Free Actual MS-102 Actual Exam Questions – Microsoft 365 Administrator - Question 6 Discussion

Question No. 6

HOTSPOT You have a Microsoft 365 E5 subscription. You need to create a Conditional Access policy that will require the use of FID02 security keys only when users join their Windows devices to Microsoft Entra ID. How should you configure the policy? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point. MS-102 practice exam questions

US
UE
Usman E.
2026-02-21

Option B for cloud apps, and require FIDO2 in grant controls.

0
MB
Mason B.
2026-02-18

I noticed that under "Cloud apps or actions," there’s an option called "Device registration" which seems to cover device join scenarios. If we pick that, it should target the join process specifically. Then for "Grant," choosing "Require multi-factor authentication" combined with "Require authentication strength" set to FIDO2 should enforce using FIDO2 keys only. Also, make sure the policy targets Windows devices under "Conditions > Device platforms" so it doesn’t apply to other OSes. This approach narrows down the policy exactly to Windows device join with FIDO2 keys.

0
KV
Kevin V.
2026-01-23

Selecting MFA for ‘Grant controls’ restricts it to FIDO2 when combined with the right conditions.

0
KV
Kevin V.
2026-01-17

Is there a way to specify FIDO2 keys only for device join in the policy settings?

0