As an Azure AD administrator, you need to implement a security measure that requires Multi-Factor Authentication (MFA) for users with specific Directory Roles, except when they're logging in from trusted office locations. What is the correct sequence of steps to implement this requirement?