MS-102 Microsoft 365 Administrator Expert Implementing Conditional Access Policies 3 — Questions and Answers
Question 1: When configuring a Conditional Access policy with 'Require hybrid Azure AD join' as a grant control, which devices will satisfy this requirement?
- Devices enrolled in Intune only
- Devices registered in Azure AD only
- On-premises domain-joined devices that are also registered in Azure AD (Correct answer)
- Devices that have passed an Intune compliance policy
Correct answer: On-premises domain-joined devices that are also registered in Azure AD
Hybrid Azure AD join applies to devices that are both joined to the on-premises Active Directory domain and registered in Azure AD.
Question 2: An administrator has configured a Conditional Access policy in 'Report-only' mode. What is the effect of this mode?
- The policy enforces controls but logs all evaluations
- The policy evaluates sign-ins and reports results without enforcing controls (Correct answer)
- The policy is disabled and not evaluated
- The policy only enforces controls for users in a pilot group
Correct answer: The policy evaluates sign-ins and reports results without enforcing controls
Report-only mode evaluates all sign-ins against the policy conditions and logs what would happen, without actually enforcing the grant or block controls.
Question 3: A Conditional Access policy requires MFA for all cloud apps, but an administrator needs to exempt the Microsoft Intune Enrollment app. What is the correct configuration?
- Exclude Microsoft Intune Enrollment from the cloud apps assignment (Correct answer)
- Set the device platform condition to exclude Windows
- Add the Intune Enrollment app to the trusted locations list
- Configure a separate policy with block access for Intune Enrollment
Correct answer: Exclude Microsoft Intune Enrollment from the cloud apps assignment
Excluding Microsoft Intune Enrollment from the cloud apps assignment prevents the MFA requirement from applying during the device enrollment process.
Question 4: Which feature must be enabled in Azure AD before Conditional Access can evaluate user risk conditions?
- Azure AD Identity Protection (Correct answer)
- Microsoft Defender for Identity
- Azure AD Privileged Identity Management
- Microsoft Defender for Cloud Apps
Correct answer: Azure AD Identity Protection
Azure AD Identity Protection generates user and sign-in risk signals that Conditional Access policies use to evaluate risk-based conditions.
Question 5: An administrator configures a Conditional Access policy with 'Require approved client app' as the grant control. Which scenario does this control address?
- Requiring access only from Intune-managed devices
- Requiring access only from apps that support Intune app protection policies (Correct answer)
- Requiring access only from Azure AD registered devices
- Requiring MFA before accessing the app
Correct answer: Requiring access only from apps that support Intune app protection policies
'Require approved client app' enforces that only Microsoft-approved client applications (which support app protection policies) can access the resource.
Question 6: A user successfully completes MFA but is still blocked by a Conditional Access policy. What should the administrator check first in the sign-in logs?
- The Conditional Access tab in sign-in logs to review which policy applied and why (Correct answer)
- The user's MFA registration status in the Authentication methods blade
- The device compliance status in the Intune admin center
- The user's group membership in Azure AD
Correct answer: The Conditional Access tab in sign-in logs to review which policy applied and why
The Conditional Access tab in Azure AD sign-in logs shows each policy that was evaluated, its result, and the reason for any block.
Question 7: A Conditional Access policy is configured to require MFA for the 'All cloud apps' assignment. A new SaaS application is integrated with Azure AD. How will this new app be affected?
- The new app will not be affected until explicitly added to a policy
- The new app will automatically be subject to the MFA requirement (Correct answer)
- The new app will require a separate Conditional Access policy
- The new app will only be affected after the next policy sync
Correct answer: The new app will automatically be subject to the MFA requirement
When 'All cloud apps' is selected, any new application integrated into Azure AD is automatically covered by that Conditional Access policy.
When configuring a Conditional Access policy with 'Require hybrid Azure AD join' as a grant control, which devices will satisfy this requirement?