exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 3 question 76 discussion

Actual exam question from Microsoft's MD-101
Question #: 76
Topic #: 3
[All MD-101 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

MFA has a trusted IP address range of 123.30.20.0/24.
You have the Azure AD named locations shown in the following table.

You create a Conditional Access policy that has the following settings:
✑ Name: CAPolicy1
✑ Assignments
- Users or workload identities
- Include: Group1
- Cloud apps or actions: App1
✑ Conditions
- Locations
- Include: All trusted locations
✑ Access controls
- Grant access
- Require multi-factor authentication
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Yes -
Location2 is not trusted.

Box 2: No -
Location1 is trusted.

Box 3:No -
MFA IP range is also trusted.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Fedexxx92
Highly Voted 2 years, 7 months ago
So much confusion here..... MULTI-FACTOR AUTH STATUS (MFA Legacy) and Conditional Access are not the same! MULTI-FACTOR AUTH STATUS (Azure Active Directory-> Users -> Per Users-MFA) Note that in the conditional access under conditions there is Include, so the policy will be applied only if the conditions is true (so the policy will apply only to the trusted location) The correct answer is: 1 - NO: User1 Sign-in from an UN-Trusted Location, so the policy CAPolicy1 won't be applied 2 - YES: User1 Sign-In from a Trusted Location, so the policy will be applied (Grant Access, Require MFA), also if the MFA Status report as disabled, doesn't mean anything. If the user has not yet configured the mfa he will be asked to register 3 - NO: The Multi-Factor Auth Status is Enforced, so at every Sign-In User2 is required to approve MFA (regardless of conditional access...MFA Legacy in enforced mode take precedence to Conditional Access), but there is Public Subnet 123.30.20.0/24 marked as trusted IP per MFA Legacy, so is not required from this location
upvoted 8 times
SlickPatty
2 years ago
agreed
upvoted 1 times
...
DashP
2 years, 7 months ago
You could be right! Because Named location section in the link provided state in the condition Include: Any location exclude: All trusted locations In here Include: All trusted locations, that means policy applies only to the trusted locations, even though MFA is disabled I think it will prompt user to register for MFA.
upvoted 2 times
...
dawnbringer69
2 years, 2 months ago
This is correct. It has been tested and found as such. Excellent Justification.
upvoted 1 times
...
4D33L
1 year, 11 months ago
for 3. yes user 2 is enforced and the CA wont apply anyway but the question is asking if they are going to be prompted for MFA...so it should be yes
upvoted 1 times
...
...
Adar_14
Most Recent 2 years ago
This is Chat GPT answer. If user level MFA is disabled and Conditional access enable MFA for the same user, which one will be applied? ChatGPT If a user has MFA disabled at the user level but there is a Conditional Access policy in place that requires MFA for that user, the Conditional Access MFA requirement will take precedence over the user-level MFA setting. In this case, the user will be prompted for MFA despite having MFA disabled at the user level. Conditional Access policies in Azure AD have a higher priority than user-level settings. When a user attempts to access a resource or sign in, the Conditional Access engine evaluates the policies that are applicable to that user based on the conditions defined in the policies. If a Conditional Access policy requires MFA for the user, it will be enforced, overriding any user-level MFA settings. It's worth noting that if a Conditional Access policy does not require MFA for a user, the user-level MFA setting will be honored, and the user will not be prompted for additional authentication factors.
upvoted 1 times
...
AliNadheer
2 years, 4 months ago
No for all, what i understood after some reading is box1: no because its not trusted location, so CA policy will not apply Box2&3: no because it is trusted location in azure and in MFA, so MFA will be bypassed. This is a tricky one.. reference: https://learn.microsoft.com/en-us/mem/intune/configuration/vpn-settings-windows-10#apps-and-traffic-rules
upvoted 1 times
...
BRoald
2 years, 6 months ago
I think NO, NO & NO https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates#azure-ad-multi-factor-authentication-user-states Also it states: If needed, you can instead enable each account for per-user Azure AD Multi-Factor Authentication. When users are enabled individually, they perform multi-factor authentication each time they sign in (with some exceptions, such as when they sign in from trusted IP addresses or when the remember MFA on trusted devices feature is turned on).
upvoted 1 times
...
Graz
2 years, 6 months ago
I'm answering NNN and taking 2 out of 3 points because idk what's right and what's not
upvoted 1 times
...
JN_311
2 years, 6 months ago
I say N, N, Y MFA Status is disabled for User 1. If the MFA Status was 'Not Registered' then yes it would prompt user to register, however its clear it shows that its disabled
upvoted 1 times
...
Feyenoord
2 years, 7 months ago
Confusing but i think it should be No No Yes No because disabled. Yes because trusted locations have been granted require MFA.
upvoted 2 times
Feyenoord
2 years, 7 months ago
Disable MFA is one of the things you do to for example a break glass account. Also a break glass account should be excluded in a CA policy.
upvoted 2 times
...
...
raduM
2 years, 7 months ago
here it should be no no. no 1. not a trusted location 2 mfa is disabled for user 1 so he cannot be prompted for mfa. 3. mfa trusted iprange so AD Multifactor Authentication bzpasses multifactor authentication prompts
upvoted 1 times
...
TonySuccess
2 years, 9 months ago
Why won't user 2 be prompted for MFA in answer 3? They are not in a trusted location.
upvoted 1 times
TonySuccess
2 years, 9 months ago
Yes they are: MFA has a trusted IP address range of 123.30.20.0/24. Missed that hehe.
upvoted 1 times
...
...
Mnguyen0503
2 years, 9 months ago
I feel like it should be N N N User 1 MFA is disabled. That should override the Conditional Access Rule. So he won't be prompted for 2FA anywhere. Please correct me if I'm wrong
upvoted 3 times
tecnicosoffshoretech
2 years, 9 months ago
i think you are wrong. MFA for user 1 is disabled but he will be requested to register to MFA as soon as she tries to connect from the untrusted network
upvoted 3 times
raduM
2 years, 7 months ago
you are wrong... if mfa is disabled he will not be asked to register
upvoted 2 times
Fedexxx92
2 years, 7 months ago
it's not true...try on you home. MFA Legacy is a method that will be (mybe) deprecated in the next future,but has no impact on conditional access. In our Azure AD ALL users have status disabled in MFA Legacy, but we manage succesfully mfa via conditional access It is dangerous when you mix the MFA Legacy and Conditional Access because you risk anomalous behavior...
upvoted 3 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...