You manage a line-of-business app protected by Azure AD. Requirements: allow access only from devices marked as compliant when users are outside trusted corporate networks; block access when sign-in risk is High. You maintain an egress IP list for corporate offices and VPN. Which two configurations should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create named locations for your corporate egress IPs and mark them as trusted. Create a Conditional Access policy for the app that applies to Any location excluding trusted named locations and grants ‘Require device to be marked as compliant’., Create a Conditional Access policy that blocks access when Sign-in risk is High for the targeted users and the app..
Why this is the answer
The first correct option addresses the requirement to allow access only from compliant devices when users are outside trusted networks. By defining trusted named locations for corporate IPs, a Conditional Access policy can then target "Any location excluding trusted named locations" and enforce the "Require device to be marked as compliant" control. This ensures that users accessing from untrusted locations must use a compliant device. The second correct option directly fulfills the requirement to block access when sign-in risk is High by creating a Conditional Access policy that targets this specific risk level. The incorrect option "Enable per-user MFA for all users..." does not address the device compliance or sign-in risk requirements. The incorrect option "Configure a location restriction in the app’s manifest..." is not an Azure AD Conditional Access feature and would not provide the necessary device compliance or risk-based access controls.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed