MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Exhibit
Refer to the exhibit.
```
$params = @{
"blockSignIn" = $true
"signInActivity" = @{
"lastSuccessfulSignInDateTime" = (Get-Date).AddDays(-90)
}
}
Update-MgUser -UserId "user@contoso.com" -BodyParameter $params
```An administrator runs the PowerShell command shown in the exhibit. What is the immediate effect on the user?
⚠ Common exam trap
Many candidates confuse `BlockCredential` with disabling the account or setting an inactivity policy, but the command only blocks sign-in immediately without any time-based or deletion behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user is blocked from signing in immediately.
The PowerShell command `Set-MgUser -UserId user@domain.com -BlockCredential $true` immediately blocks the user from signing in by setting the `BlockCredential` property to true. This prevents any new authentication attempts, effectively locking the account without changing the password or deleting the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is disabled after 90 days of inactivity.
Why it's wrong here
This cmdlet does not introduce any time delay or inactivity monitoring. It immediately flips the sign-in status property at execution time. Microsoft Entra ID's 'inactive users' detection is a separate administrative review process that identifies accounts unused for a specified period (e.g., 90 days) and requires an administrator to take action; the PowerShell command being run does not schedule or trigger that future state.
- ✓
The user is blocked from signing in immediately.
Why this is correct
The command sets the user account's sign-in block attribute (such as AccountEnabled to $false or BlockCredential to $true) synchronously. As soon as the cmdlet completes, Microsoft Entra ID revokes the user's ability to obtain tokens and authenticate for interactive or service-based sign-ins. This is a real-time, at-scale action commonly used for immediate access termination.
- ✗
The user is deleted after 90 days of inactivity.
Why it's wrong here
Deleting a user object requires a separate Remove-AzureADUser or Remove-MsolUser cmdlet and is not a deferred side effect of a sign-in block. The command only modifies the authentication toggle; it does not remove or schedule removal of the directory object. Tenant lifecycle or governance policies might eventually delete inactive users, but that would involve independent automation or admin action, not this cmdlet.
- ✗
The user's password is reset.
Why it's wrong here
Resetting a user's password involves either the Set-MsolUserPassword or Update-AzureADUserPassword cmdlet or the Azure portal self-service flow, not the sign-in block command. This cmdlet does not alter the password hash or credential store; it only changes the boolean that gates sign-in. Even if the user later has the block removed, the existing password remains unchanged.
Go deeper
Related to this question
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.