exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 70 discussion

Actual exam question from Microsoft's MS-500
Question #: 70
Topic #: 1
[All MS-500 Questions]

HOTSPOT -
You have a Microsoft 365 subscription that contains three users named User1, User2, and User3.
You have the named locations shown in the following table.

You configure an Azure Multi-Factor Authentication (MFA) trusted IP address range of 192.168.1.0/27.
You have the Conditional Access policies shown in the following table.

The users have the IP addresses shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
User1 has IP address 192.168.1.16, which is in DC named location. DC is not trusted.
CA1 applies. Access will not be granted.

Box 2: No -
User2 has IP address 192.168.2.16, which is in NY named location. NY is trusted. However, CA2 blocks Microsoft Planner NY access.

Box 3: No -
User3 is in LA. LA is not trusted.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-policies

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dan91
Highly Voted 2 years, 7 months ago
Y, N, N "All trusted locations" condition applies to All locations that have been marked as trusted location and MFA Trusted IPs (if configured) https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition#all-trusted-locations:~:text=the%20corporate%20network.-,All%20trusted%20locations,MFA%20Trusted%20IPs%20(if%20configured),-Selected%20locations
upvoted 16 times
CertRookie
2 years, 6 months ago
Provided answers are correct: N N N "User1 has IP address 192.168.1.16, which is in DC named location. DC is not trusted. CA1 applies. Access will not be granted."
upvoted 1 times
BoxGhost
2 years, 4 months ago
Also as someone else already said, private IP's are not supported. So the trusted locations will have no effect: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition
upvoted 3 times
Tweety1972
1 year, 11 months ago
WRONG. Tested with IP address 192.168.1.0/27 and no problems
upvoted 1 times
...
...
...
Lomak
2 years, 6 months ago
User 1 : (DC) Trusted = NO MFA Trusted IP range Trusted = YES Named + MFA location = 'All Trusted Locations' so User 1 will 'Grant Access: Require MFA unless Trusted Location overrides MFA Location?
upvoted 3 times
...
...
billo79152718
Highly Voted 2 years, 7 months ago
I would say Yes, No, NO
upvoted 7 times
...
ms260591
Most Recent 1 year, 10 months ago
user 1 will have access with MFA. MFA trusted IPs are included in 'All trusted locations' See - https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition#all-trusted-locations
upvoted 1 times
...
RomanV
2 years ago
Y, N, N (prove me wrong ;) ) Based on the information provided, it appears that DC 1 has an IP address within the range of 192.168.1.0/27, which is also the IP address range that has been configured as a trusted IP address range for Azure Multi-Factor Authentication (MFA). Therefore, if the conditional access policy is configured to allow access from all trusted locations but requires MFA, DC 1 should be able to access Microsoft Forms requiring MFA, since it is located within the trusted IP address range. The trusted IP address range you configured in Azure MFA overlaps with the IP address range of DC 1, so the conditional access policy should allow DC 1 to access Microsoft Forms from its current location.
upvoted 1 times
...
Dislexsick
2 years, 3 months ago
Not even considering the discussion on MFA trusted locations actually do count for Trusted Locations in CAPs (and the internal IP discussion) Answer write-up states that "DC is not trusted. CA1 applies. Access will not be granted." DC1 is not trusted -> therefore CA1 does NOT apply since it failed to meet a condition -> CA1 is NOT applied, which does not mean access is blocked, but rather in the absence of another CAP that blocks access then access is in fact GRANTED.
upvoted 1 times
...
rick001
2 years, 3 months ago
it says : You have the Conditional Access policies shown in the following table. Which means NAMED LOCATION. Which also means all the IP Ranges have to be external. Azure AD CA policies do not accept internal IP's. Due to this the answer should be Y,Y,Y - no policies are applied. But you cannot create this whole setup in the first place.... With MFA Trusted locations you can use internal IP addresses but only with an MFA server / NPS. The trusted IPs can include private IP ranges only when you use MFA Server. For cloud-based Azure AD Multi-Factor Authentication, you can use only public IP address ranges. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings TL:DR this question is stupid and makes no sense. I would go for Y,Y,Y
upvoted 3 times
...
Ksumeet91
2 years, 4 months ago
Y N N Azure MFA Trusted IP ranges option is still valid beside the trusted locations in CA !!
upvoted 1 times
...
zerrowall
2 years, 4 months ago
Regarding User1 there is some confusion. The IP range of this user is in the "trusted ips" of the MFA service settings in the old MFA portal. That means that the MFA request has to be skipped. In this case, the answer has to be N. At the same time, there is a description in Microsoft documentation, that if "Location condition" is set up as "All trusted locations" that applies to the following: - All locations that have been marked as trusted location - MFA Trusted IPs (if configured) So, based on the eam task this condition is appropriate for the 1st string of table and User1 should meet with MFA, i.e. the answer is Y. This is a weird situation. https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition#all-trusted-locations
upvoted 2 times
...
doody
2 years, 4 months ago
answer is Y,N,N All trusted locations This option applies to: 'All locations that have been marked as trusted location MFA Trusted IPs (if configured)' https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition#any-location
upvoted 1 times
...
bac0n
2 years, 5 months ago
TRIPLE NO. The IPs are Public. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings - The trusted IPs can include private IP ranges only when you use MFA Server. For cloud-based Azure AD Multi-Factor Authentication, you can use only public IP address ranges. They don't mention anything about MFA server in this question.
upvoted 5 times
bac0n
2 years, 5 months ago
the IPs are private ***
upvoted 1 times
...
...
Jawad1462
2 years, 6 months ago
YNN first one is Y, because of this You configure an Azure Multi-Factor Authentication (MFA) trusted IP address range of 192.168.1.0/27
upvoted 3 times
...
zeeen
2 years, 6 months ago
Private IP ranges can't be configured https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition#ip-address-ranges
upvoted 1 times
zeeen
2 years, 6 months ago
N,N,N This question, all IPs are private, so Doesn't it correspond to any conditional access?
upvoted 2 times
...
...
Wedge34
2 years, 6 months ago
Y,N,Y for me
upvoted 2 times
...
mohamed_Saed
2 years, 6 months ago
Yes , NO , No 1 IS TRUSTED
upvoted 1 times
Tanasi
1 year, 11 months ago
no, it is not
upvoted 1 times
...
...
ariania
2 years, 6 months ago
It dosent state if the Condition of the CA's are included or Excluded, should we just assume its excluded? Else they include the trusted locations to have MFA if accessing.
upvoted 1 times
ariania
2 years, 6 months ago
User 1 access through CA1 (forms) with Location:(included as nothing else is stated) trusted location = require MFA YES User 2 access through CA2 (planner) with Location:(included as nothing else is stated) NY = nothing NO User 3 access through CA1 (forms) with Location:(included as nothing else is stated) trusted location = require MFA, but NY is not a trusted location in the include, so no MFA will be promted. NO
upvoted 3 times
...
...
pipojede
2 years, 7 months ago
Just note the order of IP Adress ranges in the first table it. The first line (trusted range) is number TWO. .2 Trusted .1 NOT TRUSTED .3 NOT TRUSTED
upvoted 3 times
...
yoton
2 years, 7 months ago
I dont get why user3 won't be prompted for MFA. The policy applied to that user says "Grant Access: Require MFA." Can someone provide a little more explaining. To me it doesn't matter where they are logging in from, they will still be required to complete MFA.
upvoted 1 times
yoton
2 years, 7 months ago
Derp. Is it because they're logging in from an untrusted location so they will be barred access completely and thus not prompted for MFA?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago