Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam MD-102 Topic 4 Question 47 Discussion

Actual exam question for Microsoft's MD-102 exam
Question #: 47
Topic #: 4
[All MD-102 Questions]

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1.

You discover that User1 can still connect to Exchange Online from an iOS device.

You need to ensure that CAPolicy1 is enforced.

What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: B

Common signals that Conditional Access can take in to account when making a policy decision include the following signals:

* User or group membership

Policies can be targeted to specific users and groups giving administrators fine-grained control over access.

* Device

Users with devices of specific platforms or marked with a specific state can be used when enforcing Conditional Access policies.

Use filters for devices to target policies to specific devices like privileged access workstations.

* Etc.


Contribute your Thoughts:

Glendora
4 days ago
I agree with Carmen, option D seems like the best solution to enforce CAPolicy1.
upvoted 0 times
...
Carmen
5 days ago
I think we should try option D) Add a condition in CAPolicy1 to filter for devices.
upvoted 0 times
...
Emiko
15 days ago
Option B seems like the easiest fix. Just assign the policy to a different group and voila, problem solved. Unless, of course, User1 is secretly a member of Group2 as well.
upvoted 0 times
...
Sunny
17 days ago
Ah, I see the problem. User1 must be using some sort of magic iOS device that's immune to the policy. Maybe we need to call in the Hogwarts tech support team.
upvoted 0 times
Mona
4 days ago
User1 must have a special iOS device.
upvoted 0 times
...
...
Viola
1 months ago
Hmm, it seems like the policy isn't being enforced properly. I'd go with option D and add a condition to filter for devices. That should do the trick.
upvoted 0 times
Miles
26 days ago
User1: I think we should try option D and add a condition to filter for devices.
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77