Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 376–450

712 questions total · 10pages · All types, answers revealed

Page 5

Page 6 of 10

Page 7
376
Multi-Selecteasy

An administrator needs to open a Microsoft 365 support request because a critical service issue is affecting all users. Which two pieces of information should the administrator have readily available before contacting support? (Choose two.)

Select 2 answers
A.Tenant ID
B.User principal names of affected users
C.Current service health status
D.Billing contact information
AnswersA, C

The tenant ID uniquely identifies the affected Microsoft 365 organisation, letting support locate the correct tenant, correlate service telemetry and open the case against the right environment. Without it, engineers cannot verify the impacted directory or scope diagnostics to the customer's instance.

Why this answer

Option A (Tenant ID) is correct because Microsoft 365 support requires the tenant GUID to uniquely identify the organization's directory and route the case to the correct environment. Option C (Current service health status) is correct because checking the Service health dashboard in the Microsoft 365 admin center shows whether the issue is a known incident or advisory, which support uses to correlate the report and avoid duplicate tickets. Option B is not required because support needs the tenant-level scope, not individual UPNs, for a service-wide outage affecting all users.

Option D is not required because billing contact information is irrelevant to a technical service incident; support asks for tenant and service health details instead.

Exam trap

The trap here is that candidates often assume user principal names (UPNs) are needed for any support request, but Microsoft Support requires the Tenant ID and service health status for tenant-wide issues, not individual user identifiers.

377
MCQmedium

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that the number of 'Leaked Credentials' detections is high. What action should you take to automatically remediate this risk?

A.Use Microsoft Entra ID Protection to automatically reset passwords for all users with leaked credentials
B.Configure a conditional access policy to block access for users with high user risk
C.Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users
D.Enable Microsoft Entra ID Multifactor Authentication for all users
AnswerC

The correct remediation is to configure a user risk policy in Microsoft Entra ID Protection that assigns 'Require password change' as the access control for high-risk users. When a user is flagged for leaked credentials, this policy forces the user to complete a password change the next time they sign in, which revokes the compromised password and automatically lowers the user's risk back to normal. This is the only built-in, automatically enforced way to remediate leaked credentials in Entra ID.

Why this answer

A user risk policy in Microsoft Entra ID Protection can be configured to automatically trigger a password change when a user is detected as high risk, such as when leaked credentials are identified. This policy directly remediates the risk by forcing the user to update their compromised credentials, effectively invalidating the leaked password. The other options either do not address the root cause or require manual intervention.

Exam trap

The trap here is that candidates often confuse 'automatic password reset' (which is not supported) with 'requiring a password change' (which is supported via a user risk policy), leading them to select Option A instead of C.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection does not support automatic password reset; it can only trigger a password change via a user risk policy, not directly reset passwords. Option B is wrong because blocking access with a conditional access policy does not remediate the leaked credentials; it only prevents access until the risk is manually resolved, leaving the compromised password still active. Option D is wrong because enabling MFA for all users adds an extra layer of security but does not address the fact that the user's password is already leaked; the compromised credential remains valid and could still be used.

378
Multi-Selecthard

A compliance officer needs to automatically apply a sensitivity label to all documents in SharePoint Online that contain a credit card number. The label must mark the document as 'Confidential' and encrypt it. Which two Microsoft Purview components must be configured to achieve automatic labeling based on sensitive content? (Choose two.)

Select 2 answers
A.Sensitivity label
B.Auto-labeling policy
C.Data Loss Prevention (DLP) policy
D.Retention label policy
AnswersA, B

A sensitivity label is the actual content-classification construct that carries the required protection settings, such as 'Confidential' with encryption, in Microsoft Purview. Creating the label is mandatory because the auto-labeling policy can only reference an existing label and apply it to content. Therefore, the correct answer to 'automatically apply a sensitivity label' includes provisioning this label with the desired encryption and permissions.

Why this answer

Sensitivity labels define the classification and protection settings (e.g., 'Confidential' marking and encryption). Auto-labeling policies automatically apply those labels to documents containing sensitive information types, such as credit card numbers, without requiring user intervention. Together, they enable automatic labeling based on sensitive content in SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling policies, but DLP policies only monitor and block data movement, while auto-labeling policies are the correct mechanism to automatically apply sensitivity labels based on content detection.

379
MCQeasy

You are configuring Microsoft Entra ID provisioning for a SaaS application that supports SCIM 2.0. The app requires the 'manager' attribute to be mapped. However, the manager attribute is not populated for all users. What should you do to avoid provisioning failures?

A.Configure the attribute mapping to 'Ignore it if null' for the manager attribute
B.Modify the SCIM schema in the application to make manager optional
C.Use the expression language to set a default value for the manager attribute
D.Delete the manager attribute mapping from the provisioning configuration
AnswerA

In the Entra ID attribute mapping editor, the 'Ignore it if null' option instructs the provisioning engine to omit the manager attribute from the SCIM request when the source user has no manager set. This prevents the target application from receiving a null value that could fail schema validation or overwrite an existing value with empty data. As a result, users without managers are provisioned successfully, and manager relationships are only updated when a real manager actually exists.

Why this answer

When the 'manager' attribute is not populated for all users, configuring the attribute mapping to 'Ignore it if null' prevents provisioning failures by allowing the provisioning service to skip the attribute when its value is null, rather than attempting to send an empty or invalid value that the SCIM 2.0 endpoint might reject. This setting ensures that only users with a manager value trigger the mapping, avoiding errors for users without a manager.

Exam trap

The trap here is that candidates often confuse 'Ignore it if null' with setting a default value or removing the mapping, but the correct approach is to gracefully skip the null attribute rather than force a value or delete the mapping entirely.

How to eliminate wrong answers

Option B is wrong because modifying the SCIM schema in the application to make manager optional is typically not under your control—the SaaS application defines its SCIM schema, and you cannot alter it from Microsoft Entra ID. Option C is wrong because using expression language to set a default value for the manager attribute would assign a static value (e.g., 'Unknown') to users without a manager, which could cause incorrect data or provisioning failures if the application expects a valid manager reference. Option D is wrong because deleting the manager attribute mapping entirely would remove the attribute from provisioning, which might violate the application's required schema or business logic, and it does not address the need to handle null values gracefully.

380
MCQmedium

A company uses Azure AD and SharePoint Online. They want to allow users from a partner organization (which also uses Azure AD) to access a specific SharePoint Online site using their existing partner credentials. The partner users should not require new accounts to be created. Which Azure AD feature should be configured?

A.Azure AD B2B collaboration
B.Azure AD B2C
C.Azure AD Domain Services
D.Organizational Relationships
AnswerA

Azure AD B2B collaboration is the correct solution because it enables you to invite users from external organizations to access SharePoint Online resources using their own Azure AD or other identity credentials. When you add a guest via B2B, Azure AD provisions a guest account in your tenant that can be assigned to SharePoint sites and groups, preserving the partner's identity and allowing you to apply conditional access and MFA. This is specifically designed for business-to-business collaboration, making it the appropriate mechanism for partner access.

Why this answer

Azure AD B2B collaboration allows you to invite external users from a partner organization to access your Azure AD-integrated applications, such as SharePoint Online, using their own existing Azure AD credentials. This feature leverages cross-tenant trust and does not require creating new user accounts in your tenant, fulfilling the requirement exactly.

Exam trap

The trap here is that candidates often confuse Azure AD B2B collaboration with Azure AD B2C, mistakenly thinking both are for external users, but B2C is designed for consumer-facing apps with local identities, not for partner organizations using their existing Azure AD credentials.

How to eliminate wrong answers

Option B (Azure AD B2C) is wrong because it is a customer-facing identity management service for external consumers (e.g., app users) and does not support using existing partner Azure AD credentials for access; it requires users to sign up with social or local accounts. Option C (Azure AD Domain Services) is wrong because it provides managed domain services (e.g., LDAP, Kerberos) for legacy applications and has nothing to do with inviting external users or cross-tenant access. Option D (Organizational Relationships) is wrong because while it is a related concept in SharePoint on-premises for federated trust, it is not an Azure AD feature and does not enable partner users to authenticate with their existing Azure AD credentials in a cloud-only SharePoint Online scenario.

381
MCQeasy

Your organization is implementing a hybrid identity solution. You want to synchronize on-premises Active Directory users to Microsoft Entra ID. Which tool should you use?

A.Microsoft Identity Manager
B.Microsoft Entra Cloud Sync
C.Microsoft Entra Connect Sync
D.Microsoft Entra Connect
AnswerD

Microsoft Entra Connect is the correct tool for a hybrid identity solution because it provides a single, unified sync engine that connects on-premises Active Directory with Microsoft Entra ID. It supports essential features such as password hash sync, pass-through authentication, single sign-on, and optional federation to deliver a seamless hybrid experience. For most organizations, this is the recommended and fully supported path to implement hybrid identity.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) is the correct tool for synchronizing on-premises Active Directory users to Microsoft Entra ID in a hybrid identity solution. It supports both password hash synchronization, pass-through authentication, and federation with Active Directory Federation Services (AD FS), making it the primary and most feature-rich sync tool for complex hybrid environments.

Exam trap

The trap here is that candidates confuse 'Microsoft Entra Connect Sync' (the sync engine component) with the full 'Microsoft Entra Connect' tool, or they incorrectly assume 'Cloud Sync' is sufficient for all hybrid scenarios despite its missing writeback and federation capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution for managing identities across heterogeneous systems, not a dedicated sync tool for Microsoft Entra ID; it requires additional configuration and is not the recommended tool for standard hybrid sync. Option B is wrong because Microsoft Entra Cloud Sync is a lightweight agent designed for syncing from a single on-premises forest to Entra ID, but it lacks support for advanced features like device writeback, group writeback, and hybrid Azure AD join, making it unsuitable for a full hybrid identity implementation. Option C is wrong because Microsoft Entra Connect Sync is not a distinct product; it is the sync engine component within Microsoft Entra Connect, and the question asks for the tool itself, not a subcomponent.

382
MCQhard

A Microsoft 365 tenant uses a custom domain named fabrikam.com for all user principal names and email addresses. The security team requires that any email message sent from an external sender that spoofs fabrikam.com be rejected outright, while legitimate messages from the on-premises mail relay must still be accepted. You configure DKIM signing and SPF with a hard fail. What should you configure next to meet the rejection requirement?

A.Create a DMARC TXT record with p=quarantine and rely on the existing SPF hard fail to block spoofed messages.
B.Create a DMARC TXT record with p=reject and add the on-premises relay to the SPF record's include list.
C.Add a second SPF record for fabrikam.com that lists only the on-premises relay's public IP address.
D.Configure an Exchange Online transport rule that rejects messages where the sender's domain is fabrikam.com and the message originates outside the organization.
AnswerB

A DMARC policy of p=reject instructs receiving systems to reject messages that fail both SPF and DKIM alignment for fabrikam.com, which stops external spoofing. Including the on-premises relay in SPF ensures its legitimate messages pass authentication, so they are not caught by the reject policy, satisfying both halves of the requirement.

Why this answer

Enforcing rejection of spoofed fabrikam.com mail requires a DMARC record with p=reject, because DMARC is the only mechanism that tells receivers to refuse messages failing SPF and DKIM alignment. Legitimate on-premises relay traffic must still authenticate, so the relay's sending infrastructure belongs in the SPF record. Quarantine softens the action, duplicate SPF records are invalid, and transport rules cannot influence external receivers.

Exam trap

The trap here is believing that an SPF hard fail by itself rejects spoofed mail, when receivers only enforce rejection if a DMARC policy of p=reject is published.

383
MCQeasy

You run the KQL query shown in the exhibit in Microsoft Defender XDR advanced hunting. What is the primary purpose of this query?

A.Identify all PowerShell activity from a specific user
B.Detect potentially malicious PowerShell commands that are obfuscated
C.Find PowerShell processes running on a specific device
D.List all PowerShell executions in the last 7 days
AnswerB

This query deliberately searches for PowerShell processes launched with the -EncodedCommand parameter, which causes the payload to be passed as a Base64 string. Encoded commands are a hallmark of obfuscation because attackers use them to hide malicious code from casual log inspection and signature-based detection. The presence of an encoded PowerShell command is therefore a valid trigger point for investigating potentially malicious behavior.

Why this answer

The query filters for powershell.exe processes with an encoded command, which is commonly used to obfuscate malicious commands. Option A is wrong because the query does not filter for specific users. Option C is wrong because the query does not filter by device.

Option D is wrong because the query does not filter by time other than the last 7 days.

384
MCQeasy

An organization has just purchased Microsoft 365 Business Standard licenses and has added the custom domain 'contoso.com' to the tenant. The administrator wants all new user email addresses to use '@contoso.com' instead of the default '@contoso.onmicrosoft.com'. How can this be achieved?

A.Set the default domain in the Microsoft 365 admin center to contoso.com
B.Change the primary SMTP address for each user manually after creation
C.Remove the onmicrosoft.com domain from the tenant
D.Edit the user creation PowerShell script to specify the domain
AnswerA

Setting contoso.com as the default domain in the Microsoft 365 admin center is the correct tenant-wide configuration. When you set a verified custom domain as the default, every new user created through the admin center automatically receives a user principal name (UPN) and email address ending with @contoso.com, without requiring any per-user steps. This setting persists for all future user creations and does not alter existing users' addresses, making it the standard way to ensure automatic assignment of the custom domain.

Why this answer

Setting the default domain to 'contoso.com' in the Microsoft 365 admin center ensures that all newly created users automatically receive an email address with the custom domain as their primary SMTP address. This is the standard method because the default domain setting controls the domain appended to new user accounts during creation, eliminating the need for manual changes.

Exam trap

The trap here is that candidates may think they must manually update each user or use PowerShell because they overlook the simple default domain configuration in the admin center, which automatically applies to all new user creations.

How to eliminate wrong answers

Option B is wrong because manually changing the primary SMTP address for each user after creation is inefficient and does not address the requirement for all new users to automatically use '@contoso.com'; it is a workaround, not a configuration. Option C is wrong because removing the 'onmicrosoft.com' domain from the tenant is not possible—it is a reserved default domain that cannot be deleted and is required for internal routing and Azure AD operations. Option D is wrong because editing a PowerShell script to specify the domain is a valid but unnecessary approach when the default domain setting in the admin center achieves the same result more simply; the question asks how to achieve this, and the admin center method is the direct, supported way.

385
MCQeasy

A compliance officer needs to mark documents in a SharePoint Online library as regulatory records. These records must be immutable (cannot be modified or deleted) for 3 years. After 3 years, a disposition review must be initiated to decide if the records can be deleted. Which Microsoft Purview solution should the officer configure?

A.Retention label configured to mark items as records with a retention period of 3 years and disposition review
B.Data Lifecycle Management retention policy with disposition review
C.Sensitivity label with encryption
D.eDiscovery case with hold
AnswerA

This configuration directly fulfills both requirements. Applying the label marks each SharePoint item as a record, which makes the content immutable so it cannot be edited or deleted by users, and the 3-year retention period starts when the item is labeled. At the end of the period, disposition review requires a designated reviewer to approve deletion, providing a controlled, auditable end-of-life process. This is the standard way in Microsoft 365 to enforce record classification and scheduled disposition on individual documents.

Why this answer

A retention label configured to mark items as regulatory records enforces immutability (no modification or deletion) for the specified retention period of 3 years. After the retention period expires, the disposition review triggers a workflow where a reviewer must approve or reject deletion, meeting the compliance officer's requirement exactly.

Exam trap

The trap here is that candidates often confuse retention policies (which apply broadly to containers) with retention labels (which apply granularly to items and support regulatory records and disposition reviews), leading them to choose Option B incorrectly.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policies apply at the container level (site or library) and cannot mark individual items as regulatory records; they also do not support disposition review after the retention period. Option C is wrong because sensitivity labels with encryption protect content via access controls and encryption, but they do not enforce immutability or a retention period with disposition review. Option D is wrong because an eDiscovery case with hold preserves content for legal purposes but does not enforce a fixed retention period or trigger a disposition review; it is designed for litigation holds, not regulatory record management.

386
MCQmedium

A company uses Azure AD Conditional Access. The security team wants to require multi-factor authentication (MFA) for all users when accessing the Azure portal, except when they are connecting from the corporate network (which is defined as a trusted location). How should the Conditional Access policy be configured?

A.Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = all locations, exclude the corporate network, Grant = Require multi-factor authentication.
B.Create a Conditional Access policy with all users, cloud apps = All cloud apps, Conditions > Locations = all locations, exclude the corporate network, Grant = Require multi-factor authentication.
C.Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = Corporate network, Grant = Block.
D.Create a Conditional Access policy with all users, cloud apps = Microsoft Azure Management, Conditions > Locations = Corporate network, Grant = Require multi-factor authentication.
AnswerA

This policy correctly targets only the Microsoft Azure Management cloud app, which covers the Azure portal, Azure CLI, and PowerShell. By selecting all locations but excluding the corporate network, any sign-in from an untrusted location—such as home, hotel, or airport—will be challenged for MFA. Granting 'Require multi-factor authentication' fulfills the requirement to protect admin access while preserving smooth access from the trusted corporate network.

Why this answer

It targets only the Azure Portal (Microsoft Azure Management cloud app), applies MFA to all locations except the trusted corporate network, and excludes the corporate network from the policy. This ensures MFA is required for all access attempts from untrusted locations while allowing direct access from the corporate network without MFA.

Exam trap

The trap here is that candidates often select 'All cloud apps' (Option B) thinking it covers the Azure portal, but this over-scopes the policy and forces MFA on all applications, which is not the requirement.

How to eliminate wrong answers

Option B is wrong because it applies to 'All cloud apps' instead of only 'Microsoft Azure Management', which would force MFA for every cloud app (e.g., Exchange Online, SharePoint) even when the requirement is only for the Azure portal. Option C is wrong because it blocks access from the corporate network, which is the opposite of the requirement (the corporate network should be trusted and allowed without MFA). Option D is wrong because it requires MFA from the corporate network, which contradicts the requirement to exempt the corporate network from MFA.

387
MCQmedium

You run the above PowerShell command on a Windows 10 device that is onboarded to Microsoft Defender for Endpoint. The device is reporting as healthy in the portal, but you suspect that some behavioral detection capabilities are turned off. Based on the output, which setting should you modify?

A.Set DisableBehaviorMonitoring to False to enable behavior monitoring.
B.Enable cloud-delivered protection by setting MAPSReporting to Advanced.
C.Set DisableBlockAtFirstSeen to True to enable Block at First Sight.
D.Set DisableRealtimeMonitoring to True to enable real-time monitoring.
AnswerA

The existing output lists `DisableBehaviorMonitoring : True`, and because `Set-MpPreference` uses Boolean settings where `True` disables the corresponding feature, behavior monitoring is currently off. Running `Set-MpPreference -DisableBehaviorMonitoring $false` changes that value to `False`, turning on behavior monitoring. This Defender engine feature inspects process behavior, memory access, and system activity to detect fileless attacks and post-breach behaviors that static signature scanning may miss.

Why this answer

The PowerShell command output shows that DisableBehaviorMonitoring is set to True, which disables behavioral monitoring. Since the device is healthy but behavioral detection capabilities are suspected to be off, setting DisableBehaviorMonitoring to False re-enables behavior monitoring, allowing Defender for Endpoint to analyze runtime behavior for threats.

Exam trap

The trap here is that candidates confuse 'behavior monitoring' with 'real-time monitoring' or 'cloud-delivered protection,' leading them to select options that address unrelated security features instead of the specific setting shown in the PowerShell output.

How to eliminate wrong answers

Option B is wrong because MAPSReporting controls cloud-delivered protection (Microsoft Active Protection Service membership), not behavioral monitoring; setting it to Advanced enables cloud-based detection but does not address the disabled behavior monitoring. Option C is wrong because DisableBlockAtFirstSeen controls the Block at First Sight feature, which uses cloud intelligence to block new malware, but it is unrelated to behavioral monitoring. Option D is wrong because DisableRealtimeMonitoring controls real-time scanning for file-based threats; setting it to True would disable real-time monitoring, not enable it, and it does not affect behavioral monitoring.

388
Multi-Selectmedium

Which TWO Microsoft Entra ID features can be used to provide just-in-time (JIT) access to privileged roles?

Select 2 answers
A.Identity Protection
B.Privileged Identity Management (PIM)
C.Conditional Access
D.Access Reviews
E.Privileged Access Groups
AnswersB, E

Privileged Identity Management (PIM) is the primary Microsoft Entra ID service for just-in-time (JIT) access, enabling users to activate eligible role assignments for a limited time with justification and optional approval. During activation, the role is temporarily added to the user's list of active assignments, and after the maximum duration (for example, 8 hours) it automatically expires. PIM also provides audit history and alerts for activations, making it the correct answer for time-bound role elevation.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) access by allowing users to activate eligible role assignments for a limited time, with approval workflows and auditing. Privileged Access Groups extend JIT capabilities by enabling time-bound membership in groups that grant access to Azure AD roles or Azure resources, ensuring temporary elevation only when needed.

Exam trap

The trap here is that candidates confuse Access Reviews (a recertification tool) with JIT activation, or think Conditional Access can provide time-bound role elevation when it only controls access to apps, not role assignments.

389
MCQmedium

A company uses Microsoft Defender for Cloud Apps to monitor cloud app usage. They want to receive alerts when a user downloads a large number of files from SharePoint Online in a short time, which could indicate data exfiltration. What should they configure?

A.Session policy
B.Anomaly detection policy
C.File policy
D.Activity policy
AnswerD

Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against detection criteria, so a threshold rule on SharePoint Online download volume within a set timeframe triggers alerts for suspected exfiltration. This directly satisfies the requirement to detect bulk file downloads, unlike anomaly or file policies.

Why this answer

(Activity policy) is correct because activity policies allow you to monitor specific activities like mass download from SharePoint Online and trigger alerts. Option A (Session policy) is used to control access in real-time, not for alerting on historical activity. Option B (Anomaly detection policy) detects unusual user behavior but is less specific to a defined threshold of file downloads.

Option C (File policy) focuses on file sharing and external sharing policies, not download volume. Therefore, an activity policy is the best choice for configuring alerts on large file downloads indicating data exfiltration.

390
MCQmedium

A compliance administrator needs to automatically apply a retention label to all documents in a SharePoint Online site that contain Social Security numbers. The label should retain the documents for 5 years and then automatically delete them. Which feature should they configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with auto-labeling
C.retention label with auto-labeling
D.An information barrier policy
AnswerC

Auto-labeling retention labels use sensitive information types, such as Social Security numbers, to detect matching content and apply the label automatically. The label's retention settings then retain documents for five years before deleting them, meeting both requirements.

Why this answer

Retention labels with auto-labeling are designed to automatically apply retention settings based on sensitive information types, such as Social Security numbers, and can enforce a retention period (5 years) followed by automatic deletion. This feature is part of Microsoft Purview's records management and uses trainable classifiers or sensitive info types to trigger the label assignment on SharePoint Online documents.

Exam trap

The trap here is that candidates confuse DLP policies (which detect and protect) with retention labels (which manage lifecycle), leading them to choose Option A because both involve sensitive data detection, but only retention labels can enforce deletion after a set period.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy detects and protects sensitive data but does not apply retention labels or manage lifecycle actions like retention and deletion; DLP policies block or warn, not retain. Option B is wrong because sensitivity labels with auto-labeling focus on classification and protection (encryption, markings) rather than retention and deletion schedules; they do not enforce a 5-year retention followed by automatic deletion. Option D is wrong because an information barrier policy restricts communication and collaboration between groups, not document lifecycle management or retention labeling.

391
Drag & Dropmedium

Drag and drop the steps to configure a Conditional Access policy in Microsoft Entra ID in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Conditional Access policies are created in Entra ID, assigned to users, conditions defined, and access controls applied.

392
MCQeasy

Your company uses Microsoft Defender XDR. You need to review the list of incidents that were investigated automatically by the system. Where should you navigate in the Microsoft Defender portal?

A.Hunting
B.Action center
C.Reports
D.Incidents & alerts > Incidents
AnswerD

Incidents & alerts > Incidents is the central queue in the Microsoft 365 Defender portal where all security incidents—including those already escalated and automated investigations—are listed and managed. Each incident page consolidates related alerts from various workloads, affected assets, and the attack story, making it the correct location for reviewing and responding to incidents.

Why this answer

The 'Incidents & alerts > Incidents' section in the Microsoft Defender portal is the dedicated location where all incidents, including those automatically investigated by Microsoft Defender XDR's automated investigation and response (AIR) capabilities, are listed and managed. This view shows the incident queue, including the 'Investigation state' column that indicates whether an investigation was initiated automatically or manually, allowing you to filter and review system-initiated investigations.

Exam trap

The trap here is that candidates often confuse the 'Action center' (which shows remediation actions) with the incident list, mistakenly thinking that automated investigations are tracked there, but the Action center only shows the resulting actions, not the incidents or their investigation state.

How to eliminate wrong answers

Option A is wrong because 'Hunting' is used for proactive, custom threat hunting using Kusto Query Language (KQL) to search raw telemetry data, not for reviewing incidents that were already investigated automatically. Option B is wrong because the 'Action center' lists pending and completed remediation actions (e.g., quarantine, block) taken during investigations, but it does not show the incidents themselves or their investigation status. Option C is wrong because 'Reports' provides aggregated security trends and summary metrics (e.g., threat detection volume, response times), not a granular list of individual incidents or their automated investigation details.

393
Multi-Selectmedium

Which TWO actions can be performed by Microsoft Defender for Identity? (Select TWO.)

Select 2 answers
A.Manage firewall rules on endpoints.
B.Monitor domain controller activities and behavior.
C.Identify lateral movement paths in your network.
D.Scan files for malware in real time.
E.Block sign-in attempts from malicious IP addresses.
AnswersB, C

Microsoft Defender for Identity monitors domain controller activities and behaviour, satisfying the stem's requirement. It analyses authentication traffic and replication events on domain controllers to detect reconnaissance, lateral movement, and credential theft, without deploying agents on those servers.

Why this answer

Microsoft Defender for Identity is a cloud-based security solution that uses on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. It monitors domain controller activities and security events to detect suspicious behavior (Option B). It also identifies lateral movement paths by analyzing network activities and user behavior to find potential attack paths (Option C).

Option A is incorrect because managing firewall rules on endpoints is not a function of Defender for Identity; that is typically done by Microsoft Defender for Endpoint. Option D is incorrect because real-time file scanning is performed by Microsoft Defender Antivirus, not Defender for Identity. Option E is incorrect because blocking sign-ins from malicious IPs is handled by Azure AD Conditional Access or Identity Protection, not Defender for Identity.

394
MCQeasy

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The legal department requires that all email messages sent to and from the tenant be retained for seven years, and that users cannot permanently delete messages before that period ends. The solution must apply to all mailboxes, including new ones created later, and must not require users to apply retention labels manually. What should you do?

A.Create a retention policy in Microsoft Purview that retains Exchange email for seven years, applies to all Exchange mailboxes, and configure the policy to retain items at the end of the retention period.
B.Enable a litigation hold on each mailbox by using Exchange Online PowerShell for all current users, and repeat the process whenever a new user is created.
C.Create a data loss prevention policy that blocks users from deleting email messages that contain sensitive information.
D.Create a retention label with a seven-year retention period, publish it to all users, and instruct users to apply it to their messages.
AnswerA

A retention policy in Microsoft Purview can target all Exchange mailboxes, including future ones, and applies automatically without user action. Setting the retention period to seven years and choosing to retain rather than delete keeps items and prevents users from permanently removing them before the period expires, satisfying the legal hold requirement.

Why this answer

A Microsoft Purview retention policy applies retention settings at the workload and location level, so Exchange email can be retained for seven years across all current and future mailboxes without user or administrator action. Configuring the policy to retain items preserves them and prevents permanent deletion during the retention period, which meets the legal department's requirement.

Exam trap

The trap here is choosing a retention label or litigation hold, which either requires manual application or does not automatically cover mailboxes created later.

395
MCQhard

Your organization uses Microsoft Defender for Identity and has enabled Microsoft Secure Score. You notice that the Secure Score for Identity has dropped significantly after a recent configuration change. Which action is most likely to have caused the decrease?

A.Changing password expiration policy to 180 days.
B.Enabling MFA for all users.
C.Disabling password hash synchronization in Microsoft Entra Connect.
D.Implementing a conditional access policy blocking legacy authentication.
AnswerC

Disabling password hash synchronization (PHS) in Microsoft Entra Connect lowers Microsoft Secure Score for Identity because Defender for Identity relies on PHS to obtain on-premises password hashes for leaked-credential analysis and lateral movement path detection. Without PHS, Microsoft Entra ID loses a crucial data source that helps correlate on-premises and cloud activities, impairing the ability to identify compromised accounts and reducing the overall identity threat detection visibility. As a result, the identity protection pillar of Secure Score decreases, making this the correct action.

Why this answer

Disabling password hash synchronization (PHS) in Microsoft Entra Connect removes the ability for Microsoft Defender for Identity to correlate on-premises Active Directory credential exposure events with cloud authentication attempts. Without PHS, Defender for Identity cannot detect when leaked credentials are used against Azure AD, causing the Secure Score for Identity to drop because key detection capabilities are no longer available.

Exam trap

The trap here is that candidates often assume disabling password hash synchronization is a security improvement (to avoid storing hashes in the cloud), but they overlook that Defender for Identity requires it for critical leaked credential detection, and Secure Score penalizes its absence.

How to eliminate wrong answers

Option A is wrong because changing password expiration policy to 180 days does not directly affect Defender for Identity's detection capabilities or Secure Score; it may even reduce risk by encouraging longer passwords, but Secure Score for Identity focuses on configuration and detection health, not password age. Option B is wrong because enabling MFA for all users improves security posture and typically increases Secure Score, not decreases it. Option D is wrong because implementing a conditional access policy blocking legacy authentication reduces attack surface and improves security, which would raise Secure Score for Identity, not lower it.

396
MCQhard

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. Users are sharing credit card numbers in Teams chat messages. You have a DLP policy that detects credit card numbers and blocks the message. However, users report that they can still send messages containing credit card numbers without any block. What is the most likely reason?

A.The DLP policy for Teams is only applied when external users are part of the chat.
B.The DLP policy does not apply to transient messages like chat.
C.The DLP policy is not configured to include the users' group.
D.The DLP policy only applies to channel messages, not private chats.
AnswerA

Microsoft Purview DLP policies for Teams chats are often configured with a scope that specifically targets communications involving external participants. If the policy's application is limited to chats where external users are present, then internal-only Teams conversations would fall outside its enforcement scope. This explains why users can still send messages containing credit card numbers without being blocked in internal chats, directly addressing the scenario where the policy is not effective.

Why this answer

DLP for Teams chat messages only scans messages that include at least one user from outside the organization (external users). If both sender and recipient are internal, the policy does not apply. Option B is incorrect because DLP policies can be scoped to specific users.

Option C is incorrect because Teams DLP policies cover both chat and channel messages. Option D is incorrect because DLP policies apply to both persistent and transient messages.

397
MCQhard

Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove messages identified as malware from all mailboxes after delivery. What should you configure?

A.Configure an anti-malware policy with a high-confidence verdict.
B.Enable Zero-hour auto purge (ZAP) in the anti-malware policy.
C.Set up a mailbox intelligence policy.
D.Create an anti-phishing policy to block spoofed senders.
AnswerB

Enabling Zero-hour auto purge (ZAP) in the anti-malware policy instructs the service to continually re-evaluate delivered messages against updated threat intelligence. For malware specifically, ZAP detects a zero-day or newly identified malware payload in an already delivered email and automatically deletes or quarantines the message from the user's mailbox. This is the correct control for post-delivery remediation, which is why it satisfies the requirement.

Why this answer

Zero-hour auto purge (ZAP) is the correct feature because it automatically detects and removes messages that are identified as malware after they have already been delivered to a user's mailbox. By enabling ZAP in the anti-malware policy, the system retroactively moves malicious messages to the user's Junk Email folder or quarantines them, ensuring post-delivery protection without manual intervention.

Exam trap

The trap here is that candidates often confuse ZAP with initial filtering policies, assuming that configuring a high-confidence verdict in the anti-malware policy alone will handle post-delivery removal, when in fact ZAP must be explicitly enabled for that purpose.

How to eliminate wrong answers

Option A is wrong because configuring an anti-malware policy with a high-confidence verdict only affects the initial filtering and delivery decision; it does not automatically remove messages that were already delivered. Option C is wrong because a mailbox intelligence policy is part of Exchange Online Protection (EOP) for detecting unusual sending patterns and user compromise, not for removing malware after delivery. Option D is wrong because an anti-phishing policy targets spoofed senders and phishing attempts, not malware removal, and does not provide post-delivery cleanup.

398
MCQmedium

Your organization plans to allow external users to access a SharePoint Online site using their own Microsoft Entra ID credentials. You need to ensure that external users can authenticate without creating a guest account in your tenant. Which solution should you use?

A.Configure B2B collaboration
B.Create external users as members
C.Configure B2B direct connect
D.Use Microsoft Entra Verified ID
AnswerC

Configure B2B direct connect – incorrect because this feature is limited to Teams Connect shared channels and does not support SharePoint Online site access.

Why this answer

Microsoft Entra B2B direct connect allows users from another Microsoft Entra tenant to access SharePoint Online sites and OneDrive using their own home tenant credentials without creating guest accounts in your tenant. It is configured through cross-tenant access settings and supports SharePoint Online and OneDrive in addition to Teams shared channels. B2B collaboration (A) creates guest user objects in your tenant, so it does not meet the requirement.

Creating external users as members (B) also provisions user objects in the tenant. Microsoft Entra Verified ID (D) is a decentralized identity verification service and does not by itself grant external users access to SharePoint Online without a guest account.

Exam trap

The trap is assuming B2B direct connect only works for Teams Connect shared channels. In current Microsoft Entra and SharePoint Online, B2B direct connect also supports SharePoint and OneDrive access without guest accounts. Another trap is selecting Microsoft Entra Verified ID, which is for identity verification, not for cross-tenant SharePoint authentication.

How to eliminate wrong answers

Option A is wrong because B2B collaboration requires creating guest user objects in your tenant to represent external users, which contradicts the requirement to avoid guest accounts. Option B is wrong because creating external users as members still involves provisioning user objects in your tenant, and it does not leverage the external user's own Microsoft Entra ID credentials for direct authentication. Option D is wrong because Microsoft Entra Verified ID is a decentralized identity verification solution using verifiable credentials, not designed for direct authentication to SharePoint Online without guest accounts.

399
MCQmedium

Your company uses Microsoft 365 and has recently deployed Microsoft Intune for mobile device management. You need to ensure that corporate data on iOS devices is protected by preventing users from copying data from managed apps to unmanaged apps. What should you configure?

A.Mobile application management (MAM) without enrollment.
B.Device compliance policies.
C.Conditional Access policies.
D.App protection policies.
AnswerD

App protection policies in Microsoft Intune are specifically designed to manage data protection at the application layer, including settings to prevent copy-paste of organizational data into unmanaged apps. These policies can be assigned directly to users across devices with or without MDM enrollment, making them the correct mechanism for this scenario. For example, the 'Restrict cut, copy, and paste' policy mode can block the action entirely or allow it only between managed apps.

Why this answer

App protection policies (APP) are the correct choice because they provide mobile application management (MAM) controls that specifically prevent data transfer between managed and unmanaged apps on iOS devices. Unlike device-level policies, APP operates at the application layer, allowing you to restrict copy/paste, cut, and data sharing actions without requiring device enrollment. This directly addresses the requirement to protect corporate data on iOS devices by blocking data leakage to unmanaged apps.

Exam trap

The trap here is that candidates confuse the deployment model (MAM without enrollment) with the actual policy configuration (app protection policies), or they mistakenly think device compliance or Conditional Access can control app-level data sharing, which they cannot.

How to eliminate wrong answers

Option A is wrong because MAM without enrollment (also known as MAM-WE) is a deployment model, not a specific policy configuration; while it can use app protection policies, the question asks what to configure, and the correct configuration is the app protection policy itself, not the deployment model. Option B is wrong because device compliance policies enforce device-level security requirements (e.g., jailbreak detection, passcode compliance) but do not control data transfer between apps at the application layer. Option C is wrong because Conditional Access policies control access to resources based on signals like device compliance or location, but they do not directly restrict copy/paste or data sharing between managed and unmanaged apps.

400
MCQhard

Your company uses Microsoft Purview Data Lifecycle Management. You have a policy that retains items for 3 years and then deletes them. A user places an eDiscovery hold on a folder that contains items subject to this policy. What happens to those items after 3 years?

A.They are retained for an additional 3 years.
B.They are deleted after 3 years.
C.They are preserved until the hold is removed.
D.They are moved to a separate location.
AnswerC

An eDiscovery hold overrides the retention policy's deletion action, so items are kept rather than removed at three years. Preservation continues until the hold is released, satisfying the hold's requirement to retain potentially relevant content.

Why this answer

eDiscovery hold takes precedence over the deletion policy. Items under a hold are preserved indefinitely until the hold is removed, regardless of any retention and deletion policies. Option C correctly states they are preserved until the hold is removed.

Option A is incorrect because hold overrides the policy, not extending it. Option B is incorrect because items are not deleted while under hold. Option D is incorrect because items are not moved to a separate location.

401
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Purview auto-labeling policy configuration. The SensitivityTypes GUID corresponds to a sensitive info type that detects credit card numbers. The LabelId is for a 'Confidential' label. Users report that documents containing credit card numbers are not being automatically labeled. What is the most likely reason?

A.The 'Confidential' label is not published to users.
B.The sensitive info type GUID is incorrect.
C.Users do not have the appropriate license for auto-labeling.
D.The auto-labeling policy is not scoped to the correct locations (e.g., SharePoint, Exchange).
AnswerD

For an auto-labeling policy to apply labels, it must be explicitly scoped to the locations where content resides, such as SharePoint sites, Exchange mailboxes, and OneDrive. The exhibit shows that the policy does not include these locations, or includes only a subset, so the policy never scans the content. Without proper location scoping, no labeling occurs even if the label and SIT are configured correctly.

Why this answer

Auto-labeling policies in Microsoft Purview must be scoped to the locations where the sensitive data resides (Exchange, SharePoint, OneDrive, etc.). If the policy is not scoped to the correct locations, documents containing credit card numbers in those locations will never be evaluated, so no automatic labeling occurs. This is the most common configuration oversight when auto-labeling appears to do nothing.

Exam trap

The trap is focusing on label publication or licensing when the most common cause of silent auto-labeling failure is a misconfigured policy scope that omits the locations where the sensitive data actually resides.

How to eliminate wrong answers

Option A is wrong because if the 'Confidential' label were not published to users, manual labeling would fail, but auto-labeling uses the label's ID directly and does not require the label to be published to users for the policy to apply. Option B is wrong because an incorrect sensitive info type GUID would cause the policy to match nothing, but the question states the GUID corresponds to a credit card SID — the exhibit confirms it is correct. Option C is wrong because licensing issues would typically prevent policy creation or show explicit license errors, not silent non-labeling of matching documents.

402
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Entra ID Governance access review. The JSON shows an access review scope for a SharePoint site. What does the 'isExternallyAccessible': false setting indicate about the site?

A.The site's external sharing settings are not reviewed.
B.External users cannot access the site.
C.The site is configured to allow sharing with anyone.
D.External users are automatically granted access.
AnswerB

This is correct because the external sharing level is configured to 'Only people in your organization' (or equivalent), which prevents any external users from accessing the site. Even if external users receive a link, they will be blocked by the site's sharing policy. This setting ensures that only authenticated users within the tenant can view or edit content.

Why this answer

The 'isExternallyAccessible': false setting in the access review scope JSON indicates that the SharePoint site is not configured to allow external sharing. This means external users cannot access the site, making option B correct. The setting directly controls whether the site is visible to external identities in the access review, not the review process itself.

Exam trap

The trap here is that candidates confuse 'isExternallyAccessible' with the access review's review scope filtering, thinking it means the site is excluded from review, when it actually indicates the site's external sharing state.

How to eliminate wrong answers

Option A is wrong because 'isExternallyAccessible' controls the site's external sharing configuration, not whether the sharing settings are reviewed; access reviews always evaluate the site's sharing state. Option C is wrong because 'isExternallyAccessible': false explicitly means the site does not allow sharing with anyone (including 'Anyone' links), which would require the setting to be true. Option D is wrong because external users are not automatically granted access when the setting is false; they are explicitly blocked from accessing the site.

403
MCQeasy

Refer to the exhibit. You are configuring permissions for a daemon application that runs without a user. Which permission should you request?

A.User.Read.All application permission with admin consent.
B.Mail.Read delegated permission with admin consent.
C.Delegated permission type for User.Read.All.
D.User.Read.All delegated permission with user consent.
AnswerA

In an app-only daemon flow, the client authenticates with its own credentials and has no signed-in user, so the application permission is the only usable type. The exhibit shows User.Read.All with type 'Application' and adminConsentRequired true, indicating the tenant admin must consent because this scope can read every user's profile. This exactly matches the requirement for the background service.

Why this answer

For a daemon application that runs without a user, you must request an application permission (not delegated) because there is no signed-in user to delegate permissions. User.Read.All application permission allows the app to read all users' full profiles without a user context, and admin consent is required because this permission grants access to data across the entire organization.

Exam trap

The trap here is that candidates often confuse delegated and application permissions, assuming admin consent alone makes a delegated permission suitable for a daemon app, but delegated permissions always require a user context even with admin consent.

How to eliminate wrong answers

Option B is wrong because Mail.Read delegated permission requires a signed-in user context, which a daemon application does not have; delegated permissions are for user-interactive apps. Option C is wrong because Delegated permission type for User.Read.All still requires a user to be present, and the question specifies the app runs without a user. Option D is wrong because User.Read.All delegated permission with user consent cannot be used by a daemon app (no user to consent) and delegated permissions are inappropriate for non-interactive scenarios.

404
MCQhard

A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?

A.Sensitivity labels with encryption and usage rights
B.Data Loss Prevention (DLP) policy
C.Information Barriers
D.Microsoft Purview Information Protection without encryption
AnswerA

Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.

Why this answer

Sensitivity labels with encryption and usage rights allow administrators to apply Azure Rights Management (Azure RMS) protection to documents, which can restrict actions such as printing and copying. By configuring a sensitivity label with specific usage rights (e.g., 'View Only' or disabling 'Extract' and 'Print'), external users are prevented from printing or copying content even after the document is downloaded or accessed in SharePoint Online. This is the only Purview feature that directly enforces persistent content-level restrictions on external users.

Exam trap

The trap here is that candidates often confuse DLP policies with content protection, assuming DLP can restrict printing or copying after access, when in fact DLP only controls data in transit or at rest and does not enforce persistent usage rights on the document itself.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies detect and block sensitive information from being shared or exfiltrated, but they do not enforce persistent usage restrictions like preventing printing or copying after access is granted. Option C is wrong because Information Barriers are designed to prevent communication and collaboration between specific groups or users (e.g., to avoid conflicts of interest), not to control document-level actions like printing or copying. Option D is wrong because Microsoft Purview Information Protection without encryption applies labels for classification and auditing but does not enforce any technical restrictions on content usage; encryption is required to enforce usage rights.

405
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra Connect. You are planning to migrate to cloud-only authentication using Microsoft Entra Cloud Sync. However, some legacy applications still require NTLM authentication. What should you do to ensure those applications can authenticate after the migration?

A.Use Microsoft Entra Application Proxy to publish the legacy applications
B.Enable pass-through authentication (PTA)
C.Configure Microsoft Entra Cloud Sync with password hash sync
D.Deploy Microsoft Entra Password Protection
AnswerA

Microsoft Entra Application Proxy publishes legacy on-premises applications through a cloud entry point, and after the user authenticates to Microsoft Entra ID, the connector uses Kerberos Constrained Delegation (KCD) to communicate with the back-end application using NTLM or Kerberos. This provides true single sign-on for legacy apps that require integrated Windows authentication without modifying the application code. It is the only option here that actually relays the app-level authentication protocol.

Why this answer

Microsoft Entra Application Proxy allows you to publish on-premises legacy applications that rely on NTLM authentication without requiring any changes to the application itself. It acts as a reverse proxy, terminating the external connection and then forwarding the request to the internal application using Kerberos or NTLM, thus enabling cloud-only authentication while preserving NTLM support for legacy apps.

Exam trap

The trap here is that candidates often confuse authentication methods (like PTA or PHS) with application publishing solutions, mistakenly thinking that changing the authentication flow itself will fix legacy app compatibility, when in fact a reverse proxy like Application Proxy is required to relay NTLM traffic.

How to eliminate wrong answers

Option B is wrong because pass-through authentication (PTA) is an authentication method for validating user passwords against on-premises Active Directory, but it does not provide a mechanism to publish or proxy legacy NTLM-based applications; it only handles user sign-in. Option C is wrong because Microsoft Entra Cloud Sync with password hash sync synchronizes password hashes to the cloud for cloud authentication, but it does not enable legacy applications to continue using NTLM after migration; those apps still need a way to receive NTLM requests from external users. Option D is wrong because Microsoft Entra Password Protection is a feature to block weak passwords and enforce custom banned password lists; it has no role in enabling NTLM authentication for legacy applications.

406
MCQmedium

A company uses Microsoft Defender for Office 365. They want to ensure that users cannot ignore warning messages when clicking on a malicious link in an email. What should they configure?

A.Configure the anti-phishing policy with 'Impersonation protection' enabled.
B.Configure a Safe Links policy with 'Do not allow users to click through to original URL' selected.
C.Enable the 'Anti-malware' policy with 'Common attachments filter'.
D.Configure a Safe Attachments policy with 'Block' action.
AnswerB

A Safe Links policy with 'Do not allow users to click through to original URL' selected is the definitive control for stopping users from bypassing URL threat warnings. When a recipient clicks a link that Safe Links has evaluated as malicious or suspicious, Microsoft displays an interstitial warning page; this setting removes any 'proceed anyway' or 'continue to site' link, forcing a hard block. This directly addresses the stated requirement and is the only option among those listed that governs click-through behavior on links in email messages.

Why this answer

Safe Links policies include a setting 'Do not allow users to click through to the original URL' (or 'Block the following URLs' / 'Let users click through to the original URL' toggles). Selecting the option to prevent click-through ensures users cannot bypass the warning page and reach a malicious link. This is the direct control for the requirement.

Exam trap

The trap is that 'warning messages' sounds like anti-phishing or Safe Attachments, but the specific control for preventing click-through is a Safe Links policy setting — candidates must know which policy owns URL click behavior.

How to eliminate wrong answers

Option A is wrong because anti-phishing impersonation protection detects spoofed senders/domains but does not control URL click-through behavior. Option C is wrong because anti-malware with common attachments filter blocks attachment types — it has nothing to do with URL click-through. Option D is wrong because Safe Attachments with Block action detonates and blocks malicious attachments, not URLs; URL click-through is a Safe Links function.

407
MCQeasy

You are implementing Microsoft Entra ID Governance. You need to automate the creation of guest user accounts when employees submit a request through the company's HR system. What should you use?

A.Microsoft Entra Verified ID
B.Access Reviews
C.Microsoft Entra ID Protection
D.Lifecycle Workflows
AnswerD

Lifecycle Workflows in Microsoft Entra ID Governance are specifically designed to automate identity lifecycle tasks, including the creation of guest user accounts. They can be configured with custom execution conditions or triggered programmatically via API, enabling integration with external systems like an HR system. This allows for the automated provisioning of guest accounts precisely when an employee request is submitted through the HR system, satisfying the need for automated, event-driven account creation.

Why this answer

Lifecycle Workflows (D) is the correct choice because it is the Microsoft Entra ID Governance feature designed to automate identity lifecycle processes, including the creation of guest user accounts triggered by events such as HR system submissions. It uses built-in or custom workflows with tasks like 'Create user' and 'Send email' to handle the entire provisioning flow without manual intervention.

Exam trap

The trap here is that candidates often confuse Lifecycle Workflows with Access Reviews or ID Protection because all three fall under 'Identity Governance', but only Lifecycle Workflows provides the actual provisioning automation for HR-driven account creation.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Verified ID is a decentralized identity verification solution using verifiable credentials (based on W3C standards), not an automation tool for creating guest accounts from HR triggers. Option B is wrong because Access Reviews are used for periodic attestation and recertification of existing access rights, not for provisioning new accounts. Option C is wrong because Microsoft Entra ID Protection focuses on detecting and mitigating identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not include workflow automation for user creation.

408
MCQmedium

Your company uses Microsoft Entra ID and has a custom line-of-business application that supports SAML-based SSO. You need to configure the application to use Microsoft Entra ID as the identity provider. Which enterprise application configuration should you use?

A.Linked Sign-on
B.SAML-based Sign-on
C.Password-based Sign-on
D.OpenID Connect-based Sign-on
AnswerB

SAML-based Sign-on is correct because it enables true federated single sign-on between Microsoft Entra ID and a custom application that supports the SAML 2.0 standard. Entra ID acts as the identity provider, authenticates the user, and sends a digitally signed SAML assertion to the app's ACS (Assertion Consumer Service) URL, allowing the app to trust the assertion without prompting for credentials again. This is the recommended SSO method for non-gallery enterprise applications, especially older line-of-business apps that lack support for modern OAuth/OIDC protocols.

Why this answer

The application supports SAML-based SSO, so the correct enterprise application configuration is SAML-based Sign-on. This allows Microsoft Entra ID to act as the identity provider by exchanging SAML assertions with the application, enabling federated authentication.

Exam trap

The trap here is that candidates may confuse SAML-based Sign-on with OpenID Connect because both are federated protocols, but the question explicitly states the application supports SAML, not OIDC.

How to eliminate wrong answers

Option A is wrong because Linked Sign-on is used to link an existing user account in an external identity provider to Microsoft Entra ID, not to configure SAML-based SSO. Option C is wrong because Password-based Sign-on uses a password vaulting approach where Microsoft Entra ID stores and replays credentials, which does not leverage SAML assertions. Option D is wrong because OpenID Connect-based Sign-on is built on OAuth 2.0 and uses ID tokens (JWT) instead of SAML assertions, making it incompatible with an application that specifically supports SAML-based SSO.

409
MCQeasy

A company has just purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. They want to verify domain ownership. Which DNS record type must they add to their DNS provider?

A.MX record
B.CNAME record
C.TXT record
D.SPF record
AnswerC

The TXT record is the correct method because it is designed to hold arbitrary text, allowing you to publish the exact verification string Microsoft provides (e.g., MS=ms12345678). Microsoft's directory service queries the public DNS and looks for that unique token; if found, it proves you can modify DNS records and therefore own the domain. This is the standard mechanism used by Microsoft 365 and Azure AD to verify domain control without affecting mail routing or other services.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification string provided by the Microsoft 365 admin center. The TXT record is the standard DNS record type used for domain validation because it can store arbitrary text data without affecting email routing or other services. Microsoft 365 checks for this specific TXT record to confirm you control the domain.

Exam trap

The trap here is that candidates often confuse the TXT record used for domain verification with the SPF record, which is also a TXT record type, but SPF is specifically for email authentication and not for proving domain ownership.

How to eliminate wrong answers

Option A is wrong because an MX record specifies the mail server for the domain and is used for email routing, not domain ownership verification. Option B is wrong because a CNAME record aliases one domain name to another and is not used for domain validation; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record subtype that authorizes email senders and is not used for domain ownership verification; adding an SPF record alone does not prove domain control.

410
MCQmedium

You are a Microsoft 365 administrator. You run the Get-MgPolicyCrossTenantAccessPolicyDefault cmdlet and see the exhibit output. What does this configuration imply?

A.Your tenant will accept compliant device claims from external tenants
B.Your tenant will accept MFA claims from a specific partner tenant
C.Your tenant will accept MFA claims from all external Microsoft Entra tenants
D.Your tenant blocks all inbound B2B collaboration
AnswerC

This is correct. The default cross-tenant access policy you retrieved shows IsMfaAccepted equal to true, so your tenant will trust the MFA claim for external users from any Microsoft Entra tenant when they access your resources. With this setting, Azure AD Conditional Access treats the external user as having completed MFA in their home tenant, reducing friction while still enabling security policies.

Why this answer

The Get-MgPolicyCrossTenantAccessPolicyDefault cmdlet retrieves the default cross-tenant access policy settings. The exhibit output shows that the InboundTrust property is configured to accept MFA claims from all external Microsoft Entra tenants, meaning your tenant will trust MFA claims made by users from any external Entra tenant without requiring them to re-authenticate.

Exam trap

The trap here is confusing the default cross-tenant access policy (which applies to all external tenants) with partner-specific policies, leading candidates to incorrectly select a specific partner option when the default policy is being examined.

How to eliminate wrong answers

Option A is wrong because accepting compliant device claims requires the 'IsCompliantDevice' flag to be set in the InboundTrust property, which is not indicated in the exhibit. Option B is wrong because the default policy applies to all external tenants, not a specific partner tenant; specific partner tenant settings are configured via the Get-MgPolicyCrossTenantAccessPolicyPartner cmdlet. Option D is wrong because the exhibit does not show any block settings; blocking inbound B2B collaboration would require the B2B direct connect or B2B collaboration inbound settings to be set to 'blocked', which is not the case here.

411
MCQeasy

A compliance officer needs to preserve all mailbox data for a user who is under a legal investigation. The data must be preserved indefinitely, and no deletion (by the user or system) should be possible. Which Microsoft Purview feature should the officer use?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content indefinitely, including deleted items and prior versions, and blocks both user purges and automatic Exchange retention cleanup. In Exchange Online, Litigation Hold temporarily overrides deletion and applies an indefinite hold that is only lifted when the hold is explicitly removed by an administrator, making it a true preservation-for-compliance mechanism.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox content indefinitely, preventing any deletion by the user or automated processes like the Managed Folder Assistant. It ensures that data is immutable for eDiscovery purposes, meeting the compliance officer's requirement for indefinite preservation under legal investigation.

Exam trap

The trap here is that candidates often confuse Retention Policies with Litigation Hold, thinking a retention policy can indefinitely preserve data, but retention policies have configurable expiration periods and can allow deletion, whereas Litigation Hold provides an immutable, indefinite hold specifically for legal scenarios.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies can allow deletion after a specified period or apply actions like 'Delete' or 'Retain and Delete,' which does not guarantee indefinite preservation and can be overridden by user actions. Option C (Data Loss Prevention (DLP)) is wrong because DLP policies are designed to detect and prevent accidental sharing of sensitive data, not to preserve or hold mailbox data for legal purposes. Option D (Sensitivity labels) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or provide indefinite hold capabilities for mailbox items.

412
MCQhard

Your organization uses Microsoft Defender for Identity. You need to investigate an alert indicating a suspected lateral movement using pass-the-hash from a compromised workstation. Which entity should you prioritize examining in the investigation timeline?

A.The source workstation
B.The destination server
C.The compromised account
D.The network segment
AnswerC

The compromised account is the correct primary entity because pass-the-hash attacks abuse the NTLM hash of a user's password, allowing the attacker to authenticate as that user without knowing the plaintext. This account is the common thread across every lateral movement event, regardless of which source workstation or destination server is involved. Defender for Identity flags suspicious account activities such as anomalous sign-ins, TGT requests, or usage of the same hash from multiple hosts, making the account the central entity to correlate and trace in the investigation.

Why this answer

In a pass-the-hash (PtH) attack, the attacker uses the NTLM hash of a compromised account to authenticate to other systems. Microsoft Defender for Identity correlates the account's authentication events across multiple machines, so examining the compromised account in the investigation timeline reveals the full scope of lateral movement, including which workstations and servers were accessed using the stolen hash.

Exam trap

The trap here is that candidates often focus on the physical or network location (workstation or server) rather than the logical identity (the account) that carries the stolen hash across systems.

How to eliminate wrong answers

Option A is wrong because the source workstation is merely the initial entry point; focusing on it ignores the attacker's subsequent authentication attempts using the stolen hash. Option B is wrong because the destination server is only one target of the lateral movement; prioritizing it misses other systems the attacker may have accessed. Option D is wrong because the network segment is a broad grouping that does not pinpoint the specific account or authentication events involved in the PtH attack.

413
MCQhard

Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?

A.The B2BCollaborationOutbound setting is blocking access
B.The default cross-tenant access policy is set to block all
C.The B2BCollaborationInbound setting for Fabrikam does not allow any identities or applications
D.The B2BDirectConnectInbound setting is empty
AnswerC

The B2BCollaborationInbound section for Fabrikam is the exact place where Contoso must explicitly allow Fabrikam users, groups, and applications to participate in B2B collaboration. When this inbound section contains no entries at all, Microsoft Entra ID treats it as an implicit deny: no Fabrikam identities are authorized to be invited as B2B guests, and no Contoso applications are available for them to access. Because the exhibit shows an empty inbound B2B collaboration policy for Fabrikam, it actively blocks the invitation and sign-in flow for those external users, which directly causes the reported access failure.

Why this answer

The B2BCollaborationInbound setting for Fabrikam controls which external users and applications are allowed to access Contoso resources via B2B collaboration. If this setting does not allow any identities or applications, all inbound B2B collaboration attempts from Fabrikam will be blocked, even if the default cross-tenant access policy is permissive.

Exam trap

The trap here is that candidates confuse inbound vs. outbound settings or assume the default policy applies to explicitly configured tenants, when in fact a specific tenant policy overrides the default for that tenant.

How to eliminate wrong answers

Option A is wrong because the B2BCollaborationOutbound setting controls traffic leaving Contoso to Fabrikam, not inbound access from Fabrikam to Contoso. Option B is wrong because the default cross-tenant access policy applies to tenants not explicitly configured; since Fabrikam has a specific policy, the default policy does not apply. Option D is wrong because B2BDirectConnectInbound is used for Teams external access and shared channels, not for B2B collaboration invitations or resource access.

414
MCQmedium

A security analyst investigates a potential data exfiltration incident. The analyst identifies that a user's device has made multiple connections to an unknown external IP address using a custom port. Which Microsoft Defender XDR data source would provide the most detailed network communication logs for this investigation?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft 365 Defender portal alerts
AnswerC

Defender for Endpoint is the correct source because its sensor records detailed network communication events on each device, including the local process, destination IP, destination port, and protocol, which are stored in the DeviceNetworkEvents table for advanced hunting. These logs directly show an inbound or outbound connection that could represent exfiltration, with the process and user context needed for a full investigation.

Why this answer

Microsoft Defender for Endpoint (MDE) provides the most detailed network communication logs for this investigation because it captures full network events at the device level, including connections to external IP addresses on custom ports. MDE's advanced hunting schema includes the DeviceNetworkEvents table, which records source/destination IPs, ports, protocols, and process-level details, enabling precise analysis of anomalous outbound connections.

Exam trap

The trap here is that candidates often confuse the scope of Microsoft Defender for Cloud Apps, assuming it captures all network traffic, when in fact it only monitors cloud application usage and not raw endpoint network connections.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on email and collaboration threats (e.g., phishing, malware in attachments), not on device-level network traffic logs. Option B is wrong because Microsoft Defender for Cloud Apps provides visibility into cloud application usage and shadow IT, but it does not capture raw network connection logs from endpoints; it relies on API logs and traffic metadata from cloud apps. Option D is wrong because Microsoft 365 Defender portal alerts aggregate and correlate alerts from multiple sources but do not themselves store detailed network communication logs; they reference underlying data from MDE or other sources.

415
Multi-Selectmedium

Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant authentication for all users when accessing the Azure Management application. Which TWO authentication methods satisfy the requirement?

Select 2 answers
A.SMS one-time passcode
B.Windows Hello for Business
C.Microsoft Authenticator with number matching
D.FIDO2 security key
E.Voice call verification code
AnswersB, D

Windows Hello for Business implements the FIDO2 protocol to provide device-bound cryptographic credentials, with the private key stored in the TPM of the enrolled device. It requires something you have (device with TPM) and something you know (PIN) or are (biometrics), satisfying true multi-factor authentication. Because the key never leaves the device and the challenge is scoped to the specific resource, it resists phishing and credential replay attacks, making it a strong conditional-access authentication method.

Why this answer

Windows Hello for Business is a phishing-resistant authentication method because it uses a key pair bound to the device, requiring a biometric or PIN gesture that cannot be intercepted or replayed. It satisfies the Conditional Access requirement for phishing-resistant authentication when accessing the Azure Management application.

Exam trap

The trap here is that candidates often confuse 'strong authentication' (like number matching or OTP) with 'phishing-resistant' authentication, but only methods using asymmetric key cryptography bound to the device (Windows Hello for Business and FIDO2) meet the strict phishing-resistant definition under Microsoft's Conditional Access policies.

416
MCQeasy

An administrator needs to update the organization's display name, technical contact, and privacy statement URL in the Microsoft 365 admin center. Which page should they navigate to?

A.Settings > Org settings > Organization profile
B.Users > Active users > More actions > Edit contact info
C.Billing > Billing accounts > Edit organization info
D.Admin centers > Azure AD > Properties
AnswerA

The Microsoft 365 admin center path Settings > Org settings > Organization profile is the intended, tenant-wide location for editing the organization's display name, technical contact, privacy statement URL, default language, and country/region. These values are stored on the organization object in Microsoft Entra ID and surfaced across M365 services, so changing them here updates the banner, notification sender identity, and privacy links globally. No other admin center page exposes all of these fields together.

Why this answer

The 'Settings > Org settings > Organization profile' page in the Microsoft 365 admin center is the dedicated location for modifying tenant-wide metadata, including the organization's display name, technical contact email, and privacy statement URL. These settings are stored in the Microsoft 365 tenant's directory properties and are distinct from user-level or billing-level configurations.

Exam trap

The trap here is that candidates confuse the Azure AD tenant Properties blade (which shows the organization name and technical contact) with the Microsoft 365 admin center's Organization profile page, overlooking that the privacy statement URL is a Microsoft 365-specific setting not available in Azure AD.

How to eliminate wrong answers

Option B is wrong because 'Users > Active users > More actions > Edit contact info' modifies individual user contact details, not tenant-wide organization properties like the display name or privacy statement URL. Option C is wrong because 'Billing > Billing accounts > Edit organization info' manages billing-related account information (e.g., invoice address, payment method) and does not include the technical contact or privacy statement URL fields. Option D is wrong because 'Admin centers > Azure AD > Properties' opens the Azure AD tenant properties blade, which allows editing the organization name and technical contact but lacks the privacy statement URL field; the privacy statement URL is configured exclusively in the Microsoft 365 admin center's Organization profile page, not in Azure AD.

417
MCQmedium

Your organization has a Microsoft 365 tenant with a custom domain contoso.com. You have configured Exchange Online to accept emails for contoso.com. You now need to add a subdomain sales.contoso.com and ensure that email sent to sales.contoso.com is delivered to a specific shared mailbox. What should you do?

A.Add sales.contoso.com as a custom domain in the Microsoft 365 admin center and verify ownership.
B.Add sales.contoso.com as an accepted domain in Exchange Online and create a transport rule to redirect emails to the shared mailbox.
C.Configure an auto-expanding archive for the shared mailbox.
D.Create a distribution group named sales@contoso.com and add the shared mailbox as a member.
AnswerB

This is correct because an accepted domain in Exchange Online tells the service to accept email addressed to that domain (or subdomain). To make the subdomain deliverable, you must add sales.contoso.com as an accepted domain with the 'Internal Relay' or 'Authoritative' type. Then, a transport rule (mail flow rule) can be configured to match any recipient in that subdomain and redirect the message to the sales shared mailbox. This ensures all mail sent to @sales.contoso.com lands in the shared mailbox without needing separate mailboxes.

Why this answer

To route email for a subdomain to a specific mailbox, you must first add the subdomain as an accepted domain in Exchange Online (not as a custom domain in the admin center, since the parent domain is already verified). Then, you create a transport rule that matches recipients in that accepted domain and redirects the messages to the target shared mailbox. This ensures that all emails sent to sales.contoso.com are delivered to the designated mailbox without requiring additional MX records or domain verification.

Exam trap

The trap here is that candidates confuse adding a subdomain as a custom domain (which requires unnecessary DNS verification) with adding it as an accepted domain in Exchange Online, which is the correct approach for routing email to a specific mailbox without altering the parent domain's verification status.

How to eliminate wrong answers

Option A is wrong because adding sales.contoso.com as a custom domain in the Microsoft 365 admin center would require DNS verification (e.g., TXT record) for the subdomain, which is unnecessary and incorrect—the parent domain contoso.com is already verified, and subdomains inherit that verification; instead, you should add it as an accepted domain in Exchange Online. Option C is wrong because configuring an auto-expanding archive for the shared mailbox addresses storage capacity, not email routing for a subdomain. Option D is wrong because creating a distribution group with the shared mailbox as a member would not route emails sent to sales.contoso.com to that mailbox; it would only allow the group to receive emails sent to the group's address, and the subdomain routing is not configured.

418
MCQmedium

Refer to the exhibit. You are configuring consent for the Microsoft Graph application. Which of the following statements is true based on the JSON?

A.Users can consent to the User.Read.All permission.
B.The Mail.Read permission requires admin consent.
C.No consent is required for either permission.
D.The User.Read.All permission requires admin consent.
AnswerD

This is correct because the JSON entry for User.Read.All shows adminConsentRequired: true and userConsentPossible: false. User.Read.All grants access to every user's full profile across the organization, a high-privilege scope that Microsoft mandates be approved by an administrator to prevent lateral data exposure. A regular user cannot see an admin consent prompt or grant this permission, so tenant-wide admin consent is mandatory.

Why this answer

The JSON shows the User.Read.All permission has the 'AdminConsentRequired' property set to true, meaning it requires admin consent. The Mail.Read permission has 'AdminConsentRequired' set to false, so users can consent to it without admin involvement. Option D correctly identifies that User.Read.All requires admin consent.

Exam trap

The trap here is that candidates often assume all permissions with 'Read' in the name are user-consentable, but Microsoft marks permissions that access data across the entire organization (like User.Read.All) as requiring admin consent, while user-scoped reads (like Mail.Read) may not.

How to eliminate wrong answers

Option A is wrong because User.Read.All has 'AdminConsentRequired' set to true, so users cannot consent to it; admin consent is mandatory. Option B is wrong because Mail.Read has 'AdminConsentRequired' set to false, meaning it does not require admin consent; users can consent on their own. Option C is wrong because User.Read.All requires admin consent, so consent is required for at least one permission.

419
MCQeasy

A company has purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. The company wants all new users to have 'fabrikam.com' as their default email domain instead of the onmicrosoft.com domain. How should the administrator achieve this?

A.Update the MX record in the DNS to point to Microsoft 365 with the custom domain.
B.In the admin center, go to Settings > Domains, select the custom domain, and click 'Set as default'.
C.Use the Exchange admin center to set the default email address policy to use the custom domain.
D.For each new user, manually add an email alias with the custom domain and remove the onmicrosoft.com alias.
AnswerB

This is the correct method. In the Microsoft 365 admin center, navigating to Settings > Domains, selecting the verified custom domain, and clicking 'Set as default' changes the tenant-level default domain. Once set, all new users are automatically assigned a user principal name (UPN) and primary SMTP address using that custom domain, rather than the initial onmicrosoft.com domain. This is a global, automated setting that applies to every subsequently created user, making it the intended administrative control.

Why this answer

The Microsoft 365 admin center provides a dedicated setting under Settings > Domains to mark a custom domain as the default email domain. Once set as default, all new users will automatically receive a primary email address using that domain instead of the initial onmicrosoft.com domain, without requiring manual changes or additional configuration.

Exam trap

The trap here is that candidates often confuse DNS record management (like MX records) with tenant-level domain configuration, or assume that Exchange email address policies are the only way to control default domains, when in fact the admin center's 'Set as default' option is the correct and simplest method for new users.

How to eliminate wrong answers

Option A is wrong because updating the MX record only controls mail routing (where incoming emails are delivered), not the default email domain assigned to new users. Option C is wrong because the Exchange admin center's email address policy applies to existing mailboxes and can set domain preferences, but the default domain for new users is controlled at the tenant level in the Microsoft 365 admin center, not via an email address policy. Option D is wrong because manually adding and removing aliases for each new user is inefficient and unnecessary; the default domain setting automates this process for all new users.

420
MCQhard

Refer to the exhibit. The conditional access policy JSON shown above is applied to all users. A user authenticates from a trusted location and wants to access a cloud app. Which combination of controls will be enforced?

A.MFA, terms of use acceptance, sign-in frequency of 1 hour, and persistent browser never
B.Terms of use acceptance and persistent browser never only
C.MFA and terms of use acceptance only
D.MFA and sign-in frequency of 1 hour only
AnswerA

Despite the user authenticating from a trusted location, the conditional access policy's configuration dictates the enforced controls. The policy must explicitly include Multi-Factor Authentication (MFA) and terms of use acceptance within its grant controls, meaning these are required regardless of the trusted location status. Furthermore, the policy's session controls specify a sign-in frequency of 1 hour and persistent browser set to 'never', ensuring re-authentication and session termination after the specified period.

Why this answer

The conditional access policy JSON explicitly defines three grant controls: 'mfa' (require multi-factor authentication), 'termsOfUse' (require terms of use acceptance), and 'signInFrequency' (value 3600 seconds = 1 hour) combined with 'persistentBrowser' set to 'never'. Since the policy is applied to all users and the user authenticates from a trusted location, all specified controls are enforced simultaneously, as conditional access policies apply all grant controls in the 'grantControls' block unless overridden by session controls.

Exam trap

The trap here is that candidates often assume session controls (like sign-in frequency and persistent browser) are optional or ignored when grant controls are present, but in reality, all controls in both 'grantControls' and 'sessionControls' are enforced together unless explicitly conditional.

How to eliminate wrong answers

Option B is wrong because it omits the MFA requirement and the sign-in frequency control, both of which are explicitly listed in the JSON's 'grantControls' array. Option C is wrong because it ignores the 'signInFrequency' (value 3600 seconds) and 'persistentBrowser' (set to 'never') session controls, which are part of the policy's 'sessionControls' object and are enforced alongside grant controls. Option D is wrong because it omits the 'termsOfUse' grant control, which is included in the 'builtInControls' array as 'termsOfUse', and also ignores the 'persistentBrowser' session control.

421
MCQeasy

A security administrator wants to detect unusual user activity, such as a user downloading an abnormally large number of files from SharePoint Online in a short period. Which Microsoft Defender for Cloud Apps feature should be used to create a policy for this behavior?

A.Cloud Discovery
B.Conditional Access App Control
C.Anomaly detection policy
D.App permissions
AnswerC

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline normal user behaviour and alert on deviations such as mass file downloads from SharePoint Online. This matches the scenario's need to flag unusual activity rather than enforce static access rules.

Why this answer

Microsoft Defender for Cloud Apps uses anomaly detection policies to identify unusual user behavior, such as a user downloading an abnormally large number of files from SharePoint Online in a short period. These policies leverage machine learning to establish a baseline of normal activity and then trigger alerts when deviations occur, like a spike in download volume or rate.

Exam trap

The trap here is that candidates often confuse anomaly detection policies with Cloud Discovery, mistakenly thinking Cloud Discovery detects unusual user behavior, when in fact it only identifies unsanctioned cloud apps and services.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is designed to identify and analyze shadow IT usage by inspecting traffic logs from network proxies or firewalls, not to detect user-specific behavioral anomalies within sanctioned cloud apps like SharePoint Online. Option B is wrong because Conditional Access App Control enforces access policies (e.g., blocking downloads or requiring multi-factor authentication) at the session level, but it does not create detection policies for anomalous user behavior after access is granted. Option D is wrong because App permissions focuses on auditing and managing OAuth permissions granted to third-party apps, not on monitoring user download patterns or detecting unusual activity.

422
MCQhard

A company invites external partners as B2B guest users in Microsoft Entra ID. The partners' home tenants do not support MFA. The company wants to require MFA when guests access an internal application. What should the company configure?

A.Configure a Conditional Access policy that targets all guest users, require MFA, and enable MFA registration for guests in the resource tenant.
B.Ask the partners to configure MFA in their home tenant, then trust their MFA claims.
C.Use a Per-User MFA policy for guest users, but guests cannot register for MFA in the resource tenant.
D.Create a Conditional Access policy requiring MFA for all external users, but exclude guests from known networks.
AnswerA

A Conditional Access policy in the resource tenant can explicitly target guest users and apply the resource tenant's MFA requirements, independent of the home tenant's capabilities. Because the home tenants do not support MFA, the resource tenant must provide its own registration for guest users, which is enabled through MFA registration settings in the tenant. This ensures each guest can authenticate with methods governed by the resource tenant, fully satisfying the security requirement.

Why this answer

When guest users' home tenants do not support MFA, the resource tenant must enforce MFA directly. A Conditional Access policy targeting all guest users with 'Require MFA' grant control, combined with enabling MFA registration for guests in the resource tenant, allows guests to register and use MFA methods (e.g., Microsoft Authenticator) within the resource tenant. This ensures MFA is enforced regardless of the home tenant's capabilities.

Exam trap

The trap here is that candidates often assume MFA must be handled by the home tenant (Option B) or that legacy Per-User MFA (Option C) works for guests, but Microsoft Entra ID requires Conditional Access policies and resource-tenant MFA registration for guest users when the home tenant cannot provide MFA claims.

How to eliminate wrong answers

Option B is wrong because the partners' home tenants do not support MFA, so asking them to configure MFA is not feasible, and trusting their MFA claims would require the home tenant to issue MFA claims, which it cannot. Option C is wrong because Per-User MFA is a legacy policy that does not support guest user registration in the resource tenant; guests cannot register for MFA via Per-User MFA, making it ineffective. Option D is wrong because excluding guests from known networks does not address the requirement to require MFA; it would actually bypass MFA for guests on known networks, weakening security.

423
MCQeasy

You are a Microsoft 365 administrator for Litware Inc. The company uses Microsoft Purview Records Management. A file plan has been created with a retention label named 'Project Alpha'. You need to ensure that documents labeled 'Project Alpha' are retained for five years after the project ends, and then automatically deleted. What should you configure on the retention label?

A.Set the retention period to five years and trigger retention based on 'When items were last modified'.
B.Set the retention period to five years and trigger retention based on 'When items were created'.
C.Set the retention period to five years and choose 'When an event occurs' as the retention trigger.
D.Set the retention period to five years and configure a disposition review at the end of the period.
AnswerC

Event-based retention allows you to specify a custom event, such as 'Project ends', which starts the retention period. This ensures documents are retained for five years after the project ends and then deleted. This configuration meets the requirement precisely.

Why this answer

The requirement is to retain documents for five years after the project ends, which is a classic event-based retention scenario. Configuring the retention label to use 'When an event occurs' allows you to define a custom event like project completion, starting the retention period then. The label should also be set to delete items after the retention period to meet the automatic deletion requirement.

Exam trap

The trap here is selecting a creation or modification trigger, which does not align with the business event of project completion.

424
MCQmedium

You are a security administrator for Litware, Inc. The company uses Microsoft Defender XDR. You need to configure a custom detection rule that alerts when a user runs a specific PowerShell command on any device. The command is: `Invoke-WebRequest -Uri 'http://malicious.site/payload.ps1' -OutFile 'C:\temp\payload.ps1'`. Which advanced hunting table and column should you use to detect this activity?

A.DeviceEvents, using the AdditionalFields column.
B.DeviceFileEvents, using the FileName column.
C.DeviceProcessEvents, using the ProcessCommandLine column.
D.DeviceNetworkEvents, using the RemoteUrl column.
AnswerC

DeviceProcessEvents records process creation events on devices, including the command line used to launch the process. The ProcessCommandLine column contains the full command line, which would include the PowerShell command with the malicious URL and output file path. This is the correct table and column to detect the execution of the specific PowerShell command. Filtering on ProcessCommandLine for the URL or the command pattern will trigger the alert as required.

Why this answer

To detect a specific PowerShell command execution, you need the process creation event that includes the full command line. DeviceProcessEvents is the dedicated table for process events in Microsoft Defender for Endpoint, and ProcessCommandLine holds the command-line arguments. Filtering on this column for the malicious URL or command pattern will accurately trigger the custom detection rule.

Other tables either lack command-line data or are not designed for this purpose.

Exam trap

The trap here is assuming that network or file events are sufficient to detect a command execution, when in fact only process events capture the full command line.

425
MCQmedium

Your organization plans to use Microsoft 365 Copilot. To ensure compliance, you need to prevent Copilot from accessing sensitive content in SharePoint Online document libraries that are labeled as 'Highly Confidential'. What should you configure?

A.Configure a retention policy to prevent Copilot from accessing older content.
B.Create a conditional access policy to block Copilot from accessing SharePoint.
C.Create a DLP policy to block Copilot from processing 'Highly Confidential' content.
D.Configure a sensitivity label with encryption and apply it to the documents.
AnswerD

Sensitivity labels that include encryption encrypt the file itself and protect it with cryptographic access controls that Copilot explicitly respects. Because Copilot requires decrypted content to index and generate grounded responses, encrypted files are excluded from its semantic index and are not returned in Copilot results, even for users who have permission. Applying such a label is the supported way to prevent Copilot from processing sensitive documents.

Why this answer

Sensitivity labels with encryption can restrict access to documents based on their classification. When a document is labeled 'Highly Confidential' and encrypted, Microsoft 365 Copilot cannot process it because Copilot respects the encryption applied by the label, effectively preventing it from accessing the sensitive content. This is the only configuration that directly controls Copilot's ability to read the content at the file level.

Exam trap

The trap here is that candidates often confuse DLP policies (which control data sharing) with sensitivity labels (which control access and usage), leading them to choose option C, but DLP does not block internal processing by Copilot.

How to eliminate wrong answers

Option A is wrong because retention policies are designed to preserve or delete content based on time, not to control access or processing by Copilot; they do not block Copilot from reading current or older content. Option B is wrong because conditional access policies control user authentication and device access to SharePoint, not the behavior of Copilot as a service principal; Copilot operates under its own service identity and is not subject to user-level conditional access policies. Option C is wrong because DLP policies are used to detect and prevent the sharing of sensitive information, not to block internal processing by Copilot; DLP does not prevent Copilot from reading or summarizing content within the tenant.

426
MCQmedium

Your organization uses Microsoft Entra ID and requires users to authenticate using FIDO2 security keys. You need to ensure that users can register and manage their security keys through the My Security Info portal. Which authentication method policy setting should you enable?

A.Temporary Access Pass
B.Certificate-based authentication
C.Security keys (FIDO2)
D.Microsoft Authenticator
AnswerC

Security keys (FIDO2) is the correct method because Microsoft Entra ID's 'Security Keys (FIDO2)' policy specifically enables users to register a FIDO2 security key in the My Security Info portal. FIDO2 keys are hardware-based, phishing-resistant authenticators that generate a WebAuthn credential bound to the specific key and device. This policy is what appears in the Microsoft Entra admin center under Authentication methods, and it must be enabled for deploying FIDO2 passwordless sign-in for a defined user group.

Why this answer

The Security keys (FIDO2) authentication method policy must be enabled to allow users to register and manage FIDO2 security keys through the My Security Info portal. This policy controls the registration, key restrictions, and user targeting for FIDO2 authentication in Microsoft Entra ID, directly enabling the self-service management experience.

Exam trap

The trap here is that candidates confuse the authentication method policy that enables the feature (Security keys FIDO2) with the method used to authenticate after registration (like Microsoft Authenticator or Certificate-based authentication), leading them to pick an option that supports a different passwordless flow.

How to eliminate wrong answers

Option A is wrong because Temporary Access Pass is a time-limited passcode used for passwordless onboarding or recovery, not for registering or managing FIDO2 security keys. Option B is wrong because Certificate-based authentication (CBA) uses X.509 certificates for authentication, not FIDO2 security keys, and its policy does not control FIDO2 key registration. Option D is wrong because Microsoft Authenticator is a separate authentication method for phone sign-in or OTP, and its policy does not govern FIDO2 security key registration or management.

427
MCQmedium

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. Users report that they are frequently prompted for multi-factor authentication (MFA) even after signing in successfully. You want to minimize these prompts while maintaining security. What should you configure?

A.Configure Authentication Session Management
B.Modify the Conditional Access policy to require MFA for all apps
C.Change the per-user MFA state to Disabled
D.Adjust Identity Protection user risk policy
AnswerA

Configuring Authentication Session Management within a Conditional Access policy allows you to set sign-in frequency (for example, every 12 hours) and persistent browser sessions. This controls the token lifetime so that users are not repeatedly prompted for MFA within the defined window, directly reducing authentication prompts while retaining security.

Why this answer

Configuring Authentication Session Management in a Conditional Access policy allows you to control how often users are prompted for MFA by setting the sign-in frequency (e.g., every 24 hours) or persistent browser session (e.g., 'Remember MFA for 14 days'). This directly addresses the user complaint of frequent MFA prompts while maintaining security by enforcing reauthentication at defined intervals.

Exam trap

The trap here is that candidates confuse session controls (which manage MFA prompt frequency) with risk-based policies or per-user MFA states, assuming that disabling MFA or modifying risk policies will reduce prompts, when in fact session management is the precise control for this scenario.

How to eliminate wrong answers

Option B is wrong because requiring MFA for all apps would increase the frequency of MFA prompts, not minimize them, and it does not address session persistence. Option C is wrong because disabling per-user MFA would eliminate MFA entirely, compromising security, and it does not control session lifetime. Option D is wrong because Identity Protection user risk policy triggers MFA based on risk level (e.g., medium/high user risk), which is unrelated to session duration and would not reduce prompts for low-risk users.

428
MCQmedium

You are designing a Microsoft Entra ID tenant for a new subsidiary. You need to ensure that users can authenticate using their existing on-premises Active Directory credentials without synchronizing password hashes to the cloud. Which identity model should you choose?

A.Federation with AD FS
B.Cloud-only identity
C.Pass-through authentication (PTA)
D.Password hash synchronization (PHS)
AnswerC

Pass-through authentication (PTA) is correct because it validates user passwords directly against on-premises Active Directory at sign-in time without ever storing password hashes in the cloud. PTA uses a lightweight agent installed on an on-premises server that receives authentication requests from Entra ID and validates them against the local domain controller. This gives organizations the benefit of cloud-based authentication while preserving on-premises password policies, account states, and lockout settings, and avoids the cloud hash storage that would otherwise be introduced.

Why this answer

Pass-through authentication (PTA) allows users to authenticate against on-premises Active Directory directly, without synchronizing password hashes to the cloud. When a user signs in to Microsoft Entra ID, the authentication request is forwarded to an on-premises PTA agent, which validates the credentials against the local domain controller. This meets the requirement of using existing on-premises credentials without storing password hashes in the cloud.

Exam trap

The trap here is that candidates often confuse federation (AD FS) with pass-through authentication, assuming that only federation can avoid password hash sync, but PTA also avoids hash sync while being simpler to deploy and manage.

How to eliminate wrong answers

Option A is wrong because federation with AD FS requires an on-premises federation server and still does not synchronize password hashes, but it introduces additional complexity and is not the simplest solution for direct password validation without hash sync. Option B is wrong because cloud-only identity creates accounts entirely in Microsoft Entra ID with passwords stored in the cloud, which does not use existing on-premises Active Directory credentials. Option D is wrong because password hash synchronization (PHS) explicitly synchronizes password hashes from on-premises AD to Microsoft Entra ID, which violates the requirement to avoid synchronizing password hashes.

429
MCQmedium

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can reset their own passwords without administrator intervention, but only if they have registered for self-service password reset (SSPR). What should you configure?

A.Enable SSPR for a selected security group containing registered users
B.Configure a conditional access policy requiring admin approval for password changes
C.Configure Microsoft Entra ID Protection user risk policy
D.Enable SSPR for All users
AnswerA

This is correct because SSPR can be scoped to a selected Microsoft Entra (Azure AD) security group, and by populating that group only with users who have already completed SSPR registration (e.g., set up phone, email, or authenticator methods), you ensure that password reset is available only to those pre-registered users. This gives you precise control and meets the 'registered users only' requirement. As a best practice, you would maintain that group dynamic or assigned to reflect the registered-user population, and combine it with the 'Registration required' setting to keep the allowlist accurate.

Why this answer

Enabling SSPR for a selected security group ensures that only users who have been explicitly added to that group (and thus have registered for SSPR) can reset their own passwords without administrator intervention. This meets the requirement of restricting self-service password reset to registered users only, while still allowing password changes without admin approval.

Exam trap

The trap here is that candidates often confuse enabling SSPR for 'All users' as the simplest way to meet the requirement, overlooking the explicit condition that only registered users should be allowed to reset passwords, which requires scoping to a security group containing those registered users.

How to eliminate wrong answers

Option B is wrong because configuring a conditional access policy requiring admin approval for password changes would prevent users from resetting their own passwords without administrator intervention, directly contradicting the requirement. Option C is wrong because Microsoft Entra ID Protection user risk policy is designed to automatically respond to risky user behavior (e.g., by blocking sign-in or requiring MFA), not to enable or restrict self-service password reset. Option D is wrong because enabling SSPR for All users would allow any user, including those who have not registered for SSPR, to reset their passwords, which does not meet the requirement that only registered users can reset their passwords.

430
MCQmedium

An administrator has added the custom domain 'contoso.co.uk' to their Microsoft 365 tenant and verified ownership. Users now need to receive email at @contoso.co.uk. Which DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?

A.Add an MX record pointing to <tenant>.mail.protection.outlook.com
B.Add a CNAME record for autodiscover
C.Add an SPF record
D.Add a DKIM record
AnswerA

The MX record is the authoritative DNS mechanism that routes incoming SMTP mail for a domain. For Microsoft 365, it must be configured to point to <tenant>.mail.protection.outlook.com, the Exchange Online boundary, to ensure external senders deliver messages to your mailboxes. Without this record, email addressed to your domain will not reach Exchange Online, even if all other DNS records are present.

Why this answer

To route email for a custom domain to Exchange Online, you must add an MX record in the public DNS zone that points to the Exchange Online mail exchanger. The correct target is <tenant>.mail.protection.outlook.com, where <tenant> is your initial tenant name (e.g., contoso-com). This MX record tells sending mail servers to deliver messages for @contoso.co.uk to Microsoft's email infrastructure.

Exam trap

The trap here is that candidates confuse DNS records required for email routing (MX) with records required for email security or client discovery (SPF, DKIM, Autodiscover), leading them to select a record that does not actually deliver inbound messages.

How to eliminate wrong answers

Option B is wrong because a CNAME record for autodiscover is used to configure client connectivity (Outlook auto-configuration), not to route inbound email. Option C is wrong because an SPF record is a TXT record that authorizes sending servers and helps prevent spoofing, but it does not direct email delivery. Option D is wrong because a DKIM record is a TXT record used to sign outgoing emails for cryptographic verification, not to route inbound messages.

431
MCQeasy

You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?

A.Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
B.Open the Microsoft Defender for Endpoint portal and create a dashboard for all alerts.
C.Install Microsoft Sentinel and configure data connectors for all workloads.
D.Create a custom KQL query that correlates alerts from different sources and create a workbook.
AnswerA

The Incidents view in the Microsoft Defender XDR portal correlates alerts across endpoints, email and identities into unified incidents, and automatic incident creation triggers when correlated alerts fire, meeting both the visibility and automation requirements.

Why this answer

The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident view and automatically correlates alerts from multiple workloads (endpoints, email, identities) into incidents. Option B is incorrect because Microsoft Defender for Endpoint portal focuses only on endpoint data, not the unified view across all services. Option C is incorrect because while Microsoft Sentinel can provide a unified view, it requires additional licensing, configuration, and does not automatically create incidents from correlated alerts without custom analytics rules.

Option D is incorrect because custom KQL queries and workbooks provide visibility but do not automate incident creation; that requires built-in correlation from Microsoft Defender XDR.

432
MCQeasy

Your company has a Microsoft 365 E5 subscription. You need to configure multi-factor authentication (MFA) for all users. However, the CEO insists that he should not be prompted for MFA when connecting from the corporate office. What should you do?

A.Use per-user MFA and set the CEO's account to bypass.
B.Disable MFA for the CEO's account.
C.Configure trusted IPs in the MFA service settings.
D.Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.
AnswerD

Create a Conditional Access policy that targets the CEO (or all users) and the cloud apps you want to protect, with a condition that requires MFA. In that policy, add a 'named location' for the corporate office IP ranges and exclude it from the policy's assignment, so MFA is not required when the sign-in originated from that range. This is the correct approach because named locations can be defined with trusted IP ranges, and the exclusion is scoped to the policy rather than applied tenant-wide, preserving MFA protection everywhere else.

Why this answer

Conditional Access is the modern, recommended way to enforce MFA in Microsoft 365 E5, and it supports named locations (trusted IPs) that can be excluded from the MFA requirement. Creating a policy that requires MFA for all users but excludes the corporate office named location satisfies the CEO's requirement while keeping MFA enforced everywhere else.

Exam trap

MS-102 often tests the difference between legacy per-user MFA (with its bypass and trusted IP settings) and Conditional Access — the correct modern answer is always Conditional Access with named locations, not per-user bypass.

How to eliminate wrong answers

Option A is wrong because per-user MFA is the legacy approach and its 'bypass' setting disables MFA entirely for that user, not just from the corporate office — it does not meet the requirement of skipping MFA only at the office. Option B is wrong because disabling MFA for the CEO's account removes protection everywhere, which is a security regression and not what was asked. Option C is wrong because configuring trusted IPs in the legacy per-user MFA service settings is deprecated and does not integrate with Conditional Access; Microsoft now recommends named locations in Conditional Access instead, and the legacy setting is being retired.

433
MCQhard

Your organization uses Microsoft Entra ID with Application Proxy to publish on-premises web apps. Users report that they are prompted for credentials multiple times when accessing an app. You need to reduce the number of authentication prompts. What should you configure?

A.Enable Azure MFA for the application
B.Disable pre-authentication for the application
C.Increase the session lifetime in conditional access
D.Enable Kerberos Constrained Delegation (KCD) for single sign-on
AnswerD

Enabling Kerberos Constrained Delegation (KCD) is the correct approach for single sign-on to a legacy on-premises application published through Application Proxy. After the user authenticates to Entra ID, the Application Proxy connector uses the user's token to obtain a Kerberos service ticket from on-premises Active Directory on behalf of the user, then presents that ticket to the backend application. This avoids a second credential prompt because the backend app sees an already authenticated user. KCD requires the application to support Windows Integrated Authentication and careful SPN configuration, but it delivers true SSO without extra MFA prompts or session-lengthening workarounds.

Why this answer

The multiple authentication prompts indicate that the Application Proxy is not passing the user's credentials seamlessly to the on-premises app. Enabling Kerberos Constrained Delegation (KCD) allows the Application Proxy connector to impersonate the user and obtain a Kerberos ticket for the backend application, enabling single sign-on (SSO) and eliminating repeated credential prompts.

Exam trap

The trap here is that candidates often confuse session lifetime settings (Option C) with SSO configuration, thinking that extending session duration will reduce prompts, when in fact the issue is the lack of credential delegation between the proxy and the backend app.

How to eliminate wrong answers

Option A is wrong because enabling Azure MFA would add an additional authentication factor, increasing the number of prompts rather than reducing them. Option B is wrong because disabling pre-authentication would bypass Microsoft Entra ID authentication entirely, exposing the app to the internet without Entra ID protection, and would not resolve the multiple prompts caused by missing SSO. Option C is wrong because increasing the session lifetime in Conditional Access only extends how long a session remains valid before re-authentication is required; it does not address the root cause of repeated prompts within a single session due to lack of SSO.

434
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy JSON. The policy is intended to block legacy authentication. However, users are still able to connect using Exchange ActiveSync. What is the most likely reason?

A.The policy is missing the 'browser' and 'mobileAppsAndDesktopClient' client app types
B.The grant control operator 'OR' should be 'AND'
C.The policy is configured in 'report-only' mode instead of 'enforce'
D.The policy is missing a condition for 'device platforms' to target iOS and Android
AnswerC

If the policy is in report-only mode, it will not enforce the block, allowing legacy connections to succeed. This is the most likely reason.

Why this answer

The policy is configured in 'report-only' mode. In report-only mode, Conditional Access policies are evaluated but not enforced. Users can still connect using legacy authentication because the policy does not block access.

To block legacy authentication, the policy must be set to 'enforce' mode. Additionally, the client apps condition should include 'Exchange ActiveSync clients' and 'Other clients' to specifically target legacy authentication protocols.

Exam trap

A common trap is that candidates mistake report-only mode for enforcement. Report-only mode is used for testing and does not block access. Always verify the policy mode when troubleshooting Conditional Access policy effects.

How to eliminate wrong answers

Option B is wrong because the grant control operator 'OR' vs 'AND' affects how multiple controls are evaluated (e.g., require MFA or require compliant device), but it does not impact whether the policy applies to legacy authentication; the issue is the missing client app types, not the logical operator. Option C is wrong because 'report-only' mode logs the policy result without blocking, but the question states users are still able to connect, which could occur in report-only mode; however, the most likely reason is the missing client app types, as report-only mode would still show the policy applying in logs, whereas the described behavior suggests the policy is not being evaluated at all. Option D is wrong because device platform conditions (e.g., iOS, Android) are optional and not required to block legacy authentication; legacy authentication blocking depends on client app types, not device platforms.

435
MCQmedium

A security administrator wants to reduce the risk of credential dumping from LSASS on managed Windows endpoints. Which Attack Surface Reduction rule should be enabled?

A.Block credential stealing from the Windows Local Security Authority Subsystem
B.Block executable files from running unless they meet prevalence, age, or trusted list criteria
C.Block untrusted and unsigned processes that run from USB
D.Block JavaScript or VBScript from launching downloaded executable content
AnswerA

This ASR rule is specifically designed to block attempts to open and read the memory space of the Local Security Authority Subsystem Service (LSASS), the process in which Windows stores authentication credentials. By intercepting suspicious process calls to LSASS, it directly stops credential dumping tools such as Mimikatz from extracting plaintext passwords and NTLM hashes. When enabled in block mode, it logs and prevents these access attempts, making it the correct rule for reducing credential dumping on managed devices.

Why this answer

The 'Block credential stealing from the Windows Local Security Authority Subsystem' ASR rule (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) specifically prevents credential dumping from LSASS by blocking access to the process memory via common techniques like Mimikatz or direct API calls (e.g., OpenProcess, ReadProcessMemory). This directly reduces the risk of credential theft on managed Windows endpoints.

Exam trap

The trap here is that candidates often confuse ASR rules with general malware prevention or USB controls, failing to recognize that the specific rule for LSASS credential protection is explicitly named and targeted at memory-based credential theft, not broader execution or download restrictions.

How to eliminate wrong answers

Option B is wrong because it describes the 'Block executable files from running unless they meet prevalence, age, or trusted list criteria' ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25), which targets untrusted executables based on reputation, not credential dumping from LSASS. Option C is wrong because it refers to the 'Block untrusted and unsigned processes that run from USB' ASR rule (GUID: b2b3f03d-6a4c-4b7e-8c6d-1f3b2a1e5c4d), which focuses on USB-borne malware execution, not LSASS memory protection. Option D is wrong because it describes the 'Block JavaScript or VBScript from launching downloaded executable content' ASR rule (GUID: d4e5f6a7-8b9c-0d1e-2f3a-4b5c6d7e8f90), which prevents script-based download attacks, not direct credential theft from LSASS.

436
MCQeasy

Your company has a Microsoft 365 E3 tenant. You need to enable Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally via email. What must you do first?

A.Create a DLP policy in Microsoft Defender XDR
B.Navigate to the Microsoft Purview compliance portal and create a DLP policy
C.Use Exchange Online PowerShell to configure DLP rules
D.Upgrade to Microsoft 365 E5 or purchase a DLP add-on
AnswerB

Microsoft Purview DLP policies are authored in the compliance portal, so creating one establishes the rule set that detects sensitive data and blocks external email sharing. This is the prerequisite step; the E3 licence already covers the portal, so no additional licensing action is needed.

Why this answer

Microsoft 365 E3 includes DLP capabilities for Exchange Online via the Microsoft Purview compliance portal. Therefore, the correct first step is to navigate to the Microsoft Purview compliance portal and create a DLP policy (option B). Upgrading to E5 or purchasing a DLP add-on (option D) is not required for Exchange Online DLP in E3.

Exam trap

The trap is that candidates may incorrectly assume that E3 lacks DLP capabilities and that an upgrade is required. However, Microsoft 365 E3 includes DLP for Exchange Online, and policies can be created in the compliance portal.

How to eliminate wrong answers

Option A is wrong because creating a DLP policy in Microsoft Defender XDR is not the first step; Defender XDR policies focus on security incidents and threat protection, not data loss prevention, and the tenant lacks the required license. Option B is wrong because navigating to the Microsoft Purview compliance portal and creating a DLP policy is not possible without the E5 or DLP add-on license; the portal will block policy creation or enforcement due to licensing restrictions. Option C is wrong because using Exchange Online PowerShell to configure DLP rules is ineffective without the proper license; PowerShell cannot bypass licensing requirements, and the underlying DLP engine will not enforce the rules.

437
Multi-Selectmedium

Which THREE settings can you configure in a Microsoft Defender for Office 365 anti-phish policy?

Select 3 answers
A.Mailbox intelligence
B.Safe Attachments
C.DKIM signing
D.User impersonation protection
E.Spoof intelligence
AnswersA, D, E

Mailbox intelligence is configurable within anti-phish policies, satisfying the requirement for a genuine anti-phishing setting. It uses each user's historical communication patterns and frequent contacts to distinguish legitimate senders from impersonators, strengthening spoof and impersonation detection. Unlike transport rules or DLP settings, it belongs specifically to the anti-phish policy configuration surface.

Why this answer

Mailbox intelligence (A) is a configurable setting in an anti-phish policy that uses a user's past communication patterns to detect impersonation attempts. User impersonation protection (D) is also configured in anti-phish policies, allowing you to protect specific internal or external senders from impersonation. Spoof intelligence (E) is a configurable setting in anti-phish policies that controls how the service handles senders who spoof domains you don't own.

Safe Attachments (B) is a separate Defender for Office 365 policy (Safe Attachments policy), not a setting within an anti-phish policy. DKIM signing (C) is configured via DNS and Exchange Online mail flow settings, not within an anti-phish policy.

Exam trap

The trap is conflating all Defender for Office 365 protections into one policy type; candidates must know that Safe Attachments and DKIM are configured elsewhere, not inside anti-phish policies.

438
MCQmedium

Contoso uses Microsoft Entra ID P1 licenses and has a dedicated corporate office with static public IP addresses. The company wants to require MFA for all users, but exempt users when they connect from the corporate office. Which configuration should the administrator implement?

A.Create a Conditional Access policy that targets all users, grant access requiring MFA, and include the corporate office location as a condition.
B.Create a Conditional Access policy that targets all users, grant access requiring MFA, and exclude the corporate office location from the policy.
C.Configure a Per-User MFA policy and add the corporate office IPs to a list of trusted IPs in the MFA settings.
D.Create a Conditional Access policy that targets the corporate office location and grant access with MFA for all other locations.
AnswerB

Conditional Access evaluates sign-in context, so targeting all users with an MFA grant control and excluding the named corporate location satisfies the requirement. The static public IP defines the trusted location, letting office connections bypass MFA while all other sign-ins still require it.

Why this answer

A Conditional Access policy can target all users, require MFA as a grant control, and exclude the corporate office location (defined by static public IP addresses as a named location). This ensures MFA is enforced for all connections except those originating from the trusted corporate network, aligning with the requirement to exempt users at the office.

Exam trap

The trap here is that candidates often confuse 'include' and 'exclude' in Conditional Access conditions, mistakenly thinking that including the office location will exempt it, when in fact excluding the location is required to bypass MFA for that trusted network.

How to eliminate wrong answers

Option A is wrong because including the corporate office location as a condition would require MFA even when users connect from the office, which contradicts the exemption requirement. Option C is wrong because Per-User MFA is a legacy, less flexible approach that does not support location-based exemptions via Conditional Access; trusted IPs in MFA settings only bypass MFA for the MFA prompt itself but do not integrate with the granular policy controls of Conditional Access. Option D is wrong because targeting the corporate office location and granting access with MFA for all other locations is syntactically incorrect—Conditional Access policies grant access based on conditions, not by targeting a location to grant MFA elsewhere; the correct approach is to exclude the trusted location from the policy that requires MFA.

439
MCQeasy

You are deploying a new Microsoft 365 tenant for a company that has a single domain, contoso.com. You need to verify domain ownership to enable email routing. Which DNS record type must you add to the public DNS zone?

A.CNAME record with 'autodiscover' pointing to 'autodiscover.outlook.com'.
B.SPF record including Microsoft 365 IP addresses.
C.MX record pointing to Microsoft 365.
D.TXT record with a verification code provided by Microsoft 365.
AnswerD

This is the correct method: in the Microsoft 365 admin center you select the domain you want to verify, copy the unique verification code, and publish it as a TXT record at the root of that domain (for example, MS=123456). Microsoft 365 then performs a DNS query for that exact TXT value; when it resolves, the domain is considered verified because only someone with administrative control of the domain's DNS zone could create that record. TXT records are able to carry arbitrary text, which makes them ideal for storing the verification token, and this same mechanism is used for verifying domains in Azure AD as well.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification code provided by the Microsoft 365 admin center to your public DNS zone. This proves you control the domain, enabling email routing and other services. Other DNS records like CNAME, SPF, or MX are used for service configuration, not ownership verification.

Exam trap

The trap here is that candidates confuse service configuration records (like MX, SPF, or CNAME) with the mandatory verification record, assuming any DNS change proves ownership, but only the TXT record with the specific code satisfies Microsoft 365's domain proof requirement.

How to eliminate wrong answers

Option A is wrong because a CNAME record for 'autodiscover' pointing to 'autodiscover.outlook.com' is used to configure automatic client discovery for Exchange Online, not to verify domain ownership. Option B is wrong because an SPF record specifies authorized sending IP addresses for email authentication and is not used for domain verification. Option C is wrong because an MX record directs email flow to Microsoft 365 but requires prior domain ownership verification to be accepted.

440
MCQeasy

A security administrator wants to ensure that all email attachments are scanned in a sandbox environment and blocked if malicious, with email delivery delayed until scanning completes. Which Microsoft 365 Defender policy should the administrator configure?

A.Safe Links policy
B.Safe Attachments policy
C.Anti-spam policy
D.Anti-phishing policy
AnswerB

Safe Attachments detonates attachments in a sandbox before delivery, holding the message until scanning finishes. This directly satisfies the requirement to delay email delivery until malicious content is confirmed and blocked, unlike Safe Links, which only rewrites URLs at click time.

Why this answer

Safe Attachments policy is the correct choice because it provides sandbox scanning of email attachments. It can be configured to delay email delivery until scanning is complete, blocking malicious attachments. This directly meets the requirement.

Exam trap

The trap here is that candidates often confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only handles URLs, not file attachments, and the question explicitly requires sandbox scanning of attachments.

How to eliminate wrong answers

Option A is wrong because Safe Links policy protects users from malicious URLs in email messages and Office documents, not from email attachments; it does not perform sandbox scanning of files. Option C is wrong because Anti-spam policy filters inbound and outbound email based on spam, bulk mail, and phishing indicators, but it does not scan attachments in a sandbox environment. Option D is wrong because Anti-phishing policy protects against impersonation and spoofing attacks, not against malicious attachments; it does not include sandbox-based file scanning.

441
MCQhard

A company has 500 users across Sales, Marketing, and IT departments. User objects are synced from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. Each department requires different Microsoft 365 license plans (e.g., Sales needs E3, Marketing needs Business Premium, IT needs E5). The administrator wants to automatically assign the appropriate license based on the department attribute without manual intervention. Which approach should the administrator use?

A.Create a script that runs daily to sync department values and assign licenses using PowerShell.
B.Configure group-based licensing using Microsoft Entra dynamic groups with rules based on the department attribute.
C.Use Azure AD Connect to filter objects and assign licenses during sync.
D.Manually assign licenses to each user in the Microsoft 365 admin center.
AnswerB

Dynamic groups in Microsoft Entra ID evaluate membership using a rule on the department attribute, so users are automatically added or removed as their department changes. When combined with group-based licensing, a license is provisioned to every member of the group automatically, and it is removed when a user leaves the group. This approach is the recommended Microsoft solution because it scales to thousands of users without manual steps or custom code, and it integrates with Entra ID's inherent license management.

Why this answer

Microsoft Entra ID supports group-based licensing, which allows automatic license assignment to users based on their membership in dynamic groups. By creating dynamic groups with rules that filter on the department attribute (e.g., 'user.department -eq "Sales"'), the administrator can assign the appropriate license plan (E3, Business Premium, E5) to each group, and licenses are automatically applied or removed as users are added or removed from the group, without any manual or scripted intervention.

Exam trap

The trap here is that candidates may confuse Azure AD Connect's attribute filtering or sync capabilities with license assignment, or assume that a PowerShell script is the only automated method, overlooking the native group-based licensing feature that is designed exactly for this scenario.

How to eliminate wrong answers

Option A is wrong because using a script that runs daily introduces unnecessary complexity, potential delays (up to 24 hours), and administrative overhead; it also does not leverage the built-in, real-time license assignment capabilities of Microsoft Entra ID. Option C is wrong because Azure AD Connect is used for syncing identity objects and attributes, not for assigning licenses; filtering objects during sync controls which users are synced, not how licenses are assigned. Option D is wrong because manually assigning licenses to 500 users across three departments is not scalable, error-prone, and violates the requirement for automatic assignment without manual intervention.

442
MCQeasy

Your organization uses Microsoft 365 Business Premium with Microsoft Entra ID P1. You have 200 users. You need to enforce multi-factor authentication (MFA) for all users accessing the company's CRM application, which is a third-party SaaS app integrated via SAML. The CRM app does not support modern authentication protocols. You want to use a Microsoft solution that does not require additional licenses. What should you use?

A.Enable security defaults in Microsoft Entra ID.
B.Deploy Microsoft Entra application proxy for the CRM app.
C.Configure per-user MFA for users of the CRM app.
D.Create a Conditional Access policy targeting the CRM application and require MFA.
AnswerD

Create a Conditional Access policy that targets the CRM application and requires MFA provides exactly the app-level scoping you need. Conditional Access policies can be assigned to a specific cloud/SaaS application, and when a user accesses that app, the policy evaluates signals and enforces MFA only for that application. Microsoft 365 Business Premium includes Microsoft Entra ID P1, which gives you the license rights to use Conditional Access, making this the correct, modern approach.

Why this answer

Conditional Access policies in Microsoft Entra ID P1 allow you to target specific cloud applications (including third-party SAML-integrated SaaS apps) and enforce MFA. Since the CRM app does not support modern authentication protocols, Conditional Access can still enforce MFA by requiring a compliant domain-joined device or by using app-enforced restrictions; however, the key is that Conditional Access works at the authentication plane and can require MFA even for legacy apps when combined with a capable authentication method like a one-time passcode or Microsoft Authenticator. This solution uses existing Microsoft Entra ID P1 licensing without additional costs.

Exam trap

The trap here is that candidates assume per-user MFA (Option C) is the only way to enforce MFA for legacy apps, but Conditional Access policies in Microsoft Entra ID P1 can target specific SAML-integrated apps and enforce MFA without requiring modern authentication protocols on the app side.

How to eliminate wrong answers

Option A is wrong because security defaults enforce MFA for all users but cannot be scoped to a specific application like the CRM app; they apply globally to all cloud apps and break if you need granular control. Option B is wrong because Microsoft Entra application proxy is designed for publishing on-premises web apps externally, not for enforcing MFA on a third-party SaaS app that is already integrated via SAML. Option C is wrong because per-user MFA is a legacy approach that requires manual configuration and does not support targeting a specific application; it also lacks the granularity and reporting of Conditional Access and is not recommended for modern deployments.

443
MCQhard

Your organization has a hybrid identity deployment using Microsoft Entra Connect Sync. You need to ensure that password writeback is enabled so that users can reset their own passwords from the cloud. Which prerequisite must be met?

A.Self-Service Password Reset (SSPR) must be enabled in Microsoft Entra ID
B.Password hash synchronization must be enabled
C.Azure MFA must be enabled for all users
D.Microsoft Entra ID P2 licenses must be assigned
AnswerA

Enabling Self-Service Password Reset (SSPR) in Microsoft Entra ID is the controlling service that invokes password writeback. When a user resets a forgotten password through the SSPR portal, the cloud tenant calls back to the on-premises directory via the Microsoft Entra Connect sync engine, and only if SSPR is toggled on with the writeback option does the tenant pass the new password value back to the local Active Directory domain. Thus, without SSPR enabled and configured, there is no cloud-side operation to trigger the writeback service, regardless of how the on-premises sync is set up.

Why this answer

Password writeback requires that Self-Service Password Reset (SSPR) is enabled in Microsoft Entra ID because writeback is a feature of SSPR that allows password changes initiated in the cloud to be written back to the on-premises Active Directory. Without SSPR enabled, the cloud tenant has no mechanism to trigger the writeback operation, even if the Entra Connect Sync configuration is correct.

Exam trap

The trap here is that candidates often assume password hash synchronization must be enabled for any password-related feature, but password writeback is a separate SSPR function that does not depend on hash sync and can be used with other authentication methods.

How to eliminate wrong answers

Option B is wrong because password hash synchronization is not a prerequisite for password writeback; writeback works independently of hash sync and can be used with federation or pass-through authentication. Option C is wrong because Azure MFA is not a prerequisite for password writeback; MFA can be used as an additional security layer for SSPR but is not required for the writeback feature itself. Option D is wrong because Microsoft Entra ID P2 licenses are not required for password writeback; SSPR with writeback is available with Microsoft Entra ID P1 licenses, though P2 adds additional identity protection features.

444
MCQmedium

A company wants to require that all users accessing a critical internal application must be on a compliant device (managed by Intune) and must have authenticated with multi-factor authentication in the last 30 minutes. Which Conditional Access configurations are needed?

A.Grant control 'Require multi-factor authentication' and 'Require device to be marked as compliant' with session control 'Sign-in frequency' set to 30 minutes
B.Grant control 'Require multi-factor authentication' and 'Require device to be marked as compliant' and 'Require all the selected controls'
C.Grant control 'Require multi-factor authentication' and 'Require hybrid Azure AD joined device' with session control 'App enforced restrictions'
D.Grant control 'Block access' for non-compliant devices and separate policy for MFA
AnswerA

This is the correct policy design because the grant controls 'Require multi-factor authentication' and 'Require device to be marked as compliant' are combined with the session control 'Sign-in frequency' set to 30 minutes. In Conditional Access, selecting multiple grant controls defaults to 'Require all the selected controls,' so a user must satisfy both MFA and Intune compliance at access time. The session control then enforces reauthentication for this application every 30 minutes, which forces MFA to be reperformed because the MFA grant is evaluated against the new sign-in event. Together they fully satisfy the requirement: every access attempt must come from a compliant device, and the user's MFA proof must be no older than 30 minutes.

Why this answer

It combines the required grant controls ('Require multi-factor authentication' and 'Require device to be marked as compliant') with the session control 'Sign-in frequency' set to 30 minutes. The sign-in frequency session control enforces reauthentication after the specified time window, ensuring MFA was performed within the last 30 minutes. The grant controls ensure both MFA and device compliance are satisfied simultaneously.

Exam trap

The trap here is that candidates often confuse 'Require all the selected controls' (which is a logical AND operator for grant controls) with session controls, and fail to realize that time-based MFA reauthentication requires a separate session control setting, not just a grant control.

How to eliminate wrong answers

Option B is wrong because it includes 'Require all the selected controls' but omits the session control 'Sign-in frequency', which is necessary to enforce the 30-minute MFA reauthentication window; without it, MFA is only required at initial sign-in. Option C is wrong because it requires a 'hybrid Azure AD joined device' instead of a device 'marked as compliant', and uses 'App enforced restrictions' which does not enforce a 30-minute MFA reauthentication interval. Option D is wrong because using a separate policy for MFA and a 'Block access' policy for non-compliant devices cannot enforce the 30-minute MFA reauthentication requirement; session controls like 'Sign-in frequency' are needed for time-based reauthentication, and blocking non-compliant devices alone does not ensure MFA freshness.

445
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. An analyst reports that a user's device is showing signs of compromise, and you need to isolate the device from the network while preserving the ability to collect forensic evidence. The device is running Windows 11 and is onboarded to Microsoft Defender for Endpoint. Which action should you take in the Microsoft 365 Defender portal?

A.Isolate the device from the network.
B.Run a full antivirus scan on the device.
C.Collect an investigation package from the device.
D.Initiate an automated investigation on the device.
AnswerA

Isolating the device from the network disconnects it from all network traffic except for the Defender for Endpoint service, allowing you to contain the threat while preserving the ability to collect forensic evidence remotely. This is the correct action to meet the requirement.

Why this answer

Isolating the device from the network is the correct action because it immediately contains the threat by restricting network communication while still allowing the Defender for Endpoint service to communicate with the device. This enables further investigation and evidence collection without risking lateral movement or data exfiltration.

Exam trap

The trap here is confusing isolation with other response actions like running a scan or collecting an investigation package, which do not contain the threat.

446
MCQhard

Your organization has Microsoft Defender for Cloud Apps deployed. You need to be alerted when a user performs more than 50 failed login attempts in an hour from a non-corporate IP address. Which type of policy should you create?

A.Session policy
B.Anomaly detection policy
C.File policy
D.Access policy
AnswerB

Anomaly detection policies in Defender for Cloud Apps use machine-learned behavioural baselines to flag deviations such as unusual failed-login volumes, satisfying the threshold and non-corporate IP conditions. Activity policies, by contrast, apply static, user-defined filters and cannot model anomalous sign-in behaviour.

Why this answer

An anomaly detection policy in Defender for Cloud Apps can detect unusual patterns like multiple failed login attempts from non-corporate IPs. Option A is wrong because a session policy controls real-time access but doesn't detect anomalies. Option C is wrong because a file policy monitors file activities, not login attempts.

Option D is wrong because an access policy enforces conditional access based on compliance, not anomaly detection.

447
Multi-Selecthard

A security analyst wants to create a custom detection rule that triggers when a user receives a phishing email that bypassed Exchange Online Protection, and then clicks a link that leads to a known malicious domain. Which two advanced hunting tables should the analyst combine to detect this chain of events?

Select 1 answer
A.EmailEvents and DeviceNetworkEvents
B.EmailEvents and UrlClickEvents
C.EmailEvents and IdentityLogonEvents
D.UrlClickEvents and DeviceNetworkEvents
AnswersB

EmailEvents captures delivery-level data, including whether Exchange Online Protection allowed the message through, while UrlClickEvents records Safe Links click telemetry against the URL and its verdict. Joining them on NetworkMessageId correlates the bypassed phishing email with the subsequent malicious-domain click, satisfying the required two-stage detection chain.

Why this answer

Combining EmailEvents (which captures email delivery) with UrlClickEvents (which records user clicks on URLs in emails) allows the analyst to identify the specific chain: a user received a phishing email and then clicked a link. This pair directly links the email receipt to the user's click action. Option D is incorrect because while UrlClickEvents and DeviceNetworkEvents can correlate a click to a network connection, they do not include the email receipt event (EmailEvents), which is essential to detect the full chain described: receiving a phishing email and then clicking a link.

Without EmailEvents, there is no evidence that the click originated from an email.

Exam trap

The trap is that candidates may think DeviceNetworkEvents can replace EmailEvents, but network logs alone cannot prove the click originated from an email. The detection must include EmailEvents to capture the phishing email receipt, which is the initial event in the chain.

448
MCQhard

You are a Microsoft 365 administrator for Tailspin Toys. You have Microsoft Defender XDR configured with Microsoft Defender for Office 365 and Microsoft Defender for Endpoint. You need to ensure that when a user clicks a malicious link in an email, the alert is enriched with the device information of the user's computer, and the device is automatically investigated. What should you do?

A.In Microsoft Defender for Endpoint, create a device group that includes all user devices and set the automation level to 'Full - remediate threats automatically'.
B.In Microsoft Defender for Office 365, configure the 'Alert correlation' setting to include device information from Defender for Endpoint.
C.Ensure that the 'Microsoft Defender for Endpoint' integration is enabled in Microsoft Defender XDR and that the device is onboarded.
D.Enable 'Advanced hunting' in Microsoft Defender XDR and create a custom detection rule that correlates email events with device events.
AnswerC

Microsoft Defender XDR automatically correlates alerts from Defender for Office 365 with device information from Defender for Endpoint when both services are integrated and the device is onboarded. This correlation enriches the alert and can trigger an automated investigation. Enabling the integration and onboarding devices is the correct approach.

Why this answer

Microsoft Defender XDR natively integrates alerts from Defender for Office 365 and Defender for Endpoint. When a user clicks a malicious link, the alert in Defender for Office 365 can be correlated with the device if the device is onboarded to Defender for Endpoint and the services are integrated. This correlation enriches the alert with device details and can automatically initiate an investigation.

Thus, ensuring the integration is enabled and devices are onboarded is the correct action.

Exam trap

The trap here is believing that custom detection rules or device groups can achieve cross-service alert enrichment, when it is actually a built-in integration feature.

449
Multi-Selecthard

You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement access reviews for privileged roles. They want to ensure that access reviews are conducted quarterly and that reviewers must provide a justification for their decision. You need to configure the access review. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the access review to automatically apply results.
B.Set the recurrence of the access review to quarterly.
C.Enable 'Require justification on approval' in the access review settings.
D.Enable 'Require MFA to approve' in the access review settings.
E.Set the reviewers to be the users themselves.
AnswersB, C

The access review schedule includes recurrence settings. Setting it to quarterly ensures reviews occur every three months, meeting the requirement. Recurrence can be set to weekly, monthly, quarterly, semi-annually, or annually. This directly addresses the quarterly requirement.

Why this answer

To meet the requirements, you need to set the access review recurrence to quarterly and enable the option that requires reviewers to provide a justification when approving. These two settings ensure the review happens every three months and that reviewers must justify their decisions. Other settings like auto-apply or self-review do not address justification.

Exam trap

The trap here is assuming that auto-apply or MFA settings within access reviews enforce justification, when actually justification is a separate toggle.

450
Multi-Selecthard

Your organization is deploying Windows 11 using Microsoft Intune. You need to ensure that devices are automatically enrolled in Intune when users sign in with their Microsoft Entra ID credentials. Which THREE prerequisites must be met?

Select 3 answers
A.Devices must run Windows 10/11 Home edition.
B.Microsoft Configuration Manager must be deployed.
C.Microsoft Entra ID P1 or P2 license.
D.Devices must be Microsoft Entra joined or hybrid Microsoft Entra joined.
E.MDM user scope must be set to All or Some in Microsoft Entra ID.
AnswersC, D, E

A Microsoft Entra ID P1 or P2 license is required in the tenant to enable the automatic MDM enrollment feature that connects Microsoft Entra ID to Intune. This license tier permits group-based assignment of Intune licenses and allows the MDM auto-enrollment policy to be configured for users. Without P1 or P2, the automatic enrollment setting is not available, even if the user has a standalone Intune license assigned.

Why this answer

Microsoft Entra ID P1 or P2 licenses are required to enable automatic MDM enrollment via Intune. Without these licenses, the MDM authority cannot be set to Intune, and the automatic enrollment policy in Microsoft Entra ID will not function. This licensing requirement ensures that the tenant has the necessary features for conditional access and device management policies.

Exam trap

The trap here is that candidates often confuse the licensing requirement (Entra ID P1/P2) with the need for a separate MDM license like Intune, or mistakenly think that Windows Home edition or Configuration Manager are required for automatic enrollment.

Page 5

Page 6 of 10

Page 7

All pages