You have an Azure AD subscription and must require members of the Global Administrators group to use MFA and an Azure AD–joined device when they sign in from untrusted locations. Solution: you change user settings on the Multi-Factor Authentication page. Does this solution meet the requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: No.
Why this is the answer
No, changing user settings on the Multi-Factor Authentication page only enables or disables MFA for individual users or groups. It does not enforce device state (Azure AD-joined) or location-based conditions. To meet the requirement of enforcing MFA and Azure AD-joined devices for Global Administrators signing in from untrusted locations, you need to configure an Azure AD Conditional Access policy. Conditional Access allows you to define conditions like user groups, cloud apps, device state, and sign-in risk, and then enforce access controls such as requiring MFA or a compliant device.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed