AZ-500 exam dumps

AZ-500 practice question 22 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 22

Select 2

Your organization has developed a new line-of-business (LOB) web application that is registered in Microsoft Entra ID. Only the Sales department should have access to this application. In addition, all Sales users must be prompted for multi-factor authentication (MFA) whenever they attempt to sign in to the LOB application. Which two steps should you implement to meet these requirements?

  1. A

    Enable 'User assignment required' in the LOB application's properties and assign the Sales department group to the application.

  2. B

    Create a Conditional Access policy for the LOB application that targets the Sales department group and requires MFA.

  3. C

    Grant admin consent for all users in the tenant within the LOB application’s API permissions page.

  4. D

    Add the entire organization as a direct assignment to the application and rely on group membership for restricting access.

  5. E

    Disable user assignment in the LOB application settings to ensure only the assigned group can access it.

Show answer and explanation

Correct answers: A, B

Explanation

To ensure secure application access, you must first enable user assignment so that only named groups or users can authenticate to the application. Then, creating a Conditional Access policy that targets the application and requires MFA for the Sales group enforces multi-factor authentication for that specific group. For more information, see Microsoft documentation on assigning users and groups to applications (https://learn.microsoft.com/azure/active-directory/manage-apps/grant-access-portal) and Conditional Access policies (https://learn.microsoft.com/azure/active-directory/conditional-access/overview).

  • A. Correct.

    Option 1 is correct because enabling 'User assignment required' ensures that only specified users or groups can access the application. Assigning the Sales group to the application limits access to that group exclusively.

  • B. Correct.

    Option 2 is correct because creating a Conditional Access policy to require MFA specifically for the Sales department group using this application effectively enforces MFA whenever they sign in.

  • C. Incorrect.

    Option 3 is incorrect because granting admin consent at the tenant level does not limit access to the Sales department only, nor does it enforce MFA by itself. Admin consent is primarily about granting permissions for the application, not about restricting or enforcing MFA requirements.

  • D. Incorrect.

    Option 4 is incorrect because assigning the entire organization to the application contradicts the requirement to limit access solely to the Sales department. You would then have to manually remove or block other groups, which is not recommended or efficient.

  • E. Incorrect.

    Option 5 is incorrect because disabling user assignment in the application's settings actually removes the requirement for users to be explicitly assigned to the application. This would open the application to other users instead of restricting it to the Sales group.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam