SC-300 · Question #351
Hotspot Question You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2. The subscription contains the users shown in the following table. You create the following…
The correct answer is User1 will be prompted for the Stay signed in option when they sign in to the Microsoft 365 portal. = Yes; User2 must reauthenticate to Microsoft 365 Apps every two hours. = No; User3 must reauthenticate to Microsoft 365 Apps every two hours. = No. This question assesses understanding of Conditional Access policy application and session controls. User and Group Membership: User1: Member of Group1, Role: None. User2: Member of Group2, Role: Global Administrator. User3: Member of Group1, Group2, Role: None. Conditional…
Question
Hotspot Question You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2. The subscription contains the users shown in the following table. You create the following Conditional Access policies:
Name: Policy1 Users:
o Include: Group1 o Exclude: Group2 Target resources:
o Include: All cloud apps Grant:
o Grant access: Require multi-factor authentication Session:
o Persistent browser session: Never persistent Name: Policy2 Users:
o Include:
- Directory roles: Global Administrator
- Users and groups: User3
o Exclude: Group2 Target resources:
o Include: All cloud apps Session:
o Sign-in frequency:
- Periodic authentication: 2 hours
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:
Exhibit
Answer Area
- User1 will be prompted for the Stay signed in option when they sign in to the Microsoft 365 portal.Yes
- User2 must reauthenticate to Microsoft 365 Apps every two hours.No
- User3 must reauthenticate to Microsoft 365 Apps every two hours.No
Explanation
This question assesses understanding of Conditional Access policy application and session controls.
User and Group Membership:
- User1: Member of Group1, Role: None.
- User2: Member of Group2, Role: Global Administrator.
- User3: Member of Group1, Group2, Role: None.
Conditional Access Policies:
- Policy1:
- Applies to: Group1 (Include), Group2 (Exclude).
- Session: Persistent browser session: Never persistent.
- Policy2:
- Applies to: Global Administrator role (Include), User3 (Include), Group2 (Exclude).
- Session: Sign-in frequency: Periodic authentication: 2 hours.
Evaluation of Statements:
-
User1 will be prompted for the Stay signed in option when they sign in to the Microsoft 365 portal. (Yes)
- User1 is in Group1 and not in Group2. Therefore, Policy1 applies to User1.
- Policy1's session control is set to "Persistent browser session: Never persistent." Even when this setting is configured, the "Stay signed in?" prompt can still appear during the sign-in process. The "Never persistent" setting ensures that, regardless of the user's selection at the prompt, the session will not actually persist.
-
User2 must reauthenticate to Microsoft 365 Apps every two hours. (No)
- User2 is a Global Administrator and a member of Group2.
- For Policy1: User2 is in Group2, which is an exclusion. Thus, Policy1 does not apply to User2.
- For Policy2: User2 is included by their Global Administrator role, but also explicitly excluded by Group2. In Conditional Access, exclusions always take precedence over inclusions. Therefore, Policy2 does not apply to User2.
- Since no Conditional Access policy with a sign-in frequency setting applies to User2, they will not be forced to reauthenticate every two hours.
-
User3 must reauthenticate to Microsoft 365 Apps every two hours. (No)
- User3 is a member of Group1 and Group2.
- For Policy1: User3 is included by Group1, but also excluded by Group2. Exclusions take precedence, so Policy1 does not apply to User3.
- For Policy2: User3 is explicitly included, but also excluded by Group2. Exclusions take precedence, so Policy2 does not apply to User3.
- Since no Conditional Access policy with a sign-in frequency setting applies to User3, they will not be forced to reauthenticate every two hours.
Community Discussion
No community discussion yet for this question.
