Q: 17
HOTSPOT You have an Azure Active Directory (Azure AD) tenant that has Security defaults disabled. You are creating a conditional access policy as shown in the following exhibit. 
Your Answer
Discussion
Definitely Grant settings for enforcing MFA, Session settings is where you'd set re-authentication intervals.
Grant settings controls requiring MFA, and Session settings is where you configure sign-in frequency stuff. That's how it shows up when making a Conditional Access policy in Azure. I think that's right but open if anyone sees it differently.
Ugh, Microsoft really buries these under similar names. Grant settings sets the MFA requirement, session controls handle stuff like re-auth frequency. Seen a similar question in practice, almost always trips people up.
Grant settings, Session settings
Grant settings is for requiring MFA, while Session settings handle sign-in frequency like forcing re-auth. Pretty sure that's correct from what I've seen in the portal. Let me know if I'm missing something.
Yep, it's Grant settings for MFA and Session settings for re-auth frequency.
Be respectful. No spam.
