AZ-500 exam dumps

AZ-500 practice question 21 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 21

Single answer

Your organization wants to restrict access to a newly deployed Teams-based application so that only devices marked as compliant can use it. Executives also wish to minimize additional prompts for users who travel frequently or work remotely. You have assigned the Teams application to the relevant user groups in Azure AD. Which Conditional Access policy approach best meets these requirements?

  1. A

    Create a new Conditional Access policy targeting all users and require multi-factor authentication from any location for every sign-in.

  2. B

    Create a new Conditional Access policy targeting the Teams app and the assigned user group, require device compliance, and exclude trusted IP ranges from the multi-factor authentication requirement.

  3. C

    Create a new Conditional Access policy that blocks the Teams app for all networks except the corporate headquarters IP address range.

  4. D

    Create an Azure AD location-based policy allowing the Teams app only for users logging in from on-premises IP addresses.

Show answer and explanation

Correct answer: B

Explanation

A well-configured Conditional Access policy should combine device compliance with conditional requirements such as MFA. Targeting specific apps and groups while excluding trusted locations helps reduce unnecessary authentication prompts, which aligns with minimal user disruption objectives. For more details on configuring Conditional Access policies with device compliance, see the Microsoft documentation: https://learn.microsoft.com/azure/active-directory/conditional-access/howto-conditional-access-policy-compliant-device.

  • A. Incorrect.

    Option 1 is incorrect because it imposes MFA on every sign-in from all locations, which does not minimize disruptions for traveling employees. It also does not explicitly restrict access to compliant devices only.

  • B. Correct.

    Option 2 is correct. By targeting the Teams app, requiring device compliance, and excluding trusted IP ranges from additional MFA prompts, you both enforce compliant devices and reduce unnecessary authentication prompts for employees working from known safe locations.

  • C. Incorrect.

    Option 3 is incorrect because it limits access only to a single IP address range, preventing remote or traveling users from accessing Teams unless they use the corporate network. This conflicts with the requirement to minimize disruptions for traveling employees.

  • D. Incorrect.

    Option 4 is incorrect because the policy is entirely location-based and does not enforce device compliance. It also restricts offsite access, again conflicting with the requirement for remote accessibility.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam