exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 1 question 2 discussion

Actual exam question from Microsoft's AZ-104
Question #: 2
Topic #: 1
[All AZ-104 Questions]

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has an Azure Active Directory (Azure AD) subscription.
You want to implement an Azure AD conditional access policy.
The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication and an Azure AD-joined device when they connect to Azure AD from untrusted locations.
Solution: You access the multi-factor authentication page to alter the user settings.
Does the solution meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Community vote distribution
B (100%)

Comments

Chosen Answer:
This is a voting comment. You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
green_arrow
Highly Voted 4 years, 7 months ago
B is correct, 1- the best way to enforce MFA is by Conditional Access 2- the device has to be identified by azure AD as A AD joined Device. 3- the trusted ip must be configured.
upvoted 164 times
...
BeauChateau
Highly Voted 2 years, 9 months ago
Selected Answer: B
No, the solution does not meet the goal. To implement the required conditional access policy, the following steps should be taken: Create a new Conditional Access policy in Azure AD portal. Set the policy to require Multi-Factor Authentication and Azure AD device registration. In the policy's "Users and Groups" section, specify the Global Administrators group as the target. In the policy's "Conditions" section, specify the locations that are considered untrusted. Save the policy. Simply accessing the multi-factor authentication page and altering user settings does not provide a comprehensive solution to meet the stated goal.
upvoted 68 times
...
mavlouv
Most Recent 2 months, 1 week ago
Selected Answer: B
La solution proposé ne permet pas d'implementer MFA et AAD (Entra ID) conditional access
upvoted 2 times
...
RushaShah
5 months, 1 week ago
Selected Answer: B
Answer: B. No The requirement is to enforce Conditional Access rules that combine: 1. MFA (Multi-Factor Authentication) 2. Device compliance (Azure AD-joined device) 3.Location-based access (trusted vs. untrusted locations). Simply going to the Multi-Factor Authentication page and altering user settings will only enable or enforce MFA on the user account, it does not enforce device requirements, it does not apply location-based rules. To meet the requirement, you must configure a Conditional Access policy in Azure AD. That’s where you can specify conditions like "Require MFA" + "Require Hybrid Azure AD-joined or compliant device" + "Apply only to Global Administrators group" + "Exclude trusted locations." So, altering only the MFA settings does not achieve the goal.
upvoted 3 times
...
Barnabe_TEBDA
6 months, 3 weeks ago
Selected Answer: B
No, because, it is not a good solution when we use multi factoer to alter user, but we must use AD.
upvoted 1 times
...
Sahar_A
7 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
Vic_Somi
7 months, 2 weeks ago
Selected Answer: B
This is done using conditional access
upvoted 1 times
...
SherryJamkam
7 months, 3 weeks ago
Selected Answer: B
fails to enforce MFA and Azure AD-joined device requirements for Global Admins in untrusted locations. Thus, it does not meet the goal
upvoted 1 times
...
SherryJamkam
7 months, 3 weeks ago
Selected Answer: B
No, the solution does not meet the goal.
upvoted 1 times
...
Kabilanis
8 months ago
Selected Answer: B
Below are the possible options for this scenario. Consolidating here for easy read of subscribers. Solution: You access the multi-factor authentication page to alter the user settings. - No Solution: You access the Azure portal to alter the session control of the Azure AD conditional access policy. - No Solution: You access the Azure portal to alter the grant control of the Azure AD conditional access policy. - Yes
upvoted 1 times
...
Kabilanis
8 months ago
Selected Answer: B
Below are the options for this question. Commenting here for easy read. Solution: You access the multi-factor authentication page to alter the user settings. - No Solution: You access the Azure portal to alter the session control of the Azure AD conditional access policy. - No Solution: You access the Azure portal to alter the grant control of the Azure AD conditional access policy. - Yes
upvoted 1 times
...
Naru60
8 months, 2 weeks ago
Selected Answer: B
Correctly requires configuration in the “Grant (Access Control)” section
upvoted 1 times
...
ZUMY
8 months, 3 weeks ago
Selected Answer: B
B is the answer
upvoted 1 times
...
kjbalamurugan
9 months, 4 weeks ago
Selected Answer: B
Policy should be configured at group level not at user level
upvoted 1 times
...
Emmanuel25512
10 months ago
Selected Answer: B
Il faut configurer l'accès conditionnel en ajoutant MFA
upvoted 1 times
...
Makaziwe
10 months, 2 weeks ago
Selected Answer: B
Condition access policies aren't confugured on the multi-factor authentication MFA page, to achieve the desired results you'd need to create the conditional access policy in Azure AD specifying access, conditions, access controls.
upvoted 1 times
...
juancarlosdlar
11 months, 1 week ago
Selected Answer: B
You can understand the answer here: https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-azure-mfa?toc=%2Fentra%2Fidentity%2Fconditional-access%2Ftoc.json&bc=%2Fentra%2Fidentity%2Fconditional-access%2Fbreadcrumb%2Ftoc.json
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...