AZ-500 Exam QuestionsBrowse all questions from this exam

AZ-500 Exam - Question 76


HOTSPOT -

You work at a company named Contoso, Ltd. that has the offices shown in the following table.

Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com. All contoso.com users have Azure Multi-Factor Authentication (MFA) enabled. The tenant contains the users shown in the following table.

The multi-factor authentication settings for contoso.com are configured as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

Show Answer
Correct Answer:

Discussion

17 comments
Sign in to comment
RameshSesetti
Mar 11, 2021

Answer is : No-No-Yes.

Narragr
Mar 13, 2021

Why the option trusted ip is not checked

xaccan
Mar 14, 2021

Check box is not for trusted ip, it is for federated users

Jimmy500
Nov 25, 2023

There i can not see federated users

Sethoo
Mar 14, 2021

Agree with your answer. The user from Boston (guestion 2)will not be asked for MFA because at present , the IP address from Boston is excluded from MFA requirements

DarkCyberGhost
Jan 20, 2022

But the Checkbox is blank so that function has not been enabled. therefore they will be asked for MFA as the Ip Range is not being excluded.

khengoolman
Feb 8, 2022

Please read the function, it has nothing to do with the IP whitelist. N N Y is correct

LJack
Mar 14, 2021

Agree should be no, no, yes

rockyykrish
Aug 28, 2021

No-Yes-Yes. The second answer will be yes. Skip multifactor authentication for trusted locations is not enabled.

rawrkadia
Aug 30, 2021

That checkbox is to skip MFA for federated intranet locations, simply having IPs or Ranges in the text box for trusted IPs turns it on.

Vikku30
Jan 1, 2022

Then why do they have the check box, I guess we need to check the check-box, is it not the case?

domtopics
Sep 30, 2022

Check box is for when users hit the internal interface of AD FS and receive a token, regardless of public IP address they go to Azure with. IP list is for public IP address they go to Azure with, regardless of how they authenticate.

Pinto
Mar 15, 2021

Box1: No. because user1 had already signed in from device1 and had selected the 14 day period hence, won't be asked for MFA. Box2: No because Boston IP range is trusted. Box3: Yes because new device and Seattle IP is not trusted.

Gesbie
Apr 12, 2023

In Exam April 11, 2023

wardy1983
Nov 15, 2023

Box1: No. because user1 had already signed in from device1 and had selected the 14 day period hence, won't be asked for MFA. Box2: No because Boston IP range is trusted. Box3: Yes because new device and Seattle IP is not trusted.

Kiano
Apr 12, 2024

This is exactly what Pinto said. Why comment when you have no additional information?

heatfan900
Aug 24, 2023

N = USER 1 CHECKED THE 'DON NOT ASK ME FOR 14 DAYS' CHECKBOX N = USER 2 IS SIGNING IN FROM A TRUSTED LOCATION WHICH BYPASSES MFA Y = USER 1 SIGNING IN AFTER THE 14 DAYS FROM A UNTRUSTED LOCATION.

xRiot007
Jul 16, 2024

Wrong. It's Yes because user is signing in using a new device, not from an untrusted location.

xRiot007
Jul 16, 2024

Ignore first reply. Unstrusted location seems to be medium.

fonte
Jan 14, 2023

Hi all, Passed my exam (13JAN2023) with 918. 50 questions (45 + 5 of a case study). Around 95% of the questions are here. I've compiled the questions and my answers in a ppt, feel free to check it out and hope it helps. https://www.dropbox.com/s/ay00xp2fnloq1ex/AZ%20500%20-%20Exam%20Topics.pptx?dl=0 Use pass az500prep to open the file. Thanks to all the people that comment on questions, I wouldn't have passed without them :)

Tweety1972
May 1, 2023

Doesn't work

ArchitectX
Sep 15, 2023

No-No-Yes

josh_josh
Dec 31, 2022

The trusted IPs feature of Azure AD Multi-Factor Authentication bypasses multi-factor authentication prompts for users who sign in from a defined IP address range. You can set trusted IP ranges for your on-premises environments. When users are in one of these locations, there's no Azure AD Multi-Factor Authentication prompt.

majstor86
Mar 2, 2023

NO NO YES

pekay
Apr 2, 2023

the answer is no no yes

TheProfessor
Sep 18, 2023

NNY is the answer. Boston's IPs are trusted.

Obama_boy
Dec 8, 2023

in exam 08/12/23

F117A_Stealth
Nov 8, 2022

Box1: No. because user1 had already signed in from device1 and had selected the 14 day period hence, won't be asked for MFA. Box2: No because Boston IP range is trusted. Box3: Yes because new device and Seattle IP is not trusted.

gschneck
Dec 16, 2022

On test 12/16/2022

r_git
Mar 16, 2023

No = User1 on Device1 selected Don't ask again for 14 days on June 1. No = User2 on Device2 signs in from the Boston office IP address subnet 180.15.10.0/24 which is added in trusted ips textbox https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips Yes = User1 signs in to a new device which triggers MFA since it is a new sign in from a new device. The previous 14 days selection was tied to session on Device1

zellck
May 7, 2023

NNY is the answer. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips The trusted IPs feature of Azure AD Multi-Factor Authentication bypasses multi-factor authentication prompts for users who sign in from a defined IP address range. You can set trusted IP ranges for your on-premises environments. When users are in one of these locations, there's no Azure AD Multi-Factor Authentication prompt. The trusted IPs feature requires Azure AD Premium P1 edition.

zellck
May 7, 2023

https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#remember-multi-factor-authentication The remember multi-factor authentication feature lets users bypass subsequent verifications for a specified number of days, after they've successfully signed in to a device by using MFA. To enhance usability and minimize the number of times a user has to perform MFA on a given device, select a duration of 90 days or more.

Jimmy500
Nov 25, 2023

Check box is not picked for second one

ESAJRR
Jul 11, 2023

No-Yes-Yes. The second answer will be yes. Skip multifactor authentication for trusted locations is not enabled.