Your security team mandates phishing-resistant MFA for a group of Azure Virtual Desktop administrators, but standard users may continue using any MFA method. You will enforce this via Conditional Access. Which setting should you use in the grant controls of the admin-targeted policy?
Choose an answer
Tap an option to check your answer.
Correct answer: Require authentication strength: Phishing-resistant MFA.
Why this is the answer
The correct option is "Require authentication strength: Phishing-resistant MFA" because this specific grant control in Conditional Access allows you to enforce the use of phishing-resistant multifactor authentication methods, such as FIDO2 security keys or certificate-based authentication, for the targeted group of administrators. This directly addresses the security team's mandate. "Require multifactor authentication" is too broad; it would allow any MFA method, not specifically phishing-resistant ones. "Require password change" is a security measure but doesn't relate to MFA. "Require compliant device" and "Require Hybrid Azure AD joined device" are device-based controls and do not enforce MFA methods.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed