AZ-500 Secure identity and access Practice Question
Your organization uses Microsoft Entra ID to manage identities. You need to ensure that users can reset their own passwords without help desk intervention, but they must register for self-service password reset (SSPR) first. Which configuration is required?
⚠ Common exam trap
Many exam-takers confuse enabling SSPR with enforcing registration, or mistakenly think that combined registration or PIM automatically requires registration, when in fact only the registration campaign configuration forces the user to register before using SSPR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSPR and set the registration campaign to require registration at next sign-in
Enabling SSPR and configuring the registration campaign to require registration at next sign-in ensures users must register for SSPR before they can reset their own passwords. This satisfies the requirement that users register first, and the registration campaign enforces this without requiring help desk intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Entra Password Protection
Why it's wrong here
Microsoft Entra Password Protection enforces password policies by screening all password changes and resets against the global banned password list and custom banned lists, but it does not create any self-service reset workflow. It only blocks weak passwords; it has no portal, no registration process, and no ability for a user to verify identity and reset a forgotten password. Therefore, while it can be used alongside SSPR for security, it cannot deliver SSPR on its own.
- ✗
Enable Privileged Identity Management for SSPR
Why it's wrong here
Privileged Identity Management (PIM) provides time-based and approval-based role activation, access reviews, and PIM alerts for Microsoft Entra ID roles, but it is designed for privileged administrators, not end-user password reset. Enabling PIM only changes how privileged roles are activated; it doesn't give regular users a self-service password reset experience or configure authentication method registration. Even if PIM is active, an ordinary user who forgot their password still has no way to regain access through PIM.
- ✓
Enable SSPR and set the registration campaign to require registration at next sign-in
Why this is correct
Self-Service Password Reset requires users to first register authentication methods — such as phone numbers, the Microsoft Authenticator app, or email addresses — so those methods can be challenged during reset. By enabling SSPR and setting the registration campaign to require registration at next sign-in, the directory ensures users are prompted to register before they need a reset, which is the critical success factor for SSPR adoption. This is the correct configuration because an SSPR policy is meaningless if users have no registered methods to verify their identity.
- ✗
Enable combined registration for SSPR and Microsoft Entra ID Protection
Why it's wrong here
Combined registration lets users register for both Microsoft Entra ID Protection (MFA) and SSPR in a single consolidated workflow, but it is merely a registration experience and does not itself enable password reset. SSPR still must be explicitly enabled in the Password reset blade, and users must be included in the SSPR-enabled group; ID Protection is a separate risk-detection service that can trigger a password reset for risky users but isn't the mechanism that allows a user to reset a forgotten password. Thus, combined registration is a nice-to-have convenience, not the required action to enable SSPR.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.