exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 71 discussion

Actual exam question from Microsoft's AZ-500
Question #: 71
Topic #: 2
[All AZ-500 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

You create and enforce an Azure AD Identity Protection sign-in risk policy that has the following settings:
✑ Assignments: Include Group1, exclude Group2
✑ Conditions: Sign-in risk level: Low and above
✑ Access: Allow access, Require multi-factor authentication
You need to identify what occurs when the users sign in to Azure AD.
What should you identify for each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-access-policies/ https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pitch09
Highly Voted 3 years, 4 months ago
User1 - is excluded but user1 MFA is Enabled Exclusion will take precedence. Ans: MFA will be prompted User2 - is include and user meet the above threshold for sign-in risk level: low and above therefor user account will be blocked. Note: If you target this policy to a user that hasn't registered for MFA. Their access will be blocked Ans: Be blocked
upvoted 43 times
Iuzzo
3 years, 3 months ago
User1 - should be Excluded... MFA is only Enabled and not Enforced
upvoted 5 times
ruscomike
9 months, 2 weeks ago
enabled meand that he/she have to challenge MFA but has not been already configured the mfa method. after that the status become enforced
upvoted 2 times
...
...
monob25889
3 years, 4 months ago
User1: Exclusion will take precedence. The MFA will NOT be prompted.
upvoted 7 times
koreshio
2 years, 6 months ago
correct, they should be asked to set up MFA due to 'Enabled' (but not 'Enforced' state), but should be able to log in with username and pass but without MFA
upvoted 6 times
...
...
AIster77
1 year, 9 months ago
in exam taken 24 July 2023
upvoted 8 times
...
basak
1 year, 8 months ago
1. user 1 will be prompted for sign-up MFA ( exclusion is applied) 2. user 2 will be applied policy. however, since user2 MFA is disabled hw will not be able login and will be blocked. a user should prior sign-up MFA to act conditional access policy.
upvoted 3 times
...
...
Nik9059
Highly Voted 3 years, 4 months ago
I think in both the cases the user will be prompted for MFA
upvoted 23 times
mansc3wth1s
3 years, 2 months ago
MFA Disabled/Enabled on these questions do matter if they are already meeting remediation conditions. They would have to have enforced MFA already by this point. Because User1 is in Group1 and Group2 the user is then Excluded period. They're free to login with user and pass at this point. MFA is not enabled and no other policy to fallback on that we know of.
upvoted 4 times
...
[Removed]
3 years, 3 months ago
Wrong as user 2 must register for Azure AD MFA for remediation as its disabled
upvoted 1 times
...
...
Nhadipour
Most Recent 2 months, 3 weeks ago
User1: "Sign in by using a username and password only.” User2: “Be blocked”
upvoted 1 times
randy0077
4 weeks, 1 day ago
You are missing the point here, MFA is already enabled so regardless of policy applies or not MFA will be triggered.
upvoted 1 times
...
...
schpeter_091
5 months ago
User 1 has to use(setup) an MFA, regardless to his group membership, since MFA is enabled. If MFA was disabled, user wouldn't be blocked because of the exclusion.
upvoted 1 times
...
shadad
6 months ago
User1 = Excluded Yes but the MFA is enabled and enable mean it will prompt him but he still can skip it setup to use his user name as its not enforced. The question is asking about the prompting MFA then we need to answer that part ( enforced will prompt and he must use it ). User 2 = Need to use MFA but its not enabled so he will be blocked.
upvoted 1 times
...
pentium75
9 months ago
User1 - will be prompted to set up MFA, but can log in without MFA (he is excluded from the policy) User2 - will be blocked (he has not enrolled in MFA and can't do that during a risky signin)
upvoted 2 times
...
ivann2010
1 year, 1 month ago
We are talking about "Identity Protection" and not "Conditional Access". Answer for me is: "Sing in by using.....", because MFA is activated, it does not show you the MFA PROMP, it gives you the option to configure it or do it later, if you say do it later you go straight in. Regarding the second, it will force you to configure MFA although it does not change the user's status.
upvoted 3 times
...
brooklyn510
1 year, 3 months ago
On exam 1/2/24
upvoted 4 times
...
[Removed]
1 year, 4 months ago
I have tested this in the Lab When User has MFA enabled it will prompt for MFA When User has MFA disabled it will still prompt for MFA if the user is required to do MFA.
upvoted 4 times
pentium75
9 months ago
But User2 has not registered for MFA yet. And he can't register it during a risky logon that requires MFA, thus he is blocked.
upvoted 1 times
...
...
AZ5002023
1 year, 4 months ago
enabled does not mean enforced so i think box 1 user name and pass box 2 : blocked
upvoted 3 times
...
wardy1983
1 year, 5 months ago
User1 - is excluded but user1 MFA is Enabled Exclusion will take precedence. Ans: MFA will be prompted User2 - is include and user meet the above threshold for sign-in risk level: low and above therefor user account will be blocked. Note: If you target this policy to a user that hasn't registered for MFA. Their access will be blocked Ans: Be blocked Reference: http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-accesspolicies/ https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identityprotection- policies https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/conceptidentity- protection-risks
upvoted 2 times
...
flafernan
1 year, 5 months ago
If you create a mandatory MFA policy and explicitly exclude USER1 from that policy, but USER1 already has MFA enabled on their account, they will not be affected by the policy. This is because the explicit deletion of the MFA policy should override the policy, allowing USER1 to continue using their multi-factor authentication as usual. The opt-out policy is more specific and will take priority over the MFA mandatory policy. Therefore, USER1 will be able to authenticate without any problems using MFA.
upvoted 1 times
...
Troublemaker
1 year, 9 months ago
In Exam - 28/7/2023
upvoted 3 times
...
Hillary_Innocent
1 year, 10 months ago
user 1 is excluded in this policy since exclude takes precedence. therefore user one will be blocked.
upvoted 1 times
...
Anarchira
1 year, 10 months ago
User1, Sign in by using a username and paswword only Not affected cuz is excluded and : If a user has MFA configured as enabled but not forced, they are not obligated to configure and use MFA. In this case, the user can choose to sign in using only their username and password without using MFA. Having MFA enabled but not forced means that users are recommended or encouraged to use MFA to add an additional layer of security to their account, but they are not required to do so. Users have the option to configure and use MFA if they wish, but it is not imposed as a mandatory requirement. User2, be blocked cuz is affected and dont have mfa
upvoted 5 times
...
zellck
1 year, 11 months ago
1. Be prompted for MFA 2. Be blocked https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies#risk-remediation Users must register for Azure AD MFA before they face a situation requiring remediation. Users not registered are blocked and require administrator intervention.
upvoted 2 times
...
Alexbz
2 years ago
Both will be promoted for MFA. If MFA is disabled for a user and an access policy force it for login user with MFA disabled status won't be blocked, they will be prompted to set the MFA upon login.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago