Plan, implement, and manage Microsoft Entra Conditional Access
Objective conditional.access sits in Implement authentication and access management, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A company assigns a helpdesk technician to review Conditional Access policies in the Microsoft Entra admin center, without making any changes. Which role satisfies the minimum requirement for this task?
The concept
A least-privilege question asks for the smallest role that still completes the task, so the test is not whether a role works but whether a smaller one also would. Read-only tasks are satisfied by reader-tier roles, and any role that can create or edit the object is over-privileged for viewing it. Between two reader roles, the narrower scope wins.
Why this answer
Security Reader is the minimum role documented for locating and viewing Conditional Access policies, matching the read-only task described.
- AGlobal Reader also grants broad read access across the tenant, but it is a higher-privilege role than the documented minimum for this specific task.
- Security Reader is correct: it is the minimum role called out for finding Conditional Access in the admin center.
- CConditional Access Administrator can create and edit policies, which exceeds the read-only need in this scenario.
- DSecurity Administrator can manage security configurations broadly, more than the minimum needed just to view policies.
Now you: objective conditional.access questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An administrator wants a Conditional Access policy that requires multifactor authentication when a user's sign-in risk is calculated as high. Beyond a Microsoft Entra ID P1 license, which license is required to use this risk signal?
Sample question 2 of 3
A Conditional Access administrator wants a policy that requires multifactor authentication whenever Microsoft Entra ID Protection calculates a medium or high sign-in risk. Which license must the tenant have to support this risk-based policy?
Sample question 3 of 3
Contoso configured its Conditional Access policies under a Microsoft Entra ID P1 trial that has since expired. An administrator now tries to edit an existing policy to add a new group. What happens?
Full Identity and Access Admin question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.