exam questions

Exam AZ-300 All Questions

View all questions & answers for the AZ-300 exam

Exam AZ-300 topic 2 question 14 discussion

Actual exam question from Microsoft's AZ-300
Question #: 14
Topic #: 2
[All AZ-300 Questions]

You have an Azure Active Directory (Azure AD) tenant.
All administrators must enter a verification code to access the Azure portal.
You need to ensure that the administrators can access the Azure portal only from your on-premises network.
What should you configure?

  • A. the default for all the roles in Azure AD Privileged Identity Management
  • B. an Azure AD Identity Protection user risk policy
  • C. an Azure AD Identity Protection sign-in risk policy
  • D. the multi-factor authentication service settings
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ekramy_Elnaggar
Highly Voted 5 years, 6 months ago
Answer is C Administrators can also choose to create a custom Conditional Access policy including sign-in risk as an assignment condition. Ref: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies
upvoted 50 times
nagendra25may
5 years ago
On what bases the sign in risk created ? I think it should be based on trusted IPs and trusted IPs we can configure under MFA. So MFA is the correct answer
upvoted 3 times
...
...
SJAz300
Highly Voted 5 years, 5 months ago
Answer is D. The Trusted IPs feature of Azure Multi-Factor Authentication is used by administrators of a managed or federated tenant. The feature bypasses two-step verification for users who sign in from the company intranet. Ref: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings
upvoted 12 times
poohtt
4 years, 11 months ago
No, admin requested to use MFA. Trusted IPs allows not to use MFA from specified IP range. So the amswer is C, because it is an additional requirements to MFA.
upvoted 3 times
...
...
AmitRoy
Most Recent 4 years, 5 months ago
It could be the trick we miss - "All administrators must enter a verification code to access the Azure portal". MFA service settings can't achieve it beacuse it bypasses the multi-factor authentication as per MS docs. Seems like Option C is a better choice.
upvoted 1 times
...
slafcemafce
4 years, 6 months ago
Answer is C https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies => Microsoft's recommendation is to Allow access and Require multi-factor authentication.
upvoted 3 times
...
icecool
4 years, 9 months ago
Location variable in answer D is for MFA bypass, Correct answer is C
upvoted 1 times
...
TatoCM
4 years, 9 months ago
Trusted IPs The Trusted IPs feature of Azure Multi-Factor Authentication bypasses multi-factor authentication prompts for users who sign in from a defined IP address range. ---You can set trusted IP ranges for your on-premises environments to when users are in one of those locations, there's no Azure Multi-Factor Authentication prompt---.
upvoted 1 times
TatoCM
4 years, 9 months ago
The tricky part is when says: MUST to enter a code...
upvoted 1 times
...
...
basak
4 years, 9 months ago
multi-factor authentication -> service settings ->There is no option to enforce login from on premise network ( only Skip MFA for trusted IP) therefore, Option C is correct.
upvoted 1 times
...
BOC
4 years, 9 months ago
D is the correct answer
upvoted 1 times
...
BOC
4 years, 9 months ago
D is the correct answer
upvoted 1 times
...
atwind
4 years, 9 months ago
D https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips here is the explanation.
upvoted 1 times
Rajyahoo
4 years, 9 months ago
Incorrect. In the article, its states - The Trusted IPs feature of Azure Multi-Factor Authentication bypasses multi-factor authentication prompts for users who sign in from a defined IP address range
upvoted 1 times
...
...
ipvaid
4 years, 10 months ago
Answer is D here, so much confusion, see below MS link https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips "If you don't want to use Conditional Access policies to enable trusted IPs, you can configure the service settings for Azure Multi-Factor Authentication using the following steps:" We don't have conditional access available as option to MFA service settings seems to be right.
upvoted 1 times
...
GILLY28
4 years, 10 months ago
Answer is C
upvoted 1 times
...
ercank
4 years, 10 months ago
The only way to achieve is Conditional Access Policy which is not in the list. D- Only gives opportunity to skip the MFA not blocking the access outside the Trusted IPs. Also all admins have to enter a code from wherever they connect . So this is not possible B&C- Only block the access based on the Risk value on which we have no control like setting some location or whitelisted Ips. so I think wording has to be changed for this question otherwise can not see answer
upvoted 1 times
...
ChanderM
4 years, 11 months ago
Given MS documentation says it can be achieved by both ways i.e. Enable the Trusted IPs feature by using Conditional Access and Enable the Trusted IPs feature by using service settings. As Condition access is not in the list so Answer is D. https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#enable-the-trusted-ips-feature-by-using-conditional-access
upvoted 1 times
...
Rooh
4 years, 11 months ago
answer should be C
upvoted 2 times
...
mackc13
4 years, 11 months ago
Answer is C.
upvoted 2 times
...
nabylion
4 years, 11 months ago
Trusted IPs is managed in the MFA configuration
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...