Microsoft 365 Administrator Expert MS-102 Practice Question
Your company uses Microsoft Entra ID and Intune. Security requires that when users open Outlook on the web from any device that is neither hybrid Azure AD joined nor marked compliant, they must be prompted to sign in at least every four hours. Access from corporate devices must be unaffected. You plan to use supported features only. What should you configure to meet the requirement?
Create a Conditional Access policy that targets the Exchange Online cloud app, includes all users, excludes devices that are hybrid Azure AD joined or marked compliant, and adds a Session control that sets Sign-in frequency to 4 hours.
Create an Azure AD token lifetime policy that sets the RefreshTokenValidityHours property to 4 and assign it to the Exchange Online service principal.
Deploy an Intune device compliance policy that requires a password every 4 hours and mark non-compliant devices as blocked from Exchange Online.
Enable Continuous Access Evaluation for Exchange Online and configure a tenant-wide sign-in frequency of 4 hours in the Security defaults settings.
Conditional Access session controls allow you to enforce token lifetimes for specific cloud apps and scenarios. By creating a policy that targets the Exchange Online cloud app and excludes devices that are either hybrid Azure AD joined or evaluated as compliant, you can apply a Session control that sets the Sign-in frequency to four hours, forcing re-authentication only for unmanaged devices. Token lifetime policies are considered legacy, have broader scope, and are no longer the recommended approach. Continuous Access Evaluation improves responsiveness to risk events but does not let administrators specify a fixed re-authentication interval. Intune device compliance settings manage local device access, not the authentication session length of Outlook on the web, and therefore cannot meet the stated requirement on their own.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Conditional Access in Microsoft Entra ID?
Open an interactive chat with Bash
What does 'Sign-in frequency' control in Conditional Access policies?
Open an interactive chat with Bash
How do hybrid Azure AD-joined devices differ from Intune-compliant devices?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .