SC-300 · Question #346
You have a Microsoft Entra tenant that contains the users shown in the following table. Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for…
The correct answer is D. Admin1, Admin2, Admin3, and Admin4. Explanation Option D is correct because the "Require multifactor authentication for Azure management" Conditional Access template applies to all users accessing Azure management endpoints (such as the Azure portal, Azure CLI, and Azure PowerShell) - including the admin who…
Question
You have a Microsoft Entra tenant that contains the users shown in the following table. Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for Azure management template. Which users will be required to use multi-factor authentication (MFA) the next time they sign in?
Exhibit
Options
- AAdmin2 and Admin3 only
- BAdmin1 and Admin4 only
- CAdmin1, Admin2, and Admin3 only
- DAdmin1, Admin2, Admin3, and Admin4
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C4% (1)
- D84% (21)
Explanation
Explanation
Option D is correct because the "Require multifactor authentication for Azure management" Conditional Access template applies to all users accessing Azure management endpoints (such as the Azure portal, Azure CLI, and Azure PowerShell) - including the admin who created the policy (Admin4). Conditional Access policies evaluate every user who meets the defined conditions at sign-in time, regardless of role or who created the policy, so Admin1, Admin2, Admin3, and Admin4 are all subject to it.
Why the distractors are wrong: Options A and B incorrectly exclude certain admins, implying some users are exempt - but no built-in exemption exists for policy creators or specific admin roles unless an exclusion is explicitly configured. Option C incorrectly excludes Admin4, perhaps assuming the policy creator is immune, but they are not; Admin4 is subject to the same policy as everyone else.
Memory tip: Think of Conditional Access policies as traffic laws - the officer who writes the law still has to follow it. Unless you explicitly exclude a user or group from the policy scope, everyone in the tenant is subject to it, including the creator. Always ask: "Was anyone explicitly excluded?" If not, assume all users are covered.
Topics
Community Discussion
No community discussion yet for this question.
