Microsoft 365 Administrator — Question 125

You have a Microsoft 365 E5 subscription that contains users in the United States, Europe, and Asia.

You use Azure AD Identity Protection.

You have a virtual desktop infrastructure (VDI). All VDI servers are located in the United States.

Users connect to Microsoft 365 from laptops and the VDI.

Some VDI users report that they are blocked from signing in to Microsoft 365 due to a high sign-in risk.

You need to reduce the likelihood that the VDI users will be erroneously blocked from signing in to Microsoft 365. The solution must ensure that sign-ins from the VDI environment are protected by using Identity Protection.

What should you configure?

Answer options

Correct answer: B

Explanation

Configuring a trusted location allows you to mark the VDI environment as safe, reducing the risk of erroneous sign-in blocks. ExpressRoute and Conditional Access policies may provide additional security or connectivity but do not specifically address the issue of reducing sign-in risk for the VDI users. A Satellite Geography location is not applicable in this context and does not resolve the problem at hand.