MS-102 - Implement and Manage Identity and Access (26% of the exam) - Section 2.2

Implement and manage Microsoft Entra authentication methods and Conditional Access policies.

Configure the authentication methods policy to enable multifactor authentication options and design Conditional Access policies that enforce controls based on user, location, and sign-in risk. Choose the correct combination of named locations, grant controls, and sign-in risk policies for a given security requirement.

multifactor authenticationauthentication methods policyConditional Accessnamed locationssign-in risk policies

Practice question for this objective

Free sampleImplement and Manage Identity and Accessmedium

An admin asks whether they can save a single Conditional Access policy that includes both a User risk condition set to High and a Sign-in risk condition set to Medium or High. Microsoft recommends combining sign-in risk and user risk conditions in the same Conditional Access policy. Is this statement correct?

  • AYes
  • BNo Correct
Always split user risk and sign-in risk into separate Conditional Access policies; never combine the two conditions in one policy. The Risk policies article carries an explicit warning: Don't combine sign-in risk and user risk conditions in the same Conditional Access policy. Create separate policies for each risk condition. The documented design pattern is one policy per risk type.

Why A is wrong: Combining the two conditions produces unpredictable enforcement, which is why the documentation flags it as something to avoid and instead requires separate policies.

Why B is correct: Correct. The Risk policies article carries an explicit warning: Don't combine sign-in risk and user risk conditions in the same Conditional Access policy.

See more MS-102 practice questions, answers explained.

Exam traps in Implement and Manage Identity and Access

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • The policy created first takes precedence and the second policy is skipped.

    Why it is wrong: Conditional Access does not pick by creation order; multiple applicable policies are combined and all must be satisfied.

  • No

    Why it is wrong: If the answer were No, admins would have no urgency to migrate, but Microsoft has formally announced the retirement date and supplied a step-by-step migration procedure that ends with disabling the legacy policies.

  • The external method works once it has been added to the built-in Phishing-resistant MFA strength preset.

    Why it is wrong: External methods cannot be added to built-in strengths, and the docs flag them as incompatible with authentication strength altogether.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.