Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam MS-102 topic 1 question 151 discussion

Actual exam question from Microsoft's MS-102
Question #: 151
Topic #: 1
[All MS-102 Questions]

HOTSPOT
-

You have a Microsoft 365 subscription that contains the users shown in the following table.



You have the named locations shown in the following table.



You create a conditional access policy that has the following configurations:

• Users or workload identities:
• Include: Group1
• Exclude: Group2
• Cloud apps or actions: Include all cloud apps
• Conditions:
• Include: Any location
• Exclude: Montreal
• Access control: Grant access, Require multi-factor authentication

User1 is on the multi-factor authentication (MFA) blocked users list.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aleksdj
Highly Voted 5 months, 3 weeks ago
Y = User1 is on the MFA block list BUT IP range 133.107.10.20 is Montreal which is EXLUDED from MFA so user1 can access N = User1 is on the MFA block list AND IP range 193.77.10.15 is Toronto which is INCLUDED in MFA so User cannot access Y = User2 is not in the MFA block list and and member of Group2 which is excluded from the conditional acces policy and therefore can access from 193.77.10.20 Toronto. User2 is even allowed to access M365 from Montreal because the policy is noit applied to User2.
upvoted 8 times
Motanel
2 weeks, 2 days ago
But since the policy is a grant access, and not block access, doesn't that mean all answers are the other way around? which would be N, Y N
upvoted 1 times
...
...
2dwarf
Highly Voted 5 months, 2 weeks ago
I think it is NNY ,because MFA in not enforced by policy. When you are blocked with MFA you cannot sign in any way.
upvoted 7 times
...
pali5178
Most Recent 1 week, 6 days ago
Statement 1: User1 can sign in to Microsoft SharePoint Online from Toronto. No. Even though Toronto is included in the locations, User1 is on the MFA blocked users list. This means they will be blocked from signing in regardless of the conditional access policy's rules. Statement 2: User2 can sign in to SharePoint Online from Montreal. No. While User2 is part of a group excluded from the policy, the location Montreal is specifically excluded. Any access attempt from that location will be blocked. Statement 3: User3 can sign into SharePoint Online from Montreal if the user performs multi-factor authentication. Yes. Here's why: User3 is in the included Group1. Montreal is explicitly excluded, HOWEVER, the policy grants access if MFA is performed. Therefore, if User3 performs MFA successfully, the location restriction is bypassed.
upvoted 1 times
...
de0e20a
2 weeks ago
The issue here is that “Blocked MFA users List” according to Microsoft Learn is actually a report that says why a users mfa was blocked. In this case the second option would cause an entry in that “list” This is the only reference I could find to a “List” https://techcommunity.microsoft.com/t5/microsoft-entra/unblock-mfa/m-p/408018 there is however a section in Azure MFA that you can block or unblock the ability for the app to send requests to the Azure Tenant. This however is not a seen as a list in the Microsoft documentation. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-mfasettings#block-and-unblock-users So the user being on a blocked mfa list just means that they have had failed mfa attempts which wouldn’t matter to the Conditional Access Policies.
upvoted 1 times
...
SBGM
3 months, 1 week ago
Can't figure this one out and don't have the time to set up a lab scenario, but: Azure blocked users page states: 'A blocked user will not receive multifactor authentication requests. Authentication attempts for that user will be automatically denied. A user will remain blocked for 90 days from the time they are blocked.' ChatGPT: ' If a user is on the blocked MFA users list in Azure, their sign-in attempts will be blocked regardless of the location from which they are attempting to sign in. Exclusions based on location for not requiring MFA typically apply to users who are not on the blocked list. Once a user is on the blocked list, their sign-in attempts will be blocked regardless of other factors such as location exclusions. Therefore, even if the user is trying to sign in from a location excluded from MFA requirements, their login attempt will still be blocked if they are on the blocked MFA users list.' I am convinced that User 1 is unable to sign in regardless of location/IP address
upvoted 3 times
...
itguys
4 months, 3 weeks ago
NNY user MFA is enabled in lgeacy settings....
upvoted 3 times
itguys
4 months, 3 weeks ago
*legacy
upvoted 1 times
...
...
TP447
6 months ago
YNY is correct. User1 wouldnt trigger the CA Policy from Montreal due to the exclusion so would be granted access without requiring MFA.
upvoted 2 times
...
jt2214
6 months ago
I would assume since User 1 is on the blocked list they cannot access?
upvoted 3 times
...
rfree
6 months, 3 weeks ago
YNY. Question is, Can User 1 connect? NOT can User1 connect with MFA. And the CA doesn't apply to montreal anyway since its excluded.
upvoted 2 times
...
Darekmso
6 months, 4 weeks ago
https://www.examtopics.com/discussions/microsoft/view/55435-exam-ms-100-topic-4-question-36-discussion/ NNY
upvoted 2 times
...
netbw
7 months, 2 weeks ago
Answer is correct. User1 can connect from Montreal.
upvoted 1 times
...
BlackCat9588
7 months, 3 weeks ago
NNY? MFA of user1 is blocked
upvoted 3 times
BlackCat9588
7 months, 3 weeks ago
Exclude: Montreal
upvoted 1 times
NrdAlrt
6 months, 1 week ago
But an exclusion just means they are excluded from the policy and the policy grants access. I guess it's assumed they are still allowed access by skipping this policy being applied to them(and that nothing else is denying them access).
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...