Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 676–712

712 questions total · 10pages · All types, answers revealed

Page 9

Page 10 of 10

676
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to automate the removal of access when an employee leaves the company. The identity lifecycle should trigger access reviews and automatic deprovisioning. What should you configure?

A.Microsoft Entra Entitlement Management
B.Microsoft Entra Lifecycle Workflows
C.Microsoft Entra Access Reviews
D.Microsoft Entra Privileged Identity Management
AnswerB

Microsoft Entra Lifecycle Workflows directly orchestrates joiner, mover, leaver, and post-arbitration workflows using built-in tasks arranged in a configurable schedule. For deprovisioning, it can trigger on an employee's leave date (for example, employeeLeaveDateTime) to disable the account, block sign-in, revoke sessions, remove licenses, and delete the user or send a manager email. Because it is event-driven by HR attributes and runs without manual intervention, it is the only option that automates the entire lifecycle from onboarding through offboarding.

Why this answer

Microsoft Entra Lifecycle Workflows is the correct choice because it is specifically designed to automate the entire identity lifecycle, including the removal of access when an employee leaves. It can trigger access reviews and automatically deprovision accounts and group memberships based on joiner, mover, and leaver scenarios, integrating with HR systems like Workday or SuccessFactors.

Exam trap

The trap here is that candidates often confuse Entitlement Management (which handles access packages) with Lifecycle Workflows (which handles the full lifecycle automation), or they think Access Reviews alone can automate deprovisioning, when in fact Access Reviews only provide attestation without execution of removal actions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Entitlement Management manages access packages and approval workflows for resource access, but it does not automate the full identity lifecycle deprovisioning triggered by employee departure events. Option C is wrong because Microsoft Entra Access Reviews only provides periodic review and attestation of access, not automated deprovisioning or lifecycle triggers. Option D is wrong because Microsoft Entra Privileged Identity Management focuses on just-in-time privileged role activation and approval, not on automating the removal of all access for departing employees.

677
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only compliant devices can access Microsoft 365 resources. What should you configure?

A.Configure an app protection policy in Intune.
B.Create a device compliance policy in Intune.
C.Configure a Windows Hello for Business policy in Intune.
D.Create a conditional access policy in Microsoft Entra ID requiring compliant devices.
AnswerD

To demand that managed Windows 10 devices be compliant before they access cloud resources, create a Conditional Access policy in Microsoft Entra ID. In the Grant section, select the 'Require device to be marked as compliant' control; this reads the last-known compliance status that Intune reports to Microsoft Entra ID and blocks sign-in if the device is not compliant or is unknown. This grant control works alongside your Intune compliance policies to enforce access decisions at sign-in time. This is the only option listed that actually enforces a device-compliancy requirement.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) are the mechanism that enforces access controls based on signals such as device compliance. By creating a policy that requires compliant devices, you ensure that only devices meeting your compliance standards can access Microsoft 365 resources. This works in conjunction with Intune compliance policies, but the enforcement point is the Conditional Access policy.

Exam trap

The trap here is that candidates often confuse the role of Intune compliance policies (which only define and report compliance) with Conditional Access policies (which enforce access decisions), leading them to select Option B instead of D.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection at the application level without requiring device enrollment or compliance; they do not block access to Microsoft 365 resources based on device compliance. Option B is wrong because a device compliance policy in Intune defines the compliance requirements (e.g., encryption, OS version) but does not itself enforce access restrictions; it only marks the device as compliant or non-compliant. Option C is wrong because Windows Hello for Business policy configures biometric or PIN-based authentication on devices, but it does not control access to Microsoft 365 resources based on device compliance.

678
MCQmedium

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Teams. You need to prevent external users from being added to sensitive teams that contain financial data. What should you configure?

A.A sensitivity label for containers that blocks guest access.
B.Azure AD Conditional Access policy for guest users.
C.An information barrier policy between finance and external.
D.A DLP policy for Teams chat and channel messages.
AnswerA

A container sensitivity label enforces its protection settings on the connected Microsoft 365 group, so configuring it to block guest access prevents external users from being added to the team. This directly satisfies the requirement to keep guests out of sensitive teams holding financial data.

Why this answer

Sensitivity labels for containers (groups and sites) can be configured to block guest access, which directly prevents external users from being added to Teams that contain sensitive data. This is the most targeted and appropriate control because it enforces protection at the container level based on the label applied to the team. Conditional Access policies control access based on user, device, and location conditions but do not prevent guests from being added to a team.

Information barriers prevent specific users from communicating with each other but are not designed to block all external users from a team. DLP policies protect content but do not prevent membership additions.

Exam trap

MS-102 often tests the confusion between content protection (DLP) and container-level access controls; candidates might choose DLP or Conditional Access when the requirement is to prevent guests from being added to a team, which is specifically handled by sensitivity labels for containers.

How to eliminate wrong answers

Option B is wrong because Azure AD Conditional Access policies govern authentication and authorization for users accessing resources, but they do not control the membership of a Microsoft 365 group or team; a guest could still be added even if they cannot access due to Conditional Access. Option C is wrong because information barriers are used to restrict communication between specific segments of users within an organization, not to block external guests from being added to a team; they are for internal ethical walls. Option D is wrong because DLP policies for Teams chat and channel messages monitor and protect sensitive information in messages, but they do not prevent external users from being added to a team; they might block sharing of content but not membership.

679
MCQhard

A compliance officer needs to automatically identify and label content that is conceptually similar to existing sensitive documents, such as internal strategy memos or proprietary technical specifications, without relying on explicit keywords or recognized sensitive information types. Which Microsoft Purview solution should the officer use to achieve this?

A.trainable classifier
B.sensitive information type
C.An auto-labeling policy with a retention label
D.Data Loss Prevention (DLP) policy that blocks sharing
AnswerA

Trainable classifiers are designed to identify content based on examples and can learn to recognize documents that are conceptually similar, such as internal memos or proprietary specs, without needing exact keywords or predefined sensitive info types.

Why this answer

A trainable classifier uses machine learning to identify content based on patterns and context learned from sample documents, making it ideal for recognizing conceptually similar content without relying on explicit keywords or predefined sensitive information types. This allows the compliance officer to automatically label internal strategy memos or proprietary technical specifications that share conceptual similarity with existing sensitive documents.

Exam trap

The trap here is that candidates often confuse trainable classifiers with sensitive information types, assuming that keyword or regex-based patterns are sufficient for conceptual similarity, when in fact trainable classifiers are the only Microsoft Purview solution that uses machine learning to identify content based on learned patterns rather than explicit rules.

How to eliminate wrong answers

Option B is wrong because sensitive information types rely on predefined patterns (e.g., regex, keywords, checksums) and cannot identify conceptually similar content without explicit keywords or recognized types. Option C is wrong because an auto-labeling policy with a retention label applies labels based on conditions like sensitive info types or trainable classifiers, but the retention label itself does not perform conceptual identification; the labeling policy would still require a trainable classifier to trigger. Option D is wrong because a Data Loss Prevention (DLP) policy that blocks sharing can use classifiers or sensitive info types to enforce actions, but it is a protective control, not a labeling solution for automatic identification and labeling of conceptually similar content.

680
MCQeasy

Refer to the exhibit. You have a Conditional Access policy configured as shown. What is the effect of this policy?

A.It requires multi-factor authentication for trusted IPs.
B.It blocks access from all locations.
C.It blocks access from untrusted IP addresses.
D.It blocks access from trusted IP addresses.
AnswerD

This is correct. The policy is scoped to the location condition 'All trusted IPs' and its access control is set to Block. When a user signs in from an IP address that falls within the configured trusted-IP range, the policy condition is satisfied and access is denied. This demonstrates that a 'trusted' network can still be blocked in Conditional Access when the grant control is Block rather than a permissive Grant control.

Why this answer

The policy is configured to 'Block access' for 'All users' and 'All cloud apps' when the location condition is set to 'Trusted IPs'. This means that when a user attempts to access from an IP address defined as trusted in the organization's named locations, access is explicitly blocked. The effect is that trusted IP addresses are blocked, not untrusted ones.

Exam trap

The trap here is that candidates mistakenly think 'Block access' combined with 'Trusted IPs' blocks untrusted IPs, when in fact the policy explicitly blocks the trusted IPs, leaving untrusted IPs unaffected by this policy.

How to eliminate wrong answers

Option A is wrong because the policy is set to 'Block access', not 'Grant access requiring multi-factor authentication', so it does not enforce MFA for any location. Option B is wrong because the policy only applies to the 'Trusted IPs' location condition, not to 'All locations' or 'Any location', so it does not block access from all locations. Option C is wrong because the policy targets 'Trusted IPs', not 'Untrusted IPs'; untrusted IPs are not affected by this policy and would fall through to other policies or default behavior.

681
MCQeasy

You need to monitor which users have accessed a specific document stored in SharePoint Online over the last 90 days. What should you use?

A.Data Loss Prevention reports.
B.eDiscovery (Premium) case.
C.Content search in Microsoft Purview.
D.Audit log search in Microsoft Purview.
AnswerD

Audit log search in Microsoft Purview retains SharePoint Online file-access events for 90 days by default, letting you filter on the specific document and retrieve the users who opened it. This directly satisfies the 90-day historical access requirement, which standard SharePoint site analytics cannot provide.

Why this answer

Audit log search in Microsoft Purview is the correct tool because it queries the unified audit log, which records user activities such as file access, download, and sharing events across SharePoint Online and OneDrive for Business. The 'Accessed file' and 'FileAccessed' operations are captured with the user identity, timestamp, and item path, allowing you to filter by date range (up to 90 days by default, extendable to 1 year with the right license) and by the specific document URL. This directly answers the requirement to see *who* accessed a *specific document* over a defined period.

Exam trap

MS-102 often tests the confusion between content discovery tools (Content search, eDiscovery) that find *what* is in a file versus activity auditing tools (Audit log search) that reveal *who did what*—candidates incorrectly pick Content search because it also lives in Microsoft Purview and can target a specific document.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention reports surface policy match events (e.g., sensitive info types detected in content) and alert volumes, not a per-user access history of a specific file; DLP does not log every read of a document unless a policy explicitly triggers. Option B is wrong because an eDiscovery (Premium) case is designed for legal hold, custodial data collection, review sets, and analytics for litigation—it can search content but does not provide an access-audit trail of who opened a file and when. Option C is wrong because Content search in Microsoft Purview queries the content index (keywords, properties, sensitive info types) to find items, not to report user access events; it returns the documents themselves, not the activity log.

682
MCQeasy

Your organization uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) for email and collaboration content. Which policy type should you configure in the Microsoft 365 Defender portal?

A.Attack simulation training
B.Safe attachments policies
C.Quarantine policies
D.Automated investigation and response
AnswerD

Automated investigation and response (AIR) is the correct policy type in the Microsoft 365 Defender portal for configuring automated response actions for email and collaboration content. It lets administrators define which automatic actions are performed (e.g., deleting malicious email, blocking malicious URLs, or disabling compromised user accounts) and whether they should run automatically or require approval. AIR leverages predefined playbooks and machine learning to analyze alerts, correlate signals across workloads, and drive remediation, making it the appropriate setting for enabling automated investigation and response.

Why this answer

Automated investigation and response (AIR) for email and collaboration content is configured via the 'Automated investigation and response' policy within the Email & collaboration section of the Microsoft 365 Defender portal. This policy allows you to set up automatic remediation actions for threats in email and collaboration tools. Option A is incorrect because Attack simulation training is used for conducting phishing simulations, not for AIR.

Option B is incorrect because Safe attachments policies protect against malicious attachments in email and are part of anti-malware settings. Option C is incorrect because Quarantine policies manage how quarantined messages are handled, not automated investigation and response.

683
MCQeasy

A company wants to reduce help desk calls by allowing users to reset their own passwords securely. Users should be able to reset their passwords using a mobile phone number or email as verification. Which Microsoft Entra ID feature should be enabled?

A.Conditional Access
B.Self-Service Password Reset (SSPR)
C.Password Protection
D.Identity Protection
AnswerB

Self-Service Password Reset (SSPR) is a Microsoft Entra ID feature that enables users to reset or unlock their password from a web portal after verifying the authentication methods they registered, such as Microsoft Authenticator, phone numbers, or security questions. It directly addresses password reset support tickets by removing administrator involvement, making it the correct answer for reducing help desk calls.

Why this answer

Self-Service Password Reset (SSPR) is the Microsoft Entra ID feature specifically designed to allow users to reset their own passwords without help desk intervention. It supports verification methods such as mobile phone number (via SMS or phone call) and email, meeting the company's requirement for secure, user-driven password resets.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access after authentication) with SSPR (which handles the authentication recovery process), leading them to select Conditional Access when the question explicitly asks about password reset functionality.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals like user, device, or location; it does not provide password reset functionality. Option C is wrong because Password Protection is a feature that blocks weak or compromised passwords by enforcing custom banned password lists and global banned lists, but it does not enable users to reset their own passwords. Option D is wrong because Identity Protection is a risk-based detection and remediation tool that identifies suspicious sign-in behaviors and user risks (e.g., leaked credentials), but it does not offer self-service password reset capabilities.

684
MCQhard

A company has a Microsoft 365 E5 tenant with 10,000 users. You need to delegate the ability to manage Microsoft Entra ID roles to a group of support engineers. The solution must follow the principle of least privilege and allow engineers to assign only specific roles to users. What should you do?

A.Assign the engineers the Privileged Role Administrator role
B.Add the engineers to the Global Administrator role in Microsoft Entra ID
C.Create a group in Microsoft Entra ID and assign it the User Administrator role, then use PIM to elevate
D.Create a custom role in Microsoft Entra ID with permissions to assign specific roles, and use PIM to enable just-in-time access
AnswerD

Creating a custom role in Microsoft Entra ID with the specific permission to assign roles (e.g., microsoft.directory/roleAssignments/allProperties/assign) scoped to a limited set of roles, and using PIM for just-in-time access, is the correct approach. This gives engineers exactly the permission they need, only when they need it, with approval workflow, MFA, and audit logging. It balances operational efficiency with least-privilege security and is a recommended pattern for delegating role assignments in large enterprises.

Why this answer

It follows the principle of least privilege by creating a custom role that grants only the specific permissions needed to assign designated roles, and using Privileged Identity Management (PIM) for just-in-time (JIT) access ensures engineers are elevated only when required. This approach avoids granting standing administrative privileges and allows granular control over which roles can be assigned, meeting the requirement to delegate role management without over-provisioning.

Exam trap

The trap here is that candidates often confuse the Privileged Role Administrator role (which can assign any role) with a custom role that limits assignments to specific roles, or mistakenly think that adding engineers to a built-in role like User Administrator with PIM elevation is sufficient, when in fact PIM does not change the underlying permissions of the role itself.

How to eliminate wrong answers

Option A is wrong because the Privileged Role Administrator role grants full control over all role assignments in Microsoft Entra ID, including the ability to assign any role (including Global Administrator), which violates the principle of least privilege by providing excessive permissions. Option B is wrong because the Global Administrator role has unrestricted access to all tenant settings and resources, far exceeding the need to manage only specific role assignments, and is a classic over-privileged assignment. Option C is wrong because the User Administrator role only allows management of users and groups, not the assignment of Microsoft Entra ID roles to users; it does not include permissions to delegate role management, and using PIM with this role does not grant the ability to assign other roles.

685
MCQmedium

Your organization uses Microsoft Purview to classify and protect data. You need to create a custom sensitive info type that detects employee IDs formatted as 'EMP-XXXXX' where X is a digit. Which approach should you use?

A.Create a custom sensitive info type using a regular expression.
B.Use a keyword dictionary for the pattern.
C.Use exact data match (EDM) based classification.
D.Use the built-in 'Employee ID' sensitive info type.
AnswerA

Creating a custom sensitive info type (SIT) with a regular expression is the correct approach when your organization's employee ID follows a specific, predictable pattern (e.g., a prefix like “EMP-” followed by digits). In Microsoft Purview, a custom SIT lets you define a regex-based pattern that directly matches that format, and you can further refine detection with corroborative keywords, character proximity, and confidence levels. This allows DLP policies to precisely identify the data without relying on an exhaustive list of known values.

Why this answer

A custom sensitive info type using a regular expression is the best way to define the pattern 'EMP-XXXXX' (where X is a digit). Option B is incorrect because a keyword dictionary is used for exact word matching, not pattern matching. Option C is incorrect because Exact Data Match (EDM) requires a source of exact data values, not a pattern.

Option D is incorrect because the built-in 'Employee ID' sensitive info type may not match this specific format.

686
MCQhard

Your organization has Microsoft Defender for Cloud Apps (MCAS) deployed. You need to create a policy that automatically blocks downloads of files classified as 'Highly Confidential' from SharePoint Online to unmanaged devices. Which policy type should you use?

A.Access policy
B.Activity policy
C.App discovery policy
D.Session policy
AnswerD

Session policies in Microsoft Defender for Cloud Apps apply real-time controls during user sessions, including blocking downloads to unmanaged devices. This matches the requirement to prevent file downloads from SharePoint Online based on the Highly Confidential classification.

Why this answer

A session policy in Microsoft Defender for Cloud Apps (MCAS) is the correct choice because it enables real-time monitoring and control of user activities in cloud apps, such as blocking downloads based on file sensitivity labels. This policy type uses reverse proxy architecture to inspect and intervene in user sessions, allowing you to block downloads of 'Highly Confidential' files from SharePoint Online to unmanaged devices.

Exam trap

The trap here is that candidates often confuse Access policies (which control who can access the app) with Session policies (which control what users can do within the app), leading them to incorrectly choose Option A when the question specifically requires blocking a file download action.

How to eliminate wrong answers

Option A is wrong because an Access policy controls access based on user, device, or location conditions (e.g., requiring multi-factor authentication) but does not inspect or block specific file downloads in real time. Option B is wrong because an Activity policy triggers alerts or automated actions based on logged activities (e.g., mass download detection) but cannot proactively block a download during the session. Option C is wrong because an App discovery policy is used to identify shadow IT and unsanctioned cloud apps, not to control file downloads within a sanctioned app like SharePoint Online.

687
MCQmedium

You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The company has a requirement that all administrative roles must be activated only after approval by a designated approver. You configure Privileged Identity Management (PIM) for the Global Administrator role. You need to ensure that when a user activates the role, an approver must approve the request before the role is activated. What should you configure in the PIM role settings?

A.Enable 'Require multifactor authentication on activation'.
B.Enable 'Require approval to activate' and specify the approvers.
C.Set Activation maximum duration to 1 hour.
D.Configure 'Require justification on activation'.
AnswerB

In PIM role settings, the 'Require approval to activate' option enforces that a designated approver must approve an activation request. You can specify one or more approvers. This directly meets the requirement that administrative roles must be activated only after approval by a designated approver.

Why this answer

The 'Require approval to activate' setting in PIM role settings enforces an approval workflow. When a user requests activation, the designated approvers receive a notification and must approve the request before the role is activated. This ensures that administrative roles are activated only after explicit approval, meeting the company's requirement.

It is configured per role in PIM.

Exam trap

The trap here is confusing MFA on activation with approval on activation; MFA verifies the user's identity but does not require a second person's approval.

688
Drag & Dropmedium

Drag and drop the steps to configure a compliance retention policy in Microsoft Purview in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Retention policies are created in Purview, locations selected, retention settings defined, and then published.

689
MCQmedium

Refer to the exhibit. An administrator runs the KQL query in Microsoft Defender for Endpoint. The result set is empty. What is the most likely reason?

A.The device is not onboarded to Microsoft Defender for Endpoint.
B.The query is case-sensitive and the account name is 'Admin' with a capital A.
C.No logon events with the account name 'admin' exist in the past 7 days.
D.There are no logon events in the last 7 days.
AnswerC

This is correct because the KQL query filters logon events by AccountName == 'admin' and a time range of the last 7 days. When the query executes, it scans the events table and returns only rows where the account name matches exactly and the timestamp falls within the period. An empty result set directly indicates that no logon events with the account name 'admin' occurred in those 7 days. It does not imply that no logon events happened at all, only that none matched the specified account and time filter.

Why this answer

The KQL query filters for logon events where the AccountName equals 'admin' (lowercase). If no such events occurred in the last 7 days, the result set will be empty. This is the most likely reason because the query explicitly restricts the time range and account name, and an empty result does not indicate a broader issue with onboarding or case sensitivity.

Exam trap

The trap here is that candidates may assume an empty result set always indicates a configuration or onboarding problem, rather than recognizing that the query's specific filter (account name and time range) simply returned no matching data.

How to eliminate wrong answers

Option A is wrong because if the device were not onboarded to Microsoft Defender for Endpoint, the query would return an error or no data at all, but the question states the result set is empty, which is consistent with a valid query returning zero matching records. Option B is wrong because KQL is case-sensitive by default, but the query uses 'admin' (lowercase) and the exhibit shows the account name is 'admin' (lowercase), so case sensitivity is not the issue; the query would match 'admin' exactly. Option D is wrong because the query specifically filters for the account name 'admin', so even if there are other logon events in the last 7 days, they would not appear unless they match the account name; an empty result does not imply no logon events at all.

690
MCQmedium

A legal hold is required for all emails in a user's mailbox related to a litigation case. The administrator needs to ensure that the mailbox content is preserved even if the user tries to delete emails. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.eDiscovery (Standard) case hold
C.Retention policy
D.In-Place Hold
AnswerA

Litigation Hold is a dedicated hold feature in Exchange Online (under Microsoft Purview) that preserves an entire mailbox in-place, including all deleted and edited items, by maintaining copies in the Recoverable Items folder. It applies instantly and remains in effect until explicitly removed, making it the precise mechanism for legally requiring every email in a user's mailbox to be retained. Unlike policy-based deletion or case-scoped holds, Litigation Hold is designed for indefinite, mailbox-wide legal preservation without requiring a separate eDiscovery case.

Why this answer

Litigation Hold is the correct choice because it is a Microsoft Purview feature specifically designed to preserve all mailbox content, including deleted items and original versions of modified items, for legal or compliance purposes. When enabled, it places the user's entire mailbox on hold, preventing permanent deletion by the user or automated processes, and ensures that all data related to a litigation case is retained indefinitely until the hold is removed.

Exam trap

The trap here is that candidates often confuse Litigation Hold with eDiscovery case holds or retention policies, but Litigation Hold is the simplest and most direct feature for preserving an entire mailbox indefinitely for legal purposes, without needing to create a case or define retention rules.

How to eliminate wrong answers

Option B (eDiscovery (Standard) case hold) is wrong because it is used to preserve content for a specific eDiscovery case, but it requires creating an eDiscovery case and associating a hold with that case, which is more complex and not the simplest direct method for a single user's mailbox in a litigation scenario. Option C (Retention policy) is wrong because retention policies are designed for managing data lifecycle based on age or other criteria, not for indefinite preservation in response to a legal hold, and they can allow deletion after a specified period. Option D (In-Place Hold) is wrong because In-Place Hold is a legacy Exchange Online feature that has been deprecated in favor of Litigation Hold and eDiscovery holds; it is no longer available in modern Microsoft Purview deployments.

691
MCQeasy

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company wants to allow users to reset their own passwords without contacting the help desk. You need to enable self-service password reset (SSPR) for all users. What should you do?

A.Configure a conditional access policy that requires password change on next sign-in for all users.
B.In the Microsoft Entra admin center, enable password reset for all users and require users to register authentication methods.
C.Enable Azure AD Connect password writeback and configure password reset in the on-premises Active Directory.
D.Assign Microsoft 365 E5 licenses to all users to enable self-service password reset.
AnswerB

Enabling SSPR in the Microsoft Entra admin center allows users to reset their passwords if they have registered authentication methods. This is the primary step to enable self-service password reset. Requiring registration ensures users have the necessary methods. This configuration meets the requirement without additional licenses, as SSPR is included in Microsoft Entra ID Free and above.

Why this answer

To enable self-service password reset, you must configure it in the Microsoft Entra admin center and require users to register authentication methods. This allows users to reset their own passwords without help desk intervention. SSPR is included in all Microsoft Entra ID editions, so no additional licensing is needed.

Conditional access password change and on-premises writeback are not prerequisites for cloud-only SSPR.

Exam trap

The trap here is thinking that SSPR requires premium licensing or hybrid configuration; it is a baseline feature that only needs to be enabled and configured with authentication methods.

692
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. You need to investigate which user account is potentially compromised. Which tool should you use to correlate the alert with user activity?

A.Microsoft Defender XDR portal
B.Microsoft Intune admin center
C.Microsoft Purview compliance portal
D.Microsoft Entra admin center
AnswerA

The Microsoft Defender XDR portal (security.microsoft.com) is the correct console because it unifies alerts from Defender for Identity with Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue and entity timeline. Identity-related alerts—such as suspicious Kerberos authentication, LAN-LAN traffic, or privilege escalation—are ingested from Defender for Identity sensors on domain controllers and correlated to show attack narratives like lateral movement. This cross-domain correlation is what makes it the central place to investigate and respond to identity threats.

Why this answer

The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident queue that correlates alerts from Defender for Identity with user activity, including Kerberos ticket requests. This allows you to investigate the specific user account involved by examining the alert timeline, related events, and entity details such as the account's authentication patterns and potential lateral movement.

Exam trap

The trap here is that candidates may confuse the Microsoft Entra admin center (which handles identity configuration) with the Microsoft Defender XDR portal (which handles security incident correlation), leading them to choose D instead of A.

How to eliminate wrong answers

Option B is wrong because the Microsoft Intune admin center focuses on device management, compliance policies, and app deployment, not on security alert correlation or user authentication activity. Option C is wrong because the Microsoft Purview compliance portal is designed for data governance, eDiscovery, and compliance management, not for investigating real-time security alerts like suspicious Kerberos ticket requests. Option D is wrong because the Microsoft Entra admin center handles identity and access management, including user settings and conditional access policies, but it does not provide the integrated incident investigation and threat correlation capabilities needed for Defender for Identity alerts.

693
MCQmedium

A security administrator wants to block users from uploading files to personal cloud storage apps (e.g., Dropbox) from managed Windows devices, while allowing access from compliant mobile devices. Which Microsoft 365 Defender feature should be used?

A.Microsoft Defender for Endpoint Attack Surface Reduction rules
B.Microsoft Defender for Cloud Apps session policy
C.Microsoft Defender for Office 365 Safe Attachments
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Cloud Apps session policies operate through a reverse proxy in conjunction with Azure AD Conditional Access, allowing real-time inspection of a user's SaaS app session. The policy engine can enforce granular actions such as blocking a file upload, download, or print after evaluating device compliance and file attributes. This makes it the correct mechanism to stop users from uploading files to personal cloud storage apps while still allowing compliant access elsewhere.

Why this answer

Microsoft Defender for Cloud Apps session policies use reverse proxy architecture to monitor and control user activities in real time. By configuring a session policy with the 'Block' action for the 'Upload file' activity on managed Windows devices, the administrator can prevent file uploads to personal cloud storage apps like Dropbox. Conditional Access App Control enforces this policy based on device compliance, allowing compliant mobile devices to bypass the block.

Exam trap

The trap here is that candidates confuse host-level ASR rules (Option A) with cloud-level session policies, failing to recognize that ASR rules cannot enforce conditional access based on device compliance or control uploads to specific cloud apps.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction rules are host-level controls that block specific behaviors (e.g., Office apps creating child processes) but cannot differentiate between managed and unmanaged devices or enforce conditional access based on device compliance for cloud app uploads. Option C is wrong because Safe Attachments is a feature of Defender for Office 365 that scans email attachments for malware in a sandbox environment; it does not control user uploads to third-party cloud storage apps. Option D is wrong because Defender for Identity monitors on-premises Active Directory for identity-based threats (e.g., Kerberoasting, pass-the-hash) and has no capability to block file uploads to cloud apps.

694
MCQeasy

An administrator needs to configure email notifications for Exchange Online service health incidents to be sent to a specific IT support mailbox. Where should the administrator configure these notifications in the Microsoft 365 admin center?

A.Health > Service health > Customize notifications
B.Organization profile > Notifications > Service health
C.Mail flow connectors
D.Settings > Service settings
AnswerA

Service health notifications for Exchange Online are configured from Health > Service health > Customize notifications. This opens a panel where you can select specific services (such as Exchange Online) and choose which email addresses should receive incident notifications, ensuring that only relevant admins are alerted. It also allows you to set filters for issue types like high-impact incidents or advisories.

Why this answer

The 'Customize notifications' link under Health > Service health in the Microsoft 365 admin center is the dedicated interface for configuring email notifications for service health incidents, including Exchange Online. This allows administrators to specify which email addresses (such as an IT support mailbox) receive alerts for service incidents, advisories, and other health events, with granular control over which services and severity levels trigger notifications.

Exam trap

The trap here is that candidates confuse the 'Notifications' section under Organization profile (which handles admin email notifications for password resets or license assignments) with the service health notification settings, leading them to select Option B instead of navigating to the correct Health > Service health path.

How to eliminate wrong answers

Option B is wrong because 'Organization profile > Notifications > Service health' is not a valid path in the Microsoft 365 admin center; the actual notification settings for service health are located under Health > Service health, not under Organization profile. Option C is wrong because 'Mail flow connectors' are used to configure email routing between Exchange Online and on-premises or third-party email systems, not for setting up service health notifications. Option D is wrong because 'Settings > Service settings' is a generic path that does not exist in the current Microsoft 365 admin center UI; service health notifications are managed under the Health section, not under Settings.

695
MCQeasy

A company purchases Microsoft 365 E5 licenses for 500 users. The administrator wants to automatically assign licenses to new users based on their group membership. Which method should the administrator use?

A.Run a PowerShell script to assign licenses individually
B.Configure group-based licensing in Microsoft Entra ID
C.Manually assign licenses in the Microsoft 365 admin center for each user
D.Use a volume licensing product key to activate licenses
AnswerB

Group-based licensing in Microsoft Entra ID assigns M365 E5 licenses automatically to all users in a group, including new members added later. When a user leaves the group, the license is automatically removed, and the system logs any assignment errors (e.g., insufficient quota or conflicting service plans) in the user's object. This is the recommended and native method for managing per-user subscriptions like M365 E5 because it runs in the background and requires no manual effort once the group is configured.

Why this answer

Group-based licensing in Microsoft Entra ID (formerly Azure AD) allows automatic assignment and removal of licenses based on group membership. When a user is added to a licensed group, the license is automatically assigned; when removed, the license is revoked. This eliminates manual effort and ensures consistent licensing for all 500 users.

Exam trap

The trap here is that candidates often confuse group-based licensing with manual or scripted methods, assuming that PowerShell or the admin center are the only ways to assign licenses, but Microsoft Entra ID's group-based licensing is the correct automated solution for this scenario.

How to eliminate wrong answers

Option A is wrong because running a PowerShell script to assign licenses individually is a manual, scripted approach that does not scale well for 500 users and lacks the automatic, membership-driven assignment required. Option C is wrong because manually assigning licenses in the Microsoft 365 admin center for each user is time-consuming and error-prone, not leveraging automation. Option D is wrong because volume licensing product keys are used for on-premises or subscription activation, not for assigning Microsoft 365 E5 licenses to users in a cloud tenant.

696
MCQhard

A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?

A.Attack simulation training
B.Threat Explorer
C.User reported settings in the Microsoft 365 Defender portal
D.Safe Links
AnswerC

User reported settings in the Microsoft 365 Defender portal, found under Settings > Email & collaboration, are the native control plane that connects end-user report actions to backend automation. An admin can route reported messages to Microsoft for analysis, to a custom mailbox, or directly into automated investigation and response, and can enable the automatically block sender rule so that confirmed phishing verdicts instantly update the tenant block list. This is precisely the kind of correlated, report-initiated blocking that the other options lack, making it the correct choice for this scenario.

Why this answer

User reported settings in the Microsoft 365 Defender portal allow administrators to configure how user-reported messages are handled. When enabled, users can report suspicious emails directly from Outlook, and these reports can automatically trigger an investigation and block the sender via automated investigation and response (AIR) policies. This directly addresses the requirement to have user-reported emails initiate security actions.

Exam trap

The trap here is that candidates often confuse user reporting features with attack simulation training or threat hunting tools, not realizing that the specific setting to enable automated investigation and blocking from user reports is found in the User reported settings within the Microsoft 365 Defender portal.

How to eliminate wrong answers

Option A is wrong because Attack simulation training is a tool for creating and launching simulated phishing campaigns to train users, not for handling real user-reported emails or triggering automated investigations. Option B is wrong because Threat Explorer is a real-time reporting and investigation tool for analyzing threats, but it does not provide a mechanism for users to report emails or automatically block senders based on user reports. Option D is wrong because Safe Links is a time-of-click protection feature that scans URLs in emails and Office documents, but it does not enable user reporting or automated investigation workflows.

697
MCQeasy

Refer to the exhibit. You run this PowerShell command in your Microsoft 365 tenant. What is the purpose of the command?

A.To list all users with sign-in blocked
B.To list all unlicensed users with a specific usage location
C.To list all unlicensed users in the tenant
D.To list all users who have a license assigned
AnswerC

The Where-Object clause {$_.AssignedLicenses.Count -eq 0} correctly targets users whose AssignedLicenses collection has zero entries, meaning no license SKU has been assigned to the account. Because the cmdlet enumerates all user objects in the directory (with the -All switch or through Graph pagination), the result is the complete set of unlicensed users in the tenant. This is the intended purpose of the command.

Why this answer

The PowerShell command `Get-MgUser -Filter 'assignedLicenses/$count eq 0' -ConsistencyLevel eventual` retrieves all users in the Microsoft 365 tenant who have no licenses assigned. The `assignedLicenses/$count eq 0` filter checks that the count of assigned licenses is zero, and `-ConsistencyLevel eventual` is required for advanced queries on directory objects. This directly corresponds to listing all unlicensed users in the tenant.

Exam trap

The trap here is that candidates may confuse the `assignedLicenses/$count eq 0` filter with a filter for unlicensed users in a specific location or with sign-in status, but the command lacks any additional filters for usage location or account status.

How to eliminate wrong answers

Option A is wrong because the command does not filter by `accountEnabled` or `SignInActivity`, which are required to identify users with sign-in blocked. Option B is wrong because the command does not include any filter for `usageLocation`; it only checks for unlicensed users without specifying a location. Option D is wrong because the command explicitly filters for users where `assignedLicenses/$count eq 0`, meaning it returns users without licenses, not those with licenses assigned.

698
Multi-Selectmedium

Which TWO actions can an admin take to reduce the number of passwords in use for end users?

Select 2 answers
A.Enforce complex password policies
B.Enable Windows Hello for Business
C.Configure self-service password reset
D.Implement password hash sync
E.Deploy Microsoft Authenticator for passwordless sign-in
AnswersB, E

Windows Hello for Business uses a device-bound asymmetric key pair protected by PIN or biometrics and authenticates the user to Microsoft Entra ID and on-premises resources without transmitting a password. When you register the device and enable the credential, Windows replaces the password prompt with the PIN/biometric gesture at sign-in to Windows, applications, and web resources. This directly reduces the number of password-based sign-ins because the user's key and gesture satisfy the authentication challenge.

Why this answer

Windows Hello for Business replaces traditional password authentication with strong two-factor authentication tied to a user's device, using biometrics or a PIN. This directly reduces the reliance on passwords for end users by enabling passwordless sign-in to Windows devices and integrated applications.

Exam trap

The trap here is that candidates often confuse password reduction with password management improvements, such as SSPR or password policies, which do not actually decrease the number of passwords users must remember.

699
MCQhard

You are reviewing a Conditional Access policy in Microsoft Entra ID. The exhibit shows the policy configuration. You need to allow users to access Office 365 applications from personal devices that are not enrolled in Microsoft Intune. However, the policy currently blocks access because it requires a compliant device. Users are prompted for MFA but then blocked due to device compliance. What should you modify in the policy?

A.Add a session control for sign-in frequency.
B.Remove "compliantDevice" from the builtInControls grant control list.
C.Remove the cloudAppSecurity session control.
D.Change cloudAppSecurityType to "blockDownloads".
AnswerB

Removing compliantDevice from the grant controls leaves MFA as the only requirement, so personal unenrolled devices satisfy the policy. The block stems solely from the device compliance grant, not from the MFA prompt, so deleting that control restores access without altering assignment scope.

Why this answer

The policy currently uses the 'Require compliant device' grant control, which blocks access from devices not enrolled in Intune or not meeting compliance policies. Removing 'compliantDevice' from the builtInControls list allows access from personal, non-enrolled devices while still enforcing MFA. This directly resolves the scenario where users pass MFA but are blocked by device compliance.

Exam trap

The trap here is that candidates often confuse session controls (like app enforcement or sign-in frequency) with grant controls (like device compliance), leading them to incorrectly modify session settings instead of removing the device compliance requirement.

How to eliminate wrong answers

Option A is wrong because sign-in frequency controls how often users must re-authenticate, not device compliance or enrollment status, so it would not unblock non-compliant devices. Option C is wrong because removing the cloudAppSecurity session control affects session monitoring and control (e.g., for data exfiltration), not device compliance requirements, so it would not resolve the block. Option D is wrong because changing cloudAppSecurityType to 'blockDownloads' restricts file download actions in sessions, but does not alter the device compliance grant control that is causing the block.

700
MCQmedium

You are a Microsoft 365 administrator. A user reports that they cannot send emails to a specific external domain. You check the Exchange Admin Center and see that the domain is not blocked. What should you check next?

A.Verify that the user has a full mailbox and is not over the send limit.
B.Review the outbound spam filter policy.
C.Check the mail flow rules (transport rules) in Exchange Online.
D.Check the spam filter policy to see if the domain is on the blocked sender list.
AnswerC

Mail flow rules (transport rules) can contain conditions that match the recipient domain and actions such as reject, redirect, or silently drop the message. If a user can send to all domains except one, a transport rule targeting that domain is the most direct cause, especially after the blocked sender list is ruled out. Reviewing these rules in the Exchange admin center under Mail flow > Rules will reveal any applicable rule and its action.

Why this answer

Mail flow rules (transport rules) in Exchange Online can block or redirect messages based on conditions like sender, recipient domain, or message content, even if the domain is not listed in any block list. Since the domain is not blocked in the spam filter or outbound policies, a transport rule is the most likely cause of the issue, as it can silently reject or quarantine messages without appearing in the standard block lists.

Exam trap

The trap here is that candidates often assume domain blocking only occurs in the spam filter or outbound policies, overlooking that transport rules can enforce granular domain-based restrictions that are invisible in those sections.

How to eliminate wrong answers

Option A is wrong because send limits (e.g., 10,000 recipients per day) apply to all external domains equally, not to a specific domain, and the user would typically receive a non-delivery report (NDR) if over the limit. Option B is wrong because the outbound spam filter policy controls bulk email thresholds and sending limits for outbound spam, not the ability to send to a specific domain. Option D is wrong because the spam filter policy's blocked sender list applies to inbound messages (from external senders to your users), not outbound messages sent by your users to external domains.

701
MCQeasy

Your organization requires that all administrators use phishing-resistant authentication methods. Which Microsoft Entra ID authentication method meets this requirement?

A.SMS-based verification
B.Microsoft Authenticator push notification
C.Temporary Access Pass
D.FIDO2 security key
AnswerD

FIDO2 security keys implement WebAuthn, generating a private/public key pair on the device and sending an assertion that is cryptographically bound to the exact Origin and RP ID of the legitimate resource. Even if a user is tricked into visiting a phony admin portal, the key will not release a usable assertion because the fake site's origin does not match the registered relying party. This origin-bound challenge-response design makes FIDO2 phishing-resistant and the correct choice for the org's requirement.

Why this answer

FIDO2 security keys are phishing-resistant because they use public-key cryptography and are bound to a specific website origin, preventing credential reuse on fake sites. This meets Microsoft's requirement for phishing-resistant authentication under Entra ID, as it satisfies the 'something you have' factor without exposing secrets to the relying party.

Exam trap

The trap here is that candidates confuse 'multi-factor authentication' with 'phishing-resistant authentication,' assuming any MFA method (like push notifications) is sufficient, but Microsoft explicitly requires methods that resist credential theft via phishing, which only FIDO2, Windows Hello for Business, or certificate-based authentication satisfy.

How to eliminate wrong answers

Option A is wrong because SMS-based verification relies on a phone number and can be intercepted via SIM-swapping or SS7 attacks, making it vulnerable to phishing. Option B is wrong because Microsoft Authenticator push notifications use OTP or number matching, which can be intercepted by a man-in-the-middle or tricked via MFA fatigue attacks, and are not considered phishing-resistant. Option C is wrong because Temporary Access Pass is a time-limited password used for onboarding or recovery, not a phishing-resistant method; it can be phished if the user is tricked into entering it on a fake site.

702
MCQeasy

Your company uses Microsoft 365 Business Premium. You need to ensure that all company-owned Windows 10 devices are automatically enrolled in Microsoft Intune when users sign in with their work account. The devices are Azure AD joined. You have configured automatic enrollment in Intune. However, some devices are not enrolling. You need to troubleshoot the issue. What should you check first?

A.Ensure that devices are Azure AD joined and not domain joined.
B.Check the Windows 10 version; version 1607 or later is required.
C.Verify that each user has an appropriate Microsoft Intune license assigned.
D.Check that the MDM authority is set to Microsoft Intune in Microsoft Entra ID.
AnswerC

Intune licenses are assigned per user, and Microsoft 365 Business Premium includes Intune as part of the subscription. When a user without an Intune license attempts to enroll, the device will not appear in Intune even if automatic enrollment and MDM authority are correctly configured. Verifying each user has an appropriate license (or the Business Premium license) is the first and definitive check when auto-enrollment is failing.

Why this answer

Automatic enrollment in Microsoft Intune requires each user to have an appropriate Intune license (e.g., Microsoft 365 Business Premium includes Intune). Without a license, the device will not be able to enroll even if all other prerequisites are met. The license is checked during the enrollment process, and if missing, enrollment fails silently.

Exam trap

The trap here is that candidates often assume device-level prerequisites (like Azure AD join or OS version) are the most common cause, but Microsoft Intune enrollment is user-license-driven, and missing licenses are a frequent real-world issue that is easy to overlook.

How to eliminate wrong answers

Option A is wrong because the question states the devices are already Azure AD joined, so this is not a missing prerequisite; checking this again would not resolve the issue. Option B is wrong because Windows 10 version 1607 or later is a requirement, but the question does not indicate that devices are running an older version; this is a secondary check, not the first step. Option D is wrong because the MDM authority is automatically set to Microsoft Intune when you configure automatic enrollment in the Microsoft Entra admin center; if it were not set, no devices would enroll, but the question states that some devices are enrolling, so this is not the immediate issue.

703
MCQhard

Your company is migrating from an on-premises file server to SharePoint Online. You need to ensure that files containing personally identifiable information (PII) are automatically detected and classified with a sensitivity label. What should you use?

A.A retention label auto-applied by a trainable classifier.
B.Microsoft Information Protection scanner.
C.A DLP policy to block sharing of PII.
D.Auto-labeling for sensitivity labels in Microsoft 365.
AnswerD

Auto-labeling can scan SharePoint sites and apply labels automatically.

Why this answer

Auto-labeling for sensitivity labels in Microsoft 365 uses the same sensitive information types (SITs) and trainable classifiers that power DLP, but its purpose is to apply a sensitivity label rather than block or retain content. When files are uploaded to SharePoint Online, the service-side auto-labeling policy evaluates them against the configured rules and stamps the matching label, which then drives encryption, watermarking, and access controls. This is the only option that both detects PII and applies a sensitivity label automatically.

Exam trap

MS-102 often tests the confusion between DLP policies, retention labels, and sensitivity labels, so candidates must remember that only auto-labeling for sensitivity labels actually applies a sensitivity label to content; DLP only enforces actions like block or notify.

How to eliminate wrong answers

Option A is wrong because a retention label controls how long content is kept or deleted, not how it is classified for protection; a trainable classifier can trigger a retention label, but that does not produce a sensitivity label. Option B is wrong because the Microsoft Information Protection scanner is an on-premises discovery and labeling tool for file shares and repositories, not for SharePoint Online, and it does not automatically label cloud content. Option C is wrong because a DLP policy detects PII and can block or warn on sharing, but it does not apply a sensitivity label to the file.

704
MCQmedium

An organization uses a third-party SaaS application that supports SAML-based single sign-on. The application is not in the Azure AD gallery. What is the first step to configure SSO?

A.Create a new enterprise application from the 'Non-gallery application' option in Azure AD
B.Configure Azure AD Connect to sync on-premises users
C.Add the application in the Microsoft 365 admin center under 'Integrated apps'
D.Create a custom role in Azure AD for the application
AnswerA

In Azure AD, when a third-party SaaS application supports SAML 2.0 but is not pre-configured in the gallery, the correct first administrative action is to select "Create a new application" and choose "Non-gallery application" from the Azure AD Enterprise applications blade. This action provisions a dedicated service principal in your tenant that accepts SAML requests and provides the Azure AD identifier, reply URL, and certificate required to complete SAML SSO configuration on the SaaS vendor's side. This templates the identity provider relationship before you can assign users or test SSO.

Why this answer

The correct first step is to create a new enterprise application from the 'Non-gallery application' option in Azure AD. This allows you to configure SAML-based SSO for any third-party application that supports SAML 2.0, even if it is not listed in the Azure AD gallery. The non-gallery application template provides the necessary endpoints and metadata to establish trust between Azure AD and the SaaS application.

Exam trap

The trap here is that candidates often confuse the 'Integrated apps' section in the Microsoft 365 admin center with Azure AD enterprise applications, but the former is for managing add-ins and the latter is the correct location for SAML SSO configuration.

How to eliminate wrong answers

Option B is wrong because Azure AD Connect is used to synchronize on-premises Active Directory users to Azure AD, not to configure SSO for a third-party SaaS application. Option C is wrong because the Microsoft 365 admin center 'Integrated apps' section is for managing Microsoft 365 add-ins and integrations, not for configuring SAML-based SSO with external applications. Option D is wrong because custom roles in Azure AD are for managing administrative permissions, not for configuring application SSO.

705
Multi-Selecthard

A security administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps features must be configured to meet these requirements? (Select all that apply.)

Select 2 answers
A.Cloud Discovery
B.App Connectors
C.Conditional Access App Control
D.API connectors
AnswersA, C

Cloud Discovery is the Defender for Cloud Apps feature that analyzes traffic logs from enterprise proxies or Microsoft Defender for Endpoint to identify brand-specific cloud app usage across the organization. It continuously monitors shadow IT by discovering applications that users access, then scores them for risk (e.g., security, compliance) to create a catalog of sanctioned and unsanctioned apps. This is the correct first step for understanding 'which cloud apps are being used' — it provides the raw visibility that later enables blocking.

Why this answer

Cloud Discovery (A) is correct because it analyzes traffic logs from your network to identify all cloud apps in use, providing visibility into sanctioned and unsanctioned apps. Conditional Access App Control (C) is correct because it enforces real-time access controls via a reverse proxy, allowing you to block unsanctioned apps as users attempt to access them.

Exam trap

The trap here is confusing App Connectors/API connectors (which provide API-based control for specific apps) with the reverse proxy and discovery capabilities of Cloud Discovery and Conditional Access App Control, leading candidates to select options that manage existing apps rather than discover and block unsanctioned ones.

706
MCQhard

An administrator is creating a Microsoft Purview auto-labeling policy for documents containing personally identifiable information. Before turning the policy on automatically, what should the administrator do to reduce false positives?

A.Run the auto-labeling policy in simulation mode and review matches
B.Publish the label directly to all users and enable automatic application immediately
C.Create an eDiscovery hold for the SharePoint locations
D.Configure a retention policy before creating the sensitivity label
AnswerA

Running the auto-labeling policy in simulation mode is the essential first step because it executes the policy's detection logic against actual content without applying any labels, producing a match report that shows which items would have been labeled and which conditions triggered the match. Reviewing this output lets you validate whether the sensitive information types, conditions, and exclusions are correctly scoped, and tune them to reduce false positives. Only after simulation confirms accurate matches should the policy be switched to enforcement mode, preventing mass mislabeling at scale.

Why this answer

Running the auto-labeling policy in simulation mode allows the administrator to review which documents would be matched by the policy without actually applying labels. This enables analysis of the detection results to identify and reduce false positives before enabling automatic application, ensuring the policy accurately targets only documents containing the specified PII.

Exam trap

The trap here is that candidates may confuse simulation mode with other compliance features like eDiscovery or retention, or assume that immediate application is safe because the policy uses predefined PII types, but Microsoft explicitly recommends simulation mode to validate and reduce false positives before enabling automatic labeling.

How to eliminate wrong answers

Option B is wrong because publishing the label to all users and enabling automatic application immediately skips the validation step, leading to potential false positives and incorrect labeling across the tenant. Option C is wrong because an eDiscovery hold is used to preserve content for legal or investigative purposes, not to test or refine auto-labeling policy accuracy. Option D is wrong because configuring a retention policy before creating the sensitivity label does not address false positives; retention policies manage data lifecycle, not classification accuracy.

707
MCQmedium

You are the Microsoft 365 administrator for Fabrikam Inc. The compliance team needs to investigate a suspected data leak involving a former employee. They must preserve all mailbox content and SharePoint Online documents related to the employee for litigation. They also need to search for specific keywords across these locations. Which Microsoft Purview solution should they use?

A.Microsoft Purview Records Management with a retention label applied to the employee's content.
B.Microsoft Purview Data Loss Prevention (DLP) with a policy for the employee's mailbox.
C.Microsoft Purview eDiscovery (Standard) with a case hold and a search.
D.Microsoft Purview Communication Compliance with a policy monitoring the employee's communications.
AnswerC

eDiscovery (Standard) allows you to create a case, place a hold on Exchange mailboxes and SharePoint sites, and perform searches for keywords. It supports the required preservation and search capabilities for litigation. This is the appropriate solution for the described scenario.

Why this answer

The requirement is to preserve mailbox and SharePoint content and search for keywords as part of a litigation investigation. Microsoft Purview eDiscovery (Standard) provides case management, hold capabilities for Exchange and SharePoint, and search functionality. It is designed for legal investigations, unlike DLP, Records Management, or Communication Compliance, which serve different purposes.

Exam trap

The trap here is confusing retention or compliance monitoring tools with eDiscovery, which is specifically built for legal hold and investigative search.

708
MCQhard

Your organization has a Microsoft 365 E5 tenant. You want to ensure that all users are automatically signed in to Microsoft 365 apps using single sign-on (SSO) when they are on the corporate network. You have Azure AD joined the devices. What additional configuration is required?

A.Enable Azure AD Seamless Single Sign-On.
B.No additional configuration is required; Azure AD joined devices provide SSO automatically.
C.Configure Azure AD Application Proxy for each app.
D.Deploy a trusted certificate for the corporate network.
AnswerB

When a Windows device is Azure AD joined, it automatically receives a Primary Refresh Token (PRT) after the user signs in with their Azure AD credentials. This PRT is exchanged for access tokens to Microsoft 365 apps and other cloud resources without any additional sign-in prompts, providing seamless SSO across sessions. No extra configuration such as federation, password hash sync, or pass-through authentication is needed because the device and user are already registered with Azure AD.

Why this answer

Azure AD joined devices are already registered with Azure AD and use the Primary Refresh Token (PRT) to enable seamless SSO for Microsoft 365 apps without any additional configuration. When a user signs into a Windows 10/11 device that is Azure AD joined, the PRT is obtained during the initial authentication and is automatically used for browser and app sign-ins on the corporate network. Therefore, no extra steps like enabling Seamless SSO or deploying certificates are needed.

Exam trap

The trap here is that candidates often confuse Azure AD Seamless SSO (which is for non-Azure AD joined devices) with the built-in SSO capability of Azure AD joined devices, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because Azure AD Seamless Single Sign-On is a separate feature for non-Azure AD joined devices (e.g., domain-joined or non-joined devices) that relies on Kerberos delegation; it is unnecessary when devices are already Azure AD joined, as the PRT handles SSO natively. Option C is wrong because Azure AD Application Proxy is designed for publishing on-premises apps externally, not for enabling SSO on the corporate network for Microsoft 365 apps. Option D is wrong because deploying a trusted certificate is not required for SSO on Azure AD joined devices; the PRT-based SSO uses Azure AD's token infrastructure and does not depend on a locally trusted certificate for authentication.

709
MCQhard

An organization needs to restrict access to Microsoft 365 admin center to only specific users. Which approach should be used?

A.Enable MFA for all admins
B.Create a Conditional Access policy targeting the Microsoft Admin Portals cloud app
C.Assign Global Admin role only to required users
D.Use Privileged Identity Management
AnswerB

A Conditional Access policy that targets the Microsoft Admin Portals cloud app is correct because it applies grant and session controls directly to the Azure portal and Microsoft 365 admin centers. You can configure conditions such as IP location, device compliance, or sign-in risk and then choose Block access, require MFA, require a hybrid Azure AD joined device, or require a compliant device. This prevents all users—including non-admins who might normally reach certain admin pages—from accessing admin experiences outside the allowed criteria, making it the most direct and effective way to restrict admin portal access.

Why this answer

A Conditional Access policy targeting the 'Microsoft Admin Portals' cloud app allows granular control over which users can access the Microsoft 365 admin center. This policy can enforce conditions such as user/group membership, device compliance, or location to restrict access, ensuring only specific authorized users can reach the admin portals.

Exam trap

The trap here is that candidates often confuse role-based access control (assigning Global Admin) with access control to the admin center itself, assuming limiting role assignments is sufficient, but Conditional Access policies are required to explicitly block or allow access to the admin portals regardless of role membership.

How to eliminate wrong answers

Option A is wrong because enabling MFA for all admins enhances authentication security but does not restrict which users can access the admin center; any user with admin roles can still sign in after MFA. Option C is wrong because assigning the Global Admin role only to required users limits administrative privileges but does not prevent those users from accessing the admin center; the goal is to restrict access to the admin center itself, not just the role assignment. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time role activation and approval workflows, but it does not directly block access to the admin center; users with eligible roles can still activate and access it unless combined with a Conditional Access policy.

710
MCQmedium

An administrator wants to prevent users from inviting guest users from the domain 'contoso.com' to the tenant. The administrator needs to block all invitations for that specific domain while allowing invitations from all other external domains. Which setting in Microsoft Entra ID should be configured?

A.Cross-tenant access settings
B.External collaboration settings
C.User settings
D.Domain federation
AnswerB

External collaboration settings in Microsoft Entra ID contain the 'Collaboration restrictions' section where you can choose to allow invitations only to specified domains or block invitations to specific domains. Adding contoso.com to the 'Block invitations to the specified domains' list prevents users from inviting guest users whose email addresses use that domain. This is the correct administrative control for domain-based B2B invite restriction.

Why this answer

External collaboration settings in Microsoft Entra ID (formerly Azure AD) allow administrators to configure domain-based restrictions for B2B collaboration invitations. By adding 'contoso.com' to the 'Deny list' under 'Cross-tenant access settings' or specifically within the 'External collaboration settings' blade, invitations to that domain are blocked while all other external domains remain allowed. This setting directly controls the guest invitation behavior at the domain level.

Exam trap

The trap here is that candidates often confuse 'Cross-tenant access settings' (which manage tenant-to-tenant trust and access) with 'External collaboration settings' (which control domain-level invitation restrictions), leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Cross-tenant access settings control inbound and outbound access for specific tenants, not domain-based invitation blocking for all external domains; they are used for granular trust and access policies between tenants. Option C is wrong because User settings in Entra ID manage user permissions like self-service group creation or sign-in restrictions, not domain-level guest invitation blocking. Option D is wrong because Domain federation configures trust relationships for authentication (e.g., SAML/WS-Fed) with external identity providers, not invitation restrictions for specific domains.

711
MCQhard

Refer to the exhibit. You have two DLP compliance rules as shown. A user sends an email containing both PII and credit card numbers. Which rule will be applied?

A.Block PII rule only
B.Block Credit Cards rule only
C.Neither rule will apply because they conflict.
D.Both rules will be evaluated, and the most restrictive action will be applied.
AnswerD

This is correct because Microsoft 365 DLP evaluates all rules in a policy against the content and then applies the most restrictive action among those that match. Since both the Block PII rule and the Block Credit Cards rule include a Block action, the block is enforced for any matching content. This design ensures that layered protections do not weaken each other and that the highest severity action always wins.

Why this answer

When multiple DLP rules match the same email, Microsoft Purview evaluates all matching rules and applies the most restrictive action among them. In this case, both the PII rule and the Credit Cards rule match, so the action with the highest restriction (e.g., Block over Notify) is enforced. This ensures that sensitive data is protected even when multiple policies overlap.

Exam trap

The trap is assuming DLP rules conflict or that only the first matching rule applies — the exam tests whether you know that all matching rules are evaluated and the most restrictive action is enforced.

How to eliminate wrong answers

Option A is wrong because DLP does not stop evaluating after the first match — it evaluates all rules and takes the most restrictive outcome, so the PII rule alone is not the final decision. Option B is wrong for the same reason: the Credit Cards rule is not the only one applied; both are evaluated and the stricter action wins. Option C is wrong because DLP rules do not conflict in a way that disables enforcement — overlapping rules are resolved by taking the most restrictive action, not by ignoring both.

712
MCQmedium

A company wants to allow users to reset their own forgotten passwords using a mobile app notification as the verification method. Which Microsoft Entra feature should be enabled and configured?

A.Azure AD Password Protection
B.Self-service password reset
C.Privileged Identity Management
D.Identity Protection
AnswerB

Self-service password reset (SSPR) is the Microsoft Entra ID feature that lets end users verify ownership of their account through configured authentication methods—such as mobile app notification, phone call, email, or security questions—and then create a new password without help desk involvement. This directly matches the requirement in the question, making it the correct choice for allowing users to reset their own forgotten passwords.

Why this answer

Self-service password reset (SSPR) is the Microsoft Entra feature that allows users to reset their own forgotten passwords. To use a mobile app notification as the verification method, the administrator must enable SSPR and configure the 'Mobile app notification' authentication method under the 'Authentication methods' policy. This satisfies the requirement for a password reset triggered by a mobile app notification.

Exam trap

The trap here is that candidates often confuse Identity Protection (which can trigger a password reset based on risk) with the actual self-service password reset feature, forgetting that Identity Protection only initiates the reset process but does not provide the user-facing portal or verification methods for forgotten passwords.

How to eliminate wrong answers

Option A is wrong because Azure AD Password Protection is a feature that detects and blocks weak passwords and password spray attacks, not a mechanism for users to reset their own passwords. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and role activation, not self-service password reset for end users. Option D is wrong because Identity Protection uses risk-based policies to detect and respond to identity threats, such as risky sign-ins or leaked credentials, but does not enable users to reset their own passwords.

Page 9

Page 10 of 10

All pages