An organization wants to enforce multifactor authentication (MFA) for all users accessing Microsoft 365 services, but they want to bypass this requirement when users are connected to the corporate office network. The public IP addresses of the corporate office have been configured in a named location called 'CorpNet'. How should the Conditional Access policy be configured to meet this requirement?
-
A
Create one policy targeting 'All users', with the Locations condition including 'Any location' and excluding 'CorpNet', and the Grant control set to 'Require multifactor authentication'.
-
B
Create two policies: one that requires MFA from 'Any location' and a second, higher-precedence policy that blocks access from the 'CorpNet' named location.
-
C
Create one policy targeting 'All users', with the Locations condition including only the 'CorpNet' named location, and the Grant control set to 'Block access'.
-
D
Create one policy targeting 'All users', with the Client apps condition configured for 'Browser' and 'Mobile apps and desktop clients', and the Grant control set to 'Require multifactor authentication'.