Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-900 Exam - Topic 14 Question 16 Discussion

What should you use to ensure that the members of an Azure Active Directory group use multi-factor authentication (MFA) when they sign in?
B) a conditional access policy
A) Azure Active Directory (Azure AD) Identity Protection
C) Azure role-based access control (Azure RBAC)
D) Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

Microsoft SC-900 Exam - Topic 14 Question 16 Discussion

Actual exam question for Microsoft's SC-900 exam
Question #: 16
Topic #: 14
[All SC-900 Questions]

What should you use to ensure that the members of an Azure Active Directory group use multi-factor authentication (MFA) when they sign in?

Show Suggested Answer Hide Answer
Suggested Answer: B

The recommended way to enable and use Azure AD Multi-Factor Authentication is with Conditional Access policies. Conditional Access lets you create and define policies that react to sign-in events and that request additional actions before a user is granted access to an application or service.


Contribute your Thoughts:

0/2000 characters
Polly
10 months ago
Azure RBAC doesn't handle MFA, just access control!
upvoted 0 times
...
Ciara
10 months ago
Wait, can you really enforce MFA with just a policy? Sounds too easy.
upvoted 0 times
...
Shaniqua
10 months ago
Conditional access is the best choice here, no doubt!
upvoted 0 times
...
Starr
10 months ago
I thought Azure AD Identity Protection was the way to go?
upvoted 0 times
...
Beula
10 months ago
Definitely need a conditional access policy for MFA!
upvoted 0 times
...
Ruth
11 months ago
I thought PIM was for managing privileged access, so I don't think that's the right choice for enforcing MFA.
upvoted 0 times
...
Renea
11 months ago
I’m leaning towards option B too, but I also recall something about Azure RBAC being related to permissions, not MFA.
upvoted 0 times
...
Ashton
11 months ago
I remember something about Azure AD Identity Protection, but it feels like that was more about risk detection than enforcing MFA.
upvoted 0 times
...
Rene
11 months ago
I think it might be a conditional access policy, but I'm not entirely sure. We practiced that in class, right?
upvoted 0 times
...
Virgie
11 months ago
Hmm, this is a tricky one. I'm not entirely confident, but I think the objective might be to create the plan to deliver the project product, so I'll select option A.
upvoted 0 times
...
Ellen
11 months ago
Hmm, I'm a bit unsure here. Should we really focus on the risk threshold first? Establishing the report format required by the client seems like it could be just as important to get right from the start.
upvoted 0 times
...
Lilli
11 months ago
Okay, I think I know the answer. Let me double-check the options.
upvoted 0 times
...
Kimbery
11 months ago
I'm pretty confident it's VNI too, especially since there was a practice question that mentioned VNIs as identifiers for segments in VXLAN.
upvoted 0 times
...
Lauran
11 months ago
The "mgmt" tenant sounds like it could be the right answer, but I'll need to review my notes to confirm that.
upvoted 0 times
...

Save Cancel