Courseiva

AZ-500 · domain

Secure identity and access

This domain covers identity and access security in Microsoft Entra ID: authentication methods, Conditional Access, Privileged Identity Management (PIM), and zero-trust design. AZ-500 tests these through multiple-choice and scenario questions requiring you to select valid configurations, choose two correct actions, and design approval-based role activation.

70 questions21 easy29 medium20 hard

Focused practice

Practice Secure identity and access questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Secure identity and access

You must be able to identify valid Entra ID authentication methods, configure Conditional Access policies correctly, and design PIM with approval-required activation. The most important thing is knowing where each control is configured: role settings for PIM approval, policy assignments for Conditional Access.

Valid Microsoft Entra ID authentication methods including password, certificate-based, and Windows Hello for Business

Conditional Access policy configuration: assignments, conditions, grant controls, and session controls

Privileged Identity Management eligible role assignments, activation approval, and access reviews

Zero-trust identity implementation using Entra ID Protection, risk policies, and least-privilege access

Watch out for

Common Secure identity and access exam traps

  • ▸Confusing authentication methods with authentication strengths, or selecting unsupported methods like security questions as valid Entra ID authentication.
  • ▸Treating PIM eligible assignments as always-active roles; approval is configured on the role setting, not the assignment itself.
  • ▸Assuming Conditional Access applies to all users by default, or mixing up grant controls with session controls in policy design.

Question index

All Secure identity and access questions (70)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO features are available in Microsoft Entra ID Privileged Identity Management (PIM) for managing Azure AD roles? (Choose two.)

Hard
2

Your organization uses Microsoft Entra ID and needs to implement a policy that blocks all sign-ins from countries that are not approved. What should you configure?

Easy
3

Which TWO of the following are capabilities of Microsoft Entra ID Protection?

Medium
4

You are the security administrator for a company that uses Microsoft Entra ID. You need to configure a Conditional Access policy that applies to all users except the emergency break-glass accounts. The policy must require multi-factor authentication (MFA) when accessing the Azure portal from a location that is not trusted. What should you include in the policy?

Medium
5

You need to assign the 'Security Administrator' role in Microsoft Entra ID to a user named User1. The role assignment must be eligible, and User1 must provide a justification when activating the role. What should you use?

Easy
6

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without contacting IT. Which feature should you enable?

Easy
7

Your organization uses Microsoft Entra ID to manage identities. You need to ensure that users can reset their own passwords without help desk intervention, but they must register for self-service password reset (SSPR) first. Which configuration is required?

Easy
8

Which TWO actions should you take to implement a zero-trust identity model using Microsoft Entra ID? (Choose two.)

Medium
9

Your organization uses Microsoft Entra ID and wants to implement a secure passwordless authentication strategy. Which TWO solutions can be used natively in Microsoft Entra ID for passwordless sign-in?

Medium
10

Your company wants to implement a least-privilege model for administrative roles in Microsoft Entra ID. Which TWO features should you use?

Easy
11

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to ensure that all privileged role activations are approved by a manager and require a ticket number. What should you configure in PIM?

Hard
12

You are troubleshooting why a user cannot sign in to a custom line-of-business application that is federated with Microsoft Entra ID. The user reports that they are repeatedly prompted for credentials and then receive an error. The application is configured for SAML-based SSO. What is the most likely cause?

Easy
13

Which TWO of the following are methods to enforce MFA in Microsoft Entra ID?

Medium
14

Your organization uses Microsoft Entra ID to manage access for employees and partners. You need to implement a solution that allows partners to self-service request access to specific applications, with approval from their manager, and access expires after 30 days. Which feature should you use?

Hard
15

Refer to the exhibit. You are reviewing user sign-in activity using Microsoft Graph API. The user has not performed an interactive sign-in since December 1, but had a non-interactive sign-in on December 5. You need to determine if the user should be considered inactive for a policy that defines inactivity as no interactive sign-in for 30 days. Today is December 15. What should you do?

Hard
16

You are designing a privileged access strategy for Microsoft Entra ID. Your organization requires that all users who are assigned to the Global Administrator role must perform a privileged elevation only when needed, and the elevation must be approved by a security officer. Which feature should you implement?

Medium
17

You are a security engineer for a company that uses Microsoft Entra ID. The company has a policy that users must sign in using Windows Hello for Business or a FIDO2 security key. You need to block legacy authentication protocols that do not support these methods. What should you configure?

Medium
18

Which THREE of the following are required to configure Microsoft Entra ID self-service password reset (SSPR)?

Hard
19

You need to ensure that only approved iOS devices can access corporate email. Which Microsoft Intune policy should you configure?

Easy
20

You are designing a Microsoft Entra ID tenant for a multinational organization. The security team requires that all administrative users must use phishing-resistant MFA. Administrators are located in different regions and may use different devices. Which MFA method should you enforce?

Hard
21

Your company uses Microsoft Entra ID and Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with your security policies can access corporate email. You configure a Conditional Access policy targeting Exchange Online. Which grant control should you use?

Medium
22

You are a security administrator for a company that uses Microsoft Entra ID. You need to provide a partner organization with access to specific resources in your tenant. The partner users must use their own credentials, and you must be able to revoke access without managing their accounts. What should you configure?

Hard
23

You have configured the Conditional Access policy shown in the exhibit. Users report that they can still access Exchange Online using legacy authentication protocols. What is the most likely reason?

Medium
24

Your organization uses Microsoft Entra ID. You need to manage access to a line-of-business application that supports SAML 2.0. The application should be integrated as an enterprise application in Entra ID. What steps must you take?

Medium
25

Your organization uses Microsoft Entra ID and requires that all accesses to sensitive applications be approved by the application owner. You need to implement a solution where users can request access to these applications, and the request is automatically routed to the owner for approval. What should you configure?

Hard
26

You are designing a security baseline for Microsoft Entra ID. Which THREE settings are recommended by Microsoft as part of the identity security baseline?

Hard
27

Refer to the exhibit. You are configuring an Entitlement Management access package. The policy allows any existing user to request access without approval, and access expires after 30 days. However, security requirements dictate that all access to Finance applications must be reviewed by the finance team manager every quarter. What should you add to the policy?

Medium
28

You are the identity security engineer for a company that uses Microsoft Entra ID. A new security policy requires that any user who is assigned the Global Administrator role must use a phishing-resistant authentication method when signing in. You need to enforce this requirement with the least administrative effort. What should you do?

Medium
29

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a secure authentication strategy that satisfies the following requirements: - Users must not be able to bypass security verification using alternate authentication methods. - Passwordless authentication should be used where possible. - Legacy authentication protocols must be blocked. Which THREE actions should you take? (Choose three.)

Hard
30

You are configuring Microsoft Entra ID Connect to synchronize on-premises Active Directory identities to the cloud. You need to ensure that password hashes are synchronized to enable Microsoft Entra ID Password Protection and Identity Protection. Which option should you enable?

Easy
31

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using a one-time passcode sent to their mobile device, without requiring any additional app or software installation. Which authentication method should you enable?

Easy
32

Which TWO of the following are valid authentication methods in Microsoft Entra ID?

Easy
33

You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group before activation. What configuration is required?

Medium
34

You are a security engineer for a company that uses Microsoft Entra ID. You need to ensure that all users accessing the company's Salesforce application from unmanaged devices are prompted for multi-factor authentication (MFA) every time. What should you configure?

Easy
35

You are a security administrator for a financial institution. You need to implement a solution that allows users to authenticate using biometrics and prevents password-based attacks. Which Microsoft Entra ID feature should you enable?

Easy
36

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user accounts and enable self-service password reset (SSPR) for cloud users. You have set up Microsoft Entra Connect Sync. Which additional configuration is required to allow password writeback for SSPR?

Hard
37

Your company uses Microsoft Entra ID and has Microsoft Defender for Cloud Apps. You need to monitor and control access to cloud apps based on user behavior. Which feature should you use?

Medium
38

Your company uses Microsoft Entra ID. You need to block sign-ins from countries where your company does not operate. Which approach should you use?

Easy
39

Refer to the exhibit. You are creating a custom Azure RBAC role for a security analyst. The role as shown allows read access to storage accounts. The analyst reports that they cannot read the contents of a blob container in a storage account. Why is this?

Medium
40

Which THREE components are part of Microsoft Entra Conditional Access? (Choose three.)

Hard
41

Which TWO methods can be used to protect privileged accounts in Microsoft Entra ID? (Choose two.)

Medium
42

You are the security architect for a large enterprise that uses Microsoft Entra ID with 50,000 users. The company recently adopted a cloud-first strategy and is migrating on-premises applications to Azure. You need to design a secure identity and access solution that meets the following requirements: - All access to cloud applications must be authenticated using modern authentication protocols. - Legacy authentication protocols (such as POP3, IMAP4, SMTP, and basic authentication) must be blocked. - Users must be required to use multi-factor authentication (MFA) when accessing any application from outside the corporate network. - Administrative access to Azure resources must be time-bound and require approval. - The solution must minimize user friction for internal users on the corporate network. - All sign-in risks must be detected and automatically remediated. You have deployed Microsoft Entra ID P2 licensing and configured Microsoft Defender for Cloud Apps. Which of the following is the most appropriate combination of actions to meet all requirements?

Hard
43

Which TWO of the following are authentication methods supported by Microsoft Entra ID?

Easy
44

Your company deploys Microsoft Sentinel for security operations. You need to configure just-in-time (JIT) access for Azure VMs. Which Azure security feature should you integrate with Sentinel?

Medium
45

Which TWO of the following are required to implement a successful Just-In-Time (JIT) access strategy using Microsoft Entra Privileged Identity Management (PIM) for Azure resources?

Hard
46

Which THREE Microsoft Entra ID roles can be assigned to a user to manage Microsoft Defender XDR (formerly Microsoft 365 Defender) incidents? (Choose three.)

Hard
47

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that automatically detects and remediates identity risks such as leaked credentials and impossible travel. The solution must use built-in Microsoft Entra capabilities without additional licensing beyond Microsoft Entra ID P2. What should you configure?

Medium
48

You need to ensure that external users who are invited to your Microsoft Entra ID tenant via B2B collaboration can only access a specific SaaS application. What should you configure?

Easy
49

Refer to the exhibit. You are analyzing a Conditional Access policy JSON. The policy requires MFA for Office 365 applications. However, users report that they are still able to access Office 365 without MFA. What is the most likely reason?

Medium
50

Which TWO of the following are valid configurations for Microsoft Entra ID Conditional Access policies?

Medium
51

Your company uses Microsoft Entra ID with a hybrid identity model. You need to implement a solution that allows you to block legacy authentication attempts while still allowing modern authentication protocols. What should you use?

Medium
52

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users accessing sensitive data from unmanaged devices are required to use a compliant device. What should you configure?

Medium
53

Which THREE of the following are valid methods to secure service principals in Microsoft Entra ID?

Medium
54

Your organization wants to ensure that users accessing Office 365 from outside the corporate network must use MFA. What is the most efficient way to enforce this?

Easy
55

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage roles. You need to ensure that when a user activates a role, the activation is automatically approved only if the user's manager approves within 30 minutes. If the manager does not respond, the activation is denied. What configuration should you implement?

Hard
56

You are designing a secure access solution for an Azure App Service web application. The application uses Microsoft Entra ID for authentication. You need to ensure that only users from specific partner organizations can access the app. Which configuration should you use?

Medium
57

You are troubleshooting a sign-in issue. A user reports that they are repeatedly prompted for authentication when accessing a cloud app, even though they already authenticated earlier in the day. You check the Conditional Access policy and see that 'Session control - Sign-in frequency' is set to 1 hour. What is the most likely cause?

Medium
58

Your organization uses Microsoft Intune for mobile device management. You need to implement a conditional access policy that only allows access to corporate email from devices that are enrolled in Intune and compliant with security policies. However, the policy is not working for some users who report that they cannot access email even though their devices are compliant. You discover that the users have multiple devices and are signing in from a device that is not enrolled. What should you do?

Hard
59

Your company uses Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with company policies can access corporate resources. You have configured compliance policies in Intune. What additional step is required to enforce access control based on device compliance?

Medium
60

You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How should you configure the policy?

Easy
61

Your company uses Microsoft Entra ID and Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with your security policies can access Exchange Online. The solution must require users to reauthenticate every 12 hours. What should you configure?

Medium
62

You are the identity security engineer for a multinational company that uses Microsoft Entra ID. The company has recently experienced a security breach where an attacker compromised a non-administrator user account and then used that account to enumerate all users in the tenant. The attacker then attempted to brute-force passwords for high-privilege accounts. To prevent such attacks, management requires the following: - Users with administrative roles must use phishing-resistant MFA. - Any sign-in from a risky IP address must be blocked. - Users must not be able to enumerate directory information via the Graph API unless they have a specific role. - The solution should be implemented using built-in Microsoft Entra ID features. What should you configure?

Easy
63

Your company is implementing a zero-trust security model. You need to ensure that all access to cloud applications is continuously verified based on user identity, device health, and location. Which combination of Microsoft security solutions should you use?

Hard
64

You need to ensure that when a user's role in Microsoft Entra ID is changed (e.g., from User to Global Administrator), the change is approved by a manager before it takes effect. Additionally, you need to enforce just-in-time (JIT) access for that role. What should you use?

Easy
65

You are the identity security engineer for a company that uses Microsoft Entra ID. You need to reduce the risk of credential theft for administrative accounts. Which TWO controls should you implement? (Choose two.)

Medium
66

Refer to the exhibit. You run the command and see the output. What does the UserType 'Member' indicate?

Easy
67

Your organization uses Microsoft Entra ID and has deployed Microsoft Defender for Cloud Apps. You need to monitor and control access to cloud applications based on user behavior and device health. Which feature should you use?

Easy
68

Your organization has Microsoft Entra ID and uses Microsoft Copilot for Microsoft 365. You need to ensure that Copilot interactions are logged and accessible for security investigations. What should you configure?

Hard
69

You are troubleshooting an issue where users are unable to access a sensitive application protected by a Conditional Access policy. The policy requires MFA from trusted locations, but users are reporting that they are prompted for MFA even when connecting from the corporate office, which is defined as a trusted location. What is the most likely cause?

Hard
70

Your company uses Microsoft Entra ID (P2 licensed) and requires that all user logins from untrusted networks be blocked unless the user's device is marked as compliant by Microsoft Intune. You need to implement this requirement. Which TWO components should you use together to achieve this? (Choose two.)

Medium

Frequently asked questions

What does the Secure identity and access domain cover on the AZ-500 exam?
You must be able to identify valid Entra ID authentication methods, configure Conditional Access policies correctly, and design PIM with approval-required activation. The most important thing is knowing where each control is configured: role settings for PIM approval, policy assignments for Conditional Access.
How many questions are in this domain?
This page lists all 70 Secure identity and access questions in the AZ-500 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure identity and access questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
az-500 AZ-500 secure identity access Practice Questions