MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
An organization is implementing Microsoft Entra Verified ID for verifiable credentials. They want to issue credentials to employees that can be used to prove employment status to third parties. Which component must be created first?
⚠ Common exam trap
It's easy for candidates to confuse the order of setup steps, assuming the DID must be manually created first, when in fact the DID is automatically generated during the Verified ID service initialization, and the credential manifest is the first component that requires explicit user configuration in the admin center.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A credential manifest in the Microsoft Entra admin center
The credential manifest defines the rules for issuing a verifiable credential, including the claims schema, display information, and issuance policies. In Microsoft Entra Verified ID, you must create the credential manifest in the Entra admin center before any credentials can be issued, as it serves as the template that governs the credential's structure and validation. Without a manifest, there is no definition for what the credential contains or how it should be presented.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A presentation request policy
Why it's wrong here
A presentation request policy governs the verification flow, not the issuance flow. In Microsoft Entra Verified ID, a presentation request policy specifies which verifiable credentials the relying party will accept, the requested claims, and the authentication requirements when a user presents their credential wallet for verification. It does not define the schema, claims, or display rules of a credential to be issued, so creating one would fail to produce an issuance capability.
- ✗
A distributed ledger network
Why it's wrong here
The distributed ledger is an inherent part of Microsoft's infrastructure rather than something you deploy. Verified ID uses the ION (Identity Overlay Network), a Sidetree-based protocol anchored on the Bitcoin blockchain, which automatically stores the public DIDs and did-documents. When you enable Verified ID in your tenant, Microsoft creates and registers your organization's DID on this existing network; therefore, specifying or creating a distributed ledger network is not a required configuration step and is actually not even exposed as an option in the Microsoft Entra admin center.
- ✓
A credential manifest in the Microsoft Entra admin center
Why this is correct
A credential manifest is the core configuration artifact for issuing a verifiable credential in Microsoft Entra Verified ID. Defined in the Microsoft Entra admin center, it combines rules and display information: the rules definition specifies required claims, such as user attributes and optional validation logic, while the display definition controls the JSON schema and the visual layout of the credential. This manifest is what transforms a user's claim data into a signed verifiable credential, making it essential for any issuance scenario. Without it, the right issuance API calls would lack the necessary structure and would fail.
- ✗
A decentralized identifier (DID) for the organization
Why it's wrong here
A decentralized identifier (DID) for your organization is a byproduct of the Verified ID provisioning process, not a separate manual step. When you first set up Verified ID in the Microsoft Entra admin center, the system automatically generates your tenant's DID and registers it on the ION network along with the corresponding did-document. You do not have to create the DID ahead of time; attempting to do so would be redundant and could cause confusion about the intended trust anchor. This automatic creation is a key reason why a DID is not the artifact you explicitly create to enable issuance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.