SC-300 · Question #449
You have a Microsoft Entra tenant. You need to configure protected actions to require privileged users to use phishing-resistant multifactor authentication (MFA). What should you do first?
The correct answer is C. Add an authentication context.. Protected actions are enforced through Conditional Access by associating specific high-impact permissions with an authentication context. The authentication context is the “tag” that Conditional Access can target for step-up requirements. You must create this authentication conte
Question
You have a Microsoft Entra tenant. You need to configure protected actions to require privileged users to use phishing-resistant multifactor authentication (MFA). What should you do first?
Options
- ACreate an access package.
- BConfigure an authentication strength for the tenant.
- CAdd an authentication context.
- DCreate a Conditional Access policy.
How the community answered
(40 responses)- A10% (4)
- B3% (1)
- C83% (33)
- D5% (2)
Explanation
Protected actions are enforced through Conditional Access by associating specific high-impact permissions with an authentication context. The authentication context is the “tag” that Conditional Access can target for step-up requirements. You must create this authentication context first because it becomes the linkage point used later to bind the selected protected permissions to that context and build a Conditional Access policy that targets the context and requires a phishing-resistant authentication requirement (for example, the built-in Phishing- resistant MFA authentication strength). Without an authentication context in place, there’s nothing to attach protected actions to and nothing specific for a Conditional Access policy to scope to for those protected permissions.
Topics
Community Discussion
No community discussion yet for this question.