Microsoft 365 Administrator Expert MS-102 Practice Question
Contoso Ltd. uses a Microsoft Entra tenant. You are planning Conditional Access. Requirements: 1) Enforce MFA for all privileged directory roles. 2) The control should apply only when sign-ins come from outside the head-office public IP ranges. 3) Emergency break-glass accounts must remain unaffected. What is the best way to scope the new policy?
Target the built-in directory roles in Users and groups, exclude the break-glass accounts, define a named location for the head-office IP ranges and exclude it, and set Grant controls to Require multifactor authentication.
Target All users, set a Sign-in risk condition of Medium and above, require multifactor authentication, and exclude the break-glass accounts.
Target All guest users, scope the policy to the Microsoft Azure Management cloud app, exclude the head-office location, and grant Require multifactor authentication.
Target a security group that contains the privileged accounts, include only the head-office named location, and grant Require multifactor authentication.
Conditional Access can be assigned directly to built-in directory roles. By selecting the privileged roles in the Users and groups pane, every current and future holder of those roles is covered without manual group maintenance. Excluding the emergency accounts prevents lockout. Defining the head-office IP ranges as a named location and excluding it ensures MFA is required only when the sign-in originates elsewhere. Alternatives that target all users, risk levels, or guest users either affect too many identities or fail to meet the location requirement, while a static security group requires ongoing upkeep and still enforces MFA inside the trusted network.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a break-glass account in Microsoft Entra?
Open an interactive chat with Bash
What is a named location in Conditional Access policies?
Open an interactive chat with Bash
How does scoping Conditional Access policies to directory roles simplify management?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .