Microsoft 365 Administrator Expert MS-102 Practice Question
Your company has a Microsoft Entra tenant that is synchronized with an on-premises Active Directory. Security analysts report repeated password-spray attempts that target IMAP and POP endpoints. Management issues the following requirements:
Prevent all users from authenticating by using legacy protocols.
Allow two service accounts that collect printer scan jobs to continue using legacy protocols.
Preserve modern authentication for interactive sign-ins. You decide to use Conditional Access. Which configuration meets the requirements?
Create a Conditional Access policy that blocks IMAP and POP by using the Client apps condition and targets only the two service accounts.
Create a Conditional Access policy that targets all users, includes the Client apps condition for legacy authentication, sets the grant control to Block access, and excludes the two service accounts.
Create a Conditional Access policy that blocks access from unmanaged devices and applies to all users.
Create a Conditional Access policy that requires multifactor authentication for legacy authentication and includes all users.
Blocking legacy authentication is achieved in Conditional Access by configuring the Client apps condition to target "Other clients (legacy authentication)" and setting the grant control to Block access. Because Conditional Access policies are additive, excluding the two printer service accounts from the policy ensures that all other users are blocked from IMAP and POP while those accounts remain permitted. Requiring MFA does not stop legacy protocols (they cannot perform MFA), targeting only the service accounts would mistakenly block them, and filtering on device state does not address protocol usage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is legacy authentication in Microsoft Entra?
Open an interactive chat with Bash
How does Conditional Access ensure security against legacy protocols?
Open an interactive chat with Bash
What is the Client apps condition in Conditional Access policies?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .