A company wants to ensure that Entra ID guests (external collaborators) who access Microsoft 365 Copilot are subjected to the same MFA and compliant device requirements as internal employees. Which Entra ID Conditional Access configuration achieves this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Entra Conditional Access allows targeting of 'Guest or external users' as a specific user category. By creating a policy scoped to this category, targeting the Copilot application, and requiring MFA and compliant device, the organization ensures external collaborators face the same access controls as internal employees.
Full explanation below image
Full Explanation
A is correct because Microsoft Entra Conditional Access allows targeting of 'Guest or external users' as a specific user category. By creating a policy scoped to this category, targeting the Copilot application, and requiring MFA and compliant device, the organization ensures external collaborators face the same access controls as internal employees. B is wrong because Entra ID Protection can be applied to guests but it is risk-based and reactive; it does not proactively enforce MFA and compliant device on every sign-in. C is wrong because trusting MFA and device claims from a guest's home tenant allows their existing MFA to count—it does not enforce your organization's MFA requirement or device compliance posture specifically. D is wrong because adding individual guests to a policy is not scalable and does not automatically apply to future guests; targeting the 'Guest or external users' category scales automatically.