Microsoft 365 Administrator Expert MS-102 Practice Question
Your company enabled Microsoft Entra security defaults six months ago. Now the security team wants to require phishing-resistant MFA (FIDO2 security keys or Windows Hello for Business) for all members of the Privileged Authentication Administrator and Global Administrator roles, while keeping other users on the existing MFA requirement. You must also exclude two emergency break-glass accounts from any MFA enforcement. What should you do?
Keep security defaults enabled and add an authentication strength policy that requires phishing-resistant MFA for the privileged roles.
Create an access review that requires users in the privileged roles to register a FIDO2 security key before they can sign in.
Enable per-user MFA for the privileged roles and configure it to allow only FIDO2 authentication.
Disable security defaults and create a Conditional Access policy that targets the privileged roles, applies the Phishing-resistant MFA authentication strength, and excludes the break-glass accounts.
Security defaults enforce one fixed set of Conditional Access rules and cannot be modified, scoped to particular roles, or paired with authentication strength requirements. To target only specific administrative roles and to mandate a phishing-resistant method, you must first turn security defaults off. You can then create a Conditional Access policy that is scoped to the desired directory roles, applies the Phishing-resistant MFA authentication strength, and explicitly excludes the designated break-glass accounts. Per-user MFA cannot restrict authentication to FIDO2 or Windows Hello, and access reviews do not set authentication requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are security defaults in Microsoft Entra?
Open an interactive chat with Bash
What is a Conditional Access policy?
Open an interactive chat with Bash
What are break-glass accounts, and why are they excluded from MFA enforcement?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .