Contoso requires MFA when users access Microsoft 365 from outside corporate IP ranges, but not from trusted office IPs. How should this be implemented?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Named locations = home base IPs. Conditional Access: leave home base → MFA.
Full explanation below image
Full Explanation
Correct Answer — B
Named locations define trusted IPs; CA requires MFA when not from those locations. Full block is not MFA. Disabling modern auth breaks apps. Global Reader is a role, not MFA.
Exam tip: Trusted IPs + MFA elsewhere → CA + named locations.