You must require multifactor authentication only when users launch Azure Virtual Desktop resources from outside named corporate locations. Other cloud apps should not be affected. Which Conditional Access configuration meets the requirement with the least scope change?
Choose an answer
Tap an option to check your answer.
Correct answer: Cloud apps: Azure Virtual Desktop; Conditions: Locations = Outside trusted locations; Grant: Require multifactor authentication..
Why this is the answer
This option correctly targets Azure Virtual Desktop (AVD) as the specific cloud app, ensuring other cloud apps are unaffected. By setting the condition to "Locations = Outside trusted locations," MFA is only prompted when users access AVD from outside the defined corporate network, fulfilling the requirement. "Grant: Require multifactor authentication" enforces the desired security measure. The other options are incorrect because: "Cloud apps: Windows sign-in" would apply MFA to all Windows sign-ins, not just AVD, and doesn't consider location. "Cloud apps: Office 365" targets the wrong application and enforces a password change, not MFA. "Cloud apps: Azure Resource Manager" targets the wrong application and restricts by client app type, not location. "Cloud apps: Microsoft Remote Desktop" targets the wrong application (AVD is distinct from generic RDP) and restricts by device platform, not location.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed