AZ-500 exam dumps

AZ-500 practice question 18 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 18

Select 2

You are a security engineer at a company that uses Azure Active Directory (Azure AD) for identity and access management. The organization wants to enforce Multi-Factor Authentication (MFA) whenever users access Azure resources from outside the corporate network. However, users physically connected to the company’s internal network should be allowed to sign in without being prompted for MFA every time. You have decided to configure Azure AD Conditional Access policies and named locations. Which two actions should you take to meet these requirements?

  1. A

    Create a new Conditional Access policy requiring MFA for all cloud apps, targeting all users, and set the condition to exclude the corporate IP range named location.

  2. B

    Add the corporate network's IP range as a trusted named location in Azure AD, marking it as a trusted location.

  3. C

    Enable the legacy per-user MFA setting for every user in the organization to override Conditional Access policies.

  4. D

    In the Conditional Access policy, select 'Any location' under 'Locations' and require MFA only when the accessing device is running Windows 10 or higher.

Show answer and explanation

Correct answers: A, B

Explanation

By combining a Conditional Access policy that requires MFA and leveraging a trusted named location for the corporate IP range, you enforce MFA only when requests originate from outside the internal network. This approach aligns with best practices for Conditional Access and MFA in Azure AD. More details can be found in the Microsoft documentation: https://docs.microsoft.com/azure/active-directory/conditional-access/location-condition.

  • A. Correct.

    Option 1 is correct. You do need a Conditional Access policy requiring MFA for Azure resources (e.g., 'all cloud apps') and specifically exclude the corporate IP range to avoid prompting internal users for MFA. This meets the scenario of enforcing MFA outside the corporate network only.

  • B. Correct.

    Option 2 is correct. Defining the corporate network’s IP range as a named location and marking it as trusted is essential. This allows you to exclude this location from MFA requirements in the Conditional Access policy.

  • C. Incorrect.

    Option 3 is incorrect. The legacy per-user MFA setting is not the recommended approach when using Conditional Access. Conditional Access offers more granular control, so enabling per-user MFA on everyone is unnecessary and can conflict with policy-based MFA.

  • D. Incorrect.

    Option 4 is incorrect. Requiring MFA exclusively for devices running Windows 10 or higher does not align with the scenario. The requirement is to apply MFA based on location (internal vs. external), not operating system version.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam