AZ-500 Secure identity and access Practice Question
You are the identity security engineer for a company that uses Microsoft Entra ID. You need to reduce the risk of credential theft for administrative accounts. Which TWO controls should you implement? (Choose two.)
⚠ Common exam trap
The trap here is assuming that password expiration policies or self-service password reset reduce credential theft, when they mainly address password age and recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require passwordless authentication methods such as FIDO2 security keys for administrators.
Passwordless authentication removes the password as a stealable secret, and banned password lists prevent weak or predictable passwords from being set. Together they reduce the likelihood that an administrative credential can be phished, guessed, or reused, which directly addresses credential theft risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a long password expiration interval of 730 days for administrator accounts.
Why it's wrong here
Longer password expiration does not reduce credential theft; it may increase exposure if a password is compromised. Microsoft recommends removing periodic password expiration for cloud-only accounts when other protections such as MFA and banned password lists are in place.
- ✗
Assign the Privileged Authentication Administrator role to a shared helpdesk account.
Why it's wrong here
Assigning a highly privileged role to a shared account increases risk because shared credentials cannot be attributed and are harder to protect. This role can reset credentials for privileged users, so using it on a shared account expands the attack surface rather than reducing credential theft.
- ✓
Require passwordless authentication methods such as FIDO2 security keys for administrators.
Why this is correct
Passwordless methods remove the shared secret from the sign-in process, so there is no password to phish or steal. Requiring FIDO2 or Windows Hello for Business for administrators significantly reduces credential theft risk because the credential is bound to a device and cannot be replayed.
- ✗
Enable self-service password reset for all administrator accounts.
Why it's wrong here
Self-service password reset helps users recover access but does not prevent credential theft. It can even introduce risk if weak authentication methods are allowed for reset, so it is not a primary control for protecting administrative credentials.
- ✓
Enable Microsoft Entra Password Protection with a custom banned password list.
Why this is correct
Password protection with a custom banned list prevents users from setting easily guessed or organization-specific weak passwords. For administrative accounts, this reduces the chance that a stolen or guessed password can be used, directly lowering credential theft risk.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.