Courseiva

AZ-500 Secure identity and access Practice Question

You are designing a security baseline for Microsoft Entra ID. Which THREE settings are recommended by Microsoft as part of the identity security baseline?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft's general best practices (like self-service group management) with the specific, hardened settings in the identity security baseline, which prioritizes risk-based controls and blocking legacy protocols over convenience features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable risk-based Conditional Access policies

Risk-based Conditional Access policies are a core recommendation in the Microsoft identity security baseline. These policies automatically respond to detected user or sign-in risks (e.g., anonymous IP, leaked credentials) by requiring MFA or blocking access, aligning with the Zero Trust principle of continuous verification. Microsoft explicitly includes risk-based policies in its security baseline to proactively mitigate identity threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable risk-based Conditional Access policies

    Why this is correct

    Risk-based Conditional Access policies are a core component of a security baseline because they dynamically evaluate sign-in risk and user risk in real time, enabling automatic remediation actions such as requiring MFA, blocking access, or forcing password change for compromised identities. Unlike static policies, these adapt to evolving threat signals like anonymous IP addresses, impossible travel, or atypical sign-ins, thereby reducing the attack surface without permanently disrupting legitimate users. In a baseline, this should be configured with risk thresholds (e.g., medium or higher for user risk) and paired with registration campaigns for combined security information.

  • ✗

    Allow self-service group management for all users

    Why it's wrong here

    Allowing self-service group management for all users in Entra ID is outside the scope of a security baseline and can introduce privilege escalation paths if not tightly governed. When unrestricted, any user can create or join security groups, potentially granting themselves access to resources governed by group membership, which weakens the principle of least privilege. Baselines typically restrict group creation to specific administrators or use approval workflows, and while self-service may be useful for collaboration, it must be accompanied by group expiration, access reviews, and owner accountability to avoid security drift.

  • ✗

    Set sign-in session timeout to 8 hours

    Why it's wrong here

    Setting a sign-in session timeout to 8 hours is not a recognized security baseline control for Entra ID because session lifetime is fundamentally a user experience and token management setting, not a baseline security enforcement mechanism. Baselines focus on risk-based and conditional access controls, not on arbitrary session durations; an 8-hour timeout could be too permissive for high-risk workloads and too restrictive for others, and it does not mitigate real-time threats like token replay or compromised devices. Properly, session controls should be configured per policy using sign-in frequency (e.g., 1 hour for privileged roles) or persistent browser session settings, not as a global baseline rule.

  • ✓

    Enable MFA for all Global Administrators

    Why this is correct

    Enabling MFA for all Global Administrators is a mandatory, baseline security control because these accounts hold unrestricted access to the Entra ID tenant, and a compromise would be catastrophic. The baseline requires phishing-resistant MFA (e.g., FIDO2, Windows Hello for Business) or at least strong MFA methods, and it should be enforced with Conditional Access or security defaults to block sign-in if MFA is not satisfied. Additionally, Global Administrators should be covered by risk-based policies and Privileged Identity Management (PIM) to require just-in-time activation, ensuring MFA is always challenged at the highest privilege level.

  • ✓

    Block legacy authentication protocols

    Why this is correct

    Blocking legacy authentication protocols (e.g., IMAP, POP, SMTP, and older Exchange Online endpoints) is a baseline requirement because these protocols do not support MFA or modern conditional access, making them the primary vector for password spray and credential stuffing attacks. Attackers bypass baseline controls by relaying tokenless legacy auth requests, so the baseline mandates blocking such protocols at the tenant level via Conditional Access or the Exchange Online authentication policy. This aligns with Microsoft's guidance that blocking legacy auth is a first step to securing identities, and it forces apps to modernize to OAuth 2.0 and Web Account Manager.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.