AZ-500 Secure identity and access Practice Question
Exhibit
Refer to the exhibit.
```json
{
"signInActivity": {
"lastSignInDateTime": "2025-12-01T10:00:00Z",
"lastNonInteractiveSignInDateTime": "2025-12-05T08:30:00Z"
},
"userPrincipalName": "user1@contoso.com",
"userType": "Member",
"isLicensed": true,
"accountEnabled": true
}
```Refer to the exhibit. You are reviewing user sign-in activity using Microsoft Graph API. The user has not performed an interactive sign-in since December 1, but had a non-interactive sign-in on December 5. You need to determine if the user should be considered inactive for a policy that defines inactivity as no interactive sign-in for 30 days. Today is December 15. What should you do?
⚠ Common exam trap
Test-takers frequently confuse 'any sign-in' with 'interactive sign-in' and incorrectly assume non-interactive sign-ins reset the inactivity timer, when the policy explicitly specifies only interactive sign-ins count.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the lastSignInDateTime of December 1, which is only 14 days ago, so the user is not inactive.
The policy defines inactivity as no interactive sign-in for 30 days. The user's last interactive sign-in was on December 1, which is only 14 days ago as of December 15, so the user is not inactive. Microsoft Graph API's lastSignInDateTime property specifically tracks interactive sign-ins, while non-interactive sign-ins are tracked separately via lastNonInteractiveSignInDateTime and do not reset the interactive inactivity timer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check if the user has any sign-in in the last 30 days; since there is a non-interactive sign-in, the user is active.
Why it's wrong here
This option erroneously treats non-interactive sign-ins as evidence of user activity. In Microsoft Entra ID, non-interactive sign-ins represent background authentication events (e.g., token refresh, service principal activity) and are explicitly excluded from inactivity policies that focus on interactive user sign-ins. The policy in question measures lastSignInDateTime, and because the user's last interactive sign-in was 14 days ago, checking 'any sign-in' is both methodologically incorrect and would yield a misleading conclusion.
- ✗
Use the lastNonInteractiveSignInDateTime as the last sign-in time, so the user is not inactive.
Why it's wrong here
The lastNonInteractiveSignInDateTime property tracks background authentication attempts, not real user-driven authentication. These events occur automatically without user credentials being entered, so using them would classify a user as active even if they have not interactively signed in for months. Since the policy specifically references interactive sign-ins, this timestamp is irrelevant for determining inactivity, and the user's actual interactive sign-in was 14 days ago, which is within the 30-day window.
- ✓
Use the lastSignInDateTime of December 1, which is only 14 days ago, so the user is not inactive.
Why this is correct
This is correct because lastSignInDateTime corresponds to the user's last successful interactive sign-in, which occurred on December 1. As of the review date (presumably December 15), that is only 14 days ago—well under the 30-day threshold defined by the policy. Therefore, the user is not inactive, and no further action is required.
- ✗
The user is inactive because the account is enabled but there is no interactive sign-in in the last 30 days.
Why it's wrong here
This option is factually incorrect because it claims the user has no interactive sign-in in the last 30 days, but the data shows an interactive sign-in on December 1 (14 days ago). The account being enabled is irrelevant to the inactivity determination; what matters is the last interactive sign-in timestamp. Since that timestamp falls within the policy's 30-day lookback window, the user is active, not inactive.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.