nerdexam
Microsoft

SC-300 · Question #346

You have a Microsoft Entra tenant that contains the users shown in the following table. Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for…

The correct answer is D. Admin1, Admin2, Admin3, and Admin4. Explanation Option D is correct because the "Require multifactor authentication for Azure management" Conditional Access template applies to all users accessing Azure management endpoints (such as the Azure portal, Azure CLI, and Azure PowerShell) - including the admin who…

Submitted by amina.ke· Mar 6, 2026Implement authentication and access management solution

Question

You have a Microsoft Entra tenant that contains the users shown in the following table. Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for Azure management template. Which users will be required to use multi-factor authentication (MFA) the next time they sign in?

Exhibit

SC-300 question #346 exhibit

Options

  • AAdmin2 and Admin3 only
  • BAdmin1 and Admin4 only
  • CAdmin1, Admin2, and Admin3 only
  • DAdmin1, Admin2, Admin3, and Admin4

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    84% (21)

Explanation

Explanation

Option D is correct because the "Require multifactor authentication for Azure management" Conditional Access template applies to all users accessing Azure management endpoints (such as the Azure portal, Azure CLI, and Azure PowerShell) - including the admin who created the policy (Admin4). Conditional Access policies evaluate every user who meets the defined conditions at sign-in time, regardless of role or who created the policy, so Admin1, Admin2, Admin3, and Admin4 are all subject to it.

Why the distractors are wrong: Options A and B incorrectly exclude certain admins, implying some users are exempt - but no built-in exemption exists for policy creators or specific admin roles unless an exclusion is explicitly configured. Option C incorrectly excludes Admin4, perhaps assuming the policy creator is immune, but they are not; Admin4 is subject to the same policy as everyone else.

Memory tip: Think of Conditional Access policies as traffic laws - the officer who writes the law still has to follow it. Unless you explicitly exclude a user or group from the policy scope, everyone in the tenant is subject to it, including the creator. Always ask: "Was anyone explicitly excluded?" If not, assume all users are covered.

Topics

#Conditional Access#Multi-factor Authentication#Azure Management

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice