Exam MD-102 All QuestionsBrowse all questions from this exam
Question 12

You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1.

App1 must only accept modern authentication requests.

You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:

Assignments -

Users or workload identities: User1

Cloud apps or actions: App1 -

Access controls -

Grant: Block access -

You need to block only legacy authentication requests to App1.

Which condition should you add to CAPolicy1?

    Correct Answer: E

    To block only legacy authentication requests to App1, you need to target the type of client application used in the authentication request. This can be configured by selecting the 'Client apps' condition in the Conditional Access policy settings. This allows you to specify and block access for legacy authentication clients while permitting modern authentication clients, which is the requirement in this scenario.

Discussion
Gr8GreetOption: E

Seems to be correct. https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/block-legacy-authentication

mohdAjOption: E

Here's a step-by-step guide: Go to the Microsoft 365 admin center. Navigate to "Security" and then "Conditional Access." Create a new Conditional Access policy (CAPolicy1) and configure the following: Assignments: Users or workload identities: User1 Cloud apps or actions: Include App1 Conditions: Client apps: Modern authentication clients Access controls: Grant: Block access

Praveenm2712Option: E

E Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator. Browse to Protection > Conditional Access. Select Create new policy. Give your policy a name. We recommend that organizations create a meaningful standard for the names of their policies. Under Assignments, select Users or workload identities. Under Include, select All users. Under Exclude, select Users and groups and choose any accounts that must maintain the ability to use legacy authentication. Exclude at least one account to prevent yourself from being locked out. If you don't exclude any account, you won't be able to create this policy. Under Target resources > Cloud apps > Include, select All cloud apps. Under Conditions > Client apps, set Configure to Yes. Check only the boxes Exchange ActiveSync clients and Other clients. Select Done. Under Access controls > Grant, select Block access.

veliyathOption: E

To block only legacy authentication requests to App1, you need to target the type of client application used in the authentication request. In Conditional Access policies, this is done using the "Client apps" condition. Therefore, the correct condition to add to CAPolicy1 is: E. Client apps

MR_EliotOption: E

E is correct.

DarkfireOption: E

E is correct 7. Under Conditions > Client apps, set Configure to Yes https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-block-legacy

ubiquituzOption: E

E client apps https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-block-legacy

Amir1909Option: E

Correct

TonskuOption: E

Grant: Block access - client Apps block only legacy authentication

mhmyzOption: E

Correct https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-block-legacy

poppinaz

Correct

Rocky83Option: E

Correct

pindaOption: E

Correct