You have an Azure AD subscription and must require Global Administrators to use MFA and an Azure AD–joined device when connecting from untrusted locations. Solution: you modify the session controls of the Azure AD conditional access policy in the Azure portal. Does this solution meet the requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: No.
Why this is the answer
No, modifying session controls alone will not meet the requirement. While session controls can enforce things like app enforced restrictions or sign-in frequency, they do not directly enforce MFA or require an Azure AD-joined device. To enforce MFA and require an Azure AD-joined device for Global Administrators connecting from untrusted locations, you need to configure the "Grant" controls within the Conditional Access policy. Specifically, you would select "Require multi-factor authentication" and "Require device to be Azure AD joined" under the Grant section.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed