaults) before Conditional Access can function.
  • Option D is wrong because User consent settings govern how users approve app permissions in Azure AD, which has no bearing on enabling Conditional Access policies.

Memory Tip: Think of Security Defaults as the "training wheels" Microsoft provides out of the box - you must remove the training wheels before you can steer with your own custom Conditional Access "controls." New tenant = Security Defaults ON = Conditional Access OFF.

Topics

#Conditional Access#Security defaults#Azure AD#Access Control

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice