Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization wants to enhance security for its Azure environment. An administrator needs to ensure that all administrators are required to use Multi-Factor Authentication (MFA) specifically when accessing administrative tools like the Azure portal and Azure CLI.
Which Microsoft Entra ID capability should the administrator configure to enforce this requirement based on targeted user assignments and cloud applications?
Conditional Access is the zero-trust policy engine in Microsoft Entra ID (formerly Azure AD) that evaluates real-time signals and conditions before granting access to organizational resources. It serves as an intelligent gatekeeper that balances security requirements with user productivity.
Conditional Access allows administrators to create granular rules specifying who (assignments such as administrative users or directory roles), what (target cloud apps and resources such as the Windows Azure Service Management API or Microsoft Admin Portals), and under what conditions access is requested. Under Access controls > Grant, administrators can specifically enforce Require multifactor authentication, ensuring that MFA verification is triggered whenever administrative portals are accessed.
Using Conditional Access policies is the recommended method to enforce MFA dynamically for privileged administrative tools without disrupting regular end-user workflows across unrelated applications.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.