SC-300 Azure AD Conditional Access 1 — Questions and Answers
Question 1: Which Conditional Access grant control requires users to use a device that is marked as compliant in Microsoft Intune?
- Require approved client app
- Require device to be marked as compliant (Correct answer)
- Require hybrid Azure AD joined device
- Require app protection policy
Correct answer: Require device to be marked as compliant
The 'Require device to be marked as compliant' grant control enforces that the accessing device meets Intune compliance policies.
Question 2: A Conditional Access policy is set to 'Report-only' mode. What is the effect on users?
- Users are blocked from signing in
- Policy is enforced and users must comply
- Policy evaluates but does not enforce; results are logged only (Correct answer)
- Policy is disabled and not evaluated
Correct answer: Policy evaluates but does not enforce; results are logged only
Report-only mode evaluates the policy against sign-in events and logs the outcome without enforcing the controls.
Question 3: Which named location type in Conditional Access allows you to specify trusted locations using IP ranges?
- Countries/Regions location
- IP ranges location (Correct answer)
- Trusted devices location
- Compliant network location
Correct answer: IP ranges location
IP ranges named locations let administrators define trusted network zones by specifying IPv4 or IPv6 CIDR blocks.
Question 4: You want to require MFA only when users sign in from outside the corporate network. Which Conditional Access condition should you configure?
- Device platforms
- Named locations (Correct answer)
- User risk
- Sign-in frequency
Correct answer: Named locations
Named locations let you include or exclude specific IP ranges so MFA is enforced only for sign-ins originating outside the trusted corporate network.
Question 5: Which session control in Conditional Access restricts the duration of a user's authenticated session before re-authentication is required?
- Application enforced restrictions
- Persistent browser session
- Sign-in frequency (Correct answer)
- Continuous access evaluation
Correct answer: Sign-in frequency
Sign-in frequency controls how often users must re-authenticate, overriding the default session lifetime.
Question 6: A Conditional Access policy targets the 'All cloud apps' assignment. An administrator needs to exclude the Azure portal from this policy. Where is this exclusion configured?
- Under 'Conditions' > 'Locations'
- Under 'Cloud apps or actions' > 'Exclude' (Correct answer)
- Under 'Users' > 'Exclude'
- Under 'Grant' controls
Correct answer: Under 'Cloud apps or actions' > 'Exclude'
Specific apps can be excluded from a policy by selecting them under the 'Exclude' tab within the 'Cloud apps or actions' assignment section.
Which Conditional Access grant control requires users to use a device that is marked as compliant in Microsoft Intune?