Courseiva

AZ-500 · topic practice

Secure identity and access practice questions

This domain covers identity and access security in Microsoft Entra ID: authentication methods, Conditional Access, Privileged Identity Management (PIM), and zero-trust design. AZ-500 tests these through multiple-choice and scenario questions requiring you to select valid configurations, choose two correct actions, and design approval-based role activation.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Secure identity and access

What the exam tests

What to know about Secure identity and access

You must be able to identify valid Entra ID authentication methods, configure Conditional Access policies correctly, and design PIM with approval-required activation. The most important thing is knowing where each control is configured: role settings for PIM approval, policy assignments for Conditional Access.

Valid Microsoft Entra ID authentication methods including password, certificate-based, and Windows Hello for Business

Conditional Access policy configuration: assignments, conditions, grant controls, and session controls

Privileged Identity Management eligible role assignments, activation approval, and access reviews

Zero-trust identity implementation using Entra ID Protection, risk policies, and least-privilege access

Watch out for

Common Secure identity and access exam traps

  • ▸Confusing authentication methods with authentication strengths, or selecting unsupported methods like security questions as valid Entra ID authentication.
  • ▸Treating PIM eligible assignments as always-active roles; approval is configured on the role setting, not the assignment itself.
  • ▸Assuming Conditional Access applies to all users by default, or mixing up grant controls with session controls in policy design.

Practice set

Secure identity and access questions

20 questions · select your answer, then reveal the explanation

Your company has a Microsoft Entra ID tenant and uses Azure AD Application Proxy to publish on-premises web apps. Users report that they are prompted for their password every time they access the app, even though they selected 'Keep me signed in'. You need to improve the sign-in experience without compromising security. What should you configure?

Your organization is implementing a zero-trust security model using Microsoft Entra ID. You need to ensure that all access requests to sensitive applications are evaluated in real-time based on user behavior and device posture before granting access. Which Microsoft Entra ID feature should you use?

Your company uses Microsoft Entra ID Governance features for access reviews. You need to ensure that guest users who do not sign in for 90 days are automatically removed from access to a critical application. The removal should happen without manual intervention. What should you configure?

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a secure authentication method that reduces password-related risks. The solution must support users signing in from unmanaged devices without installing any software. Which authentication method should you prioritize?

Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to implement a solution that detects password changes on-premises and forces re-authentication for active sessions within minutes. Which feature should you enable?

Which TWO of the following are capabilities of Microsoft Entra ID Protection?

Refer to the exhibit. You are reviewing the output of the Get-AzureADGroup PowerShell cmdlet. You need to create a Conditional Access policy that dynamically includes users based on their department attribute set to 'Finance'. Which group should you use in the policy?

Exhibit

Refer to the exhibit.

Get-AzureADGroup -Top 5 | ConvertTo-Json
[
  {
    "ObjectId": "11111111-1111-1111-1111-111111111111",
    "DisplayName": "All Users",
    "SecurityEnabled": true,
    "MailEnabled": false,
    "GroupTypes": []
  },
  {
    "ObjectId": "22222222-2222-2222-2222-222222222222",
    "DisplayName": "Administrators",
    "SecurityEnabled": true,
    "MailEnabled": false,
    "GroupTypes": ["DynamicMembership"]
  },
  {
    "ObjectId": "33333333-3333-3333-3333-333333333333",
    "DisplayName": "External Users",
    "SecurityEnabled": true,
    "MailEnabled": false,
    "GroupTypes": []
  },
  {
    "ObjectId": "44444444-4444-4444-4444-444444444444",
    "DisplayName": "Finance Team",
    "SecurityEnabled": true,
    "MailEnabled": false,
    "GroupTypes": []
  },
  {
    "ObjectId": "55555555-5555-5555-5555-555555555555",
    "DisplayName": "Sales Team",
    "SecurityEnabled": true,
    "MailEnabled": false,
    "GroupTypes": ["DynamicMembership"]
  }
]

Your organization uses Microsoft Entra ID for identity management. You need to prevent users from using their work accounts to access corporate resources from untrusted locations unless they have registered their devices. Which conditional access policy setting should you configure?

You are implementing Microsoft Entra ID Protection. You need to detect and respond to risky user behaviors such as leaked credentials and anonymous IP address usage. Which feature should you enable?

Your organization uses Microsoft Entra ID and wants to provide external partners with access to a specific SharePoint Online site. You need to ensure that partners authenticate using their own corporate credentials (SAML/WS-Fed) and that access is automatically revoked when the partner's account is disabled. Which solution should you use?

Refer to the exhibit. A Microsoft Entra ID Conditional Access policy is defined as shown. You observe that the policy is blocking all users from accessing email via Exchange ActiveSync, but users can still access email via Outlook for iOS. What is the most likely reason?

Exhibit

{
  "policy": {
    "tenantId": "contoso.onmicrosoft.com",
    "displayName": "Block legacy authentication",
    "conditions": {
      "clientAppTypes": ["exchangeActiveSync", "other"],
      "applications": {
        "includeApplications": ["All"]
      },
      "users": {
        "includeUsers": ["All"]
      },
      "locations": {
        "includeLocations": ["All"]
      }
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}

Which TWO actions should you perform to implement Microsoft Entra ID Password Protection for an on-premises Active Directory environment? (Choose two.)

Which THREE conditions can be used in a Microsoft Entra ID Conditional Access policy to control access based on sign-in risk? (Choose three.)

Question 14mediummultiple choice
Study the full multicast explanation →

Refer to the exhibit. You are configuring a PIM role setting for an Azure AD role. The exhibit shows the activation settings. A user activates the role and provides a justification. An approver from the Security Team does not see any pending requests. What is the most likely reason?

Exhibit

{
  "properties": {
    "assignmentType": "Eligible",
    "duration": "P1D",
    "justificationRequired": true,
    "approvalRequired": true,
    "approvers": [
      {
        "id": "12345",
        "displayName": "Security Team"
      }
    ]
  }
}

Refer to the exhibit. You run the PowerShell cmdlet Get-AzureADPolicy for a tenant. Based on the output, what is the access token lifetime for this policy?

Exhibit

Get-AzureADPolicy | Format-List Id, DisplayName, Definition

Id           : aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee
DisplayName  : TokenLifetimePolicy
Definition   : {"TokenLifetimePolicy":{"Version":1,"AccessTokenLifetime":"01:00:00","MaxAgeSingleFactor":"06:00:00","MaxAgeMultiFactor":"12:00:00"}}

You manage a Microsoft Entra ID tenant for a multinational company. Users in the European office report that they cannot access the company's custom line-of-business application during peak hours, while users in the US office have no issues. The application uses OAuth 2.0 authentication with Conditional Access policies applied. What is the most likely cause?

Your organization has a Microsoft Entra ID tenant with 50,000 users. You are designing a solution to automatically revoke access for users who have not signed in for 90 days. The solution must be cost-effective and use built-in Microsoft Entra ID features. What should you do?

Your organization uses Microsoft Entra ID and has several applications registered. You need to ensure that only specific applications can call a particular web API. The web API is also registered in Microsoft Entra ID. What should you configure?

Your company uses Microsoft Entra ID and Microsoft Sentinel. You need to detect when a user account is created outside of normal business hours (9 AM - 5 PM local time) and automatically suspend the account. What should you use?

You need to ensure that external users who are invited to collaborate via Microsoft Entra B2B can only access the applications assigned to them. Which configuration should you use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Secure identity and access sessions

Start a Secure identity and access only practice session

Every question in these sessions is drawn from the Secure identity and access domain — nothing else.

Related practice questions

Related AZ-500 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-500 exam test about Secure identity and access?
You must be able to identify valid Entra ID authentication methods, configure Conditional Access policies correctly, and design PIM with approval-required activation. The most important thing is knowing where each control is configured: role settings for PIM approval, policy assignments for Conditional Access.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Secure identity and access questions in a focused session?
Yes — the session launcher on this page draws every question from the Secure identity and access domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-500 topics?
Use the topic links above to move to related areas, or go back to the AZ-500 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-500 exam covers. They are not copied from any real exam or dump site.