You have a user (User1) and a web app (App1). App1 must accept only modern authentication. You create a Conditional Access policy (CAPolicy1) targeting User1 and App1 and set Grant to Block access. To block only legacy authentication attempts to App1, which condition should you add to CAPolicy1?
Choose an answer
Tap an option to check your answer.
Correct answer: Client apps.
Why this is the answer
The correct answer is Client apps. To block only legacy authentication attempts while allowing modern authentication, you must configure the "Client apps" condition in your Conditional Access policy. This condition allows you to specify which client applications (e.g., mobile apps, desktop clients, browsers) are allowed or blocked. By selecting "Mobile apps and desktop clients" and then choosing "Other clients" (which represents legacy authentication protocols), you can effectively block only those legacy attempts. "Filter for devices" is used to target specific device attributes. "Device platforms" targets operating systems. "User risk" and "Sign-in risk" are used to evaluate the likelihood of a compromised user account or suspicious sign-in, respectively, and do not differentiate between modern and legacy authentication protocols directly for this purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed