Courseiva

CCNA Deploy and manage a Microsoft 365 tenant Questions

46 of 196 questions · Page 3/3 · Deploy and manage a Microsoft 365 tenant · Answers revealed

151
Multi-Selecteasy

Your company is planning to use Microsoft 365 Copilot for Microsoft 365. Which THREE prerequisites are required for Copilot to function? (Choose three.)

Select 3 answers
A.Microsoft Entra ID (formerly Azure AD)
B.Microsoft Sentinel for security monitoring
C.Microsoft Intune for mobile device management
D.A Copilot for Microsoft 365 license assigned to each user
E.An active Microsoft 365 subscription (E3, E5, Business Premium, etc.)
AnswersA, D, E

Microsoft Entra ID is the identity and authentication backbone for Microsoft 365 Copilot. When a user sends a prompt, Copilot uses the Entra ID token to authenticate the user and to determine which resources the user can access through Microsoft Graph. Without Entra ID, there is no verified user identity, no conditional access enforcement, and no way to apply tenant policies to Copilot interactions, so this is a mandatory prerequisite rather than an optional component.

Why this answer

Microsoft Entra ID (formerly Azure AD) is required because Copilot for Microsoft 365 relies on Entra ID for authentication, identity management, and policy enforcement. Without Entra ID, Copilot cannot verify user identities, apply conditional access policies, or access Microsoft Graph to retrieve user and organizational data.

Exam trap

The trap here is that candidates confuse optional security or management services (Sentinel, Intune) with mandatory infrastructure (Entra ID), leading them to select non-essential components as prerequisites.

152
MCQeasy

A company has purchased 1000 Microsoft 365 E5 licenses and wants to automatically assign licenses to users based on their department attribute, which is synchronized from on-premises Active Directory. The department attribute is stored in Azure AD. Which automated method should the administrator use to achieve this?

A.Group-based licensing with dynamic groups
B.scheduled PowerShell script that runs daily
C.Manual license assignment via the Microsoft 365 admin center
D.Bulk assign licenses using the admin center import feature
AnswerA

Dynamic groups in Azure AD use membership rules based on user attributes such as department or location. When a user satisfies the rule, they are automatically added to the group, and licenses assigned to the group are provisioned to that user without manual intervention. If the user no longer meets the rule, they are removed and the license is automatically revoked. This built-in, identity-driven approach scales effortlessly to 1000 users and handles future changes in membership automatically.

Why this answer

Group-based licensing with dynamic groups is the correct method because it allows automatic license assignment based on user attributes like department, which is synchronized from on-premises Active Directory via Azure AD Connect. Dynamic groups evaluate membership rules in Azure AD, and when a user's department attribute matches the rule, the group-based licensing policy automatically assigns or removes the Microsoft 365 E5 license without manual intervention.

Exam trap

The trap here is that candidates often choose a scheduled PowerShell script (Option B) thinking it is more flexible or reliable, but they overlook that group-based licensing is the native, fully automated, and supported method for attribute-driven license assignment in Azure AD.

How to eliminate wrong answers

Option B is wrong because a scheduled PowerShell script that runs daily introduces latency (up to 24 hours) and requires ongoing maintenance, whereas group-based licensing provides near-real-time assignment and revocation. Option C is wrong because manual license assignment via the Microsoft 365 admin center is not automated and does not scale to 1000 users based on a dynamic attribute. Option D is wrong because bulk assign licenses using the admin center import feature is a one-time, static assignment based on a CSV file, not an automated method that responds to changes in the department attribute.

153
MCQeasy

An administrator runs the PowerShell command shown in the exhibit. What is the immediate effect on the user?

A.The user is disabled after 90 days of inactivity.
B.The user is blocked from signing in immediately.
C.The user is deleted after 90 days of inactivity.
D.The user's password is reset.
AnswerB

The command sets the user account's sign-in block attribute (such as AccountEnabled to $false or BlockCredential to $true) synchronously. As soon as the cmdlet completes, Azure AD revokes the user's ability to obtain tokens and authenticate for interactive or service-based sign-ins. This is a real-time, at-scale action commonly used for immediate access termination.

Why this answer

The PowerShell command `Set-MgUser -UserId user@domain.com -BlockCredential $true` immediately blocks the user from signing in by setting the `BlockCredential` property to true. This prevents any new authentication attempts, effectively locking the account without changing the password or deleting the user.

Exam trap

The trap here is that candidates confuse `BlockCredential` with disabling the account or setting an inactivity policy, but the command only blocks sign-in immediately without any time-based or deletion behavior.

How to eliminate wrong answers

Option A is wrong because the command does not set any inactivity-based disablement; that would require a different cmdlet like `Set-MgUser` with `-SignInActivity` or a conditional access policy. Option C is wrong because the command does not delete the user; deletion requires `Remove-MgUser`. Option D is wrong because the command does not reset the password; password reset requires `Update-MgUserPassword` or the admin portal.

154
MCQeasy

A company has just signed up for Microsoft 365 Business Standard without adding a custom domain. An administrator needs to create the first user accounts. What will be the default email address format for these new users?

A.username@contoso.com
B.username@onmicrosoft.com
C.username@<tenantname>.onmicrosoft.com
D.username@microsoftonline.com
AnswerC

When the tenant is provisioned, Microsoft creates a unique initial domain in the format <tenantname>.onmicrosoft.com, which is automatically registered and verified. New users are assigned the user principal name and email address using this domain by default, because no custom domains have been added yet. This domain remains the default until a custom domain is added and set as primary. Therefore, username@<tenantname>.onmicrosoft.com is the correct email suffix after signing up for Microsoft 365 Business Standard.

Why this answer

When a Microsoft 365 tenant is created without adding a custom domain, the default domain is the `<tenantname>.onmicrosoft.com` domain. New user accounts are automatically assigned an email address in the format `username@<tenantname>.onmicrosoft.com`, as this is the initial domain provisioned for the tenant. Option C correctly reflects this default behavior.

Exam trap

The trap here is that candidates often confuse the default `onmicrosoft.com` domain with the generic `microsoftonline.com` domain used for Azure AD authentication, or assume a custom domain like `contoso.com` is automatically assigned, leading them to select A or D instead of recognizing the tenant-specific subdomain format.

How to eliminate wrong answers

Option A is wrong because `contoso.com` is a custom domain that must be explicitly added and verified in the tenant; it is not the default domain when no custom domain is configured. Option B is wrong because `onmicrosoft.com` is a Microsoft-owned domain used for services like Outlook, but the tenant-specific subdomain (e.g., `contoso.onmicrosoft.com`) is required; a bare `@onmicrosoft.com` address is not valid for a tenant. Option D is wrong because `microsoftonline.com` is the domain used for Azure AD authentication endpoints (e.g., login.microsoftonline.com), not for user email addresses.

155
MCQhard

You are a Microsoft 365 administrator. Your tenant has a Microsoft Entra ID P2 license. You need to create a dynamic group for all users whose department is 'Engineering' and who are located in the United States. Which rule syntax should you use?

A.user.department -eq "Engineering" and user.country -eq "US"
B.user.department -eq "Engineering" And user.country -eq "United States"
C.user.department -eq "Engineering" and user.country -eq "United States"
D.user.department -eq "Engineering" AND user.country -eq "United States"
AnswerC

This expression is correct because it uses all lowercase operators ('and'), which are required by the dynamic membership rule parser, and matches the exact stored values: the department attribute string 'Engineering' and the country attribute display name 'United States'. The rule accurately targets users who meet both conditions simultaneously.

Why this answer

Dynamic group rules in Microsoft Entra ID require the use of lowercase 'and' as the logical operator, and the country attribute value must match the display name 'United States' as stored in the directory. The rule syntax must follow the property -operator 'value' format exactly, with no capitalization of 'and'.

Exam trap

The trap here is that candidates often confuse the country attribute value with the two-letter ISO code 'US' or incorrectly capitalize the logical operator 'and', leading them to choose options that would fail validation or produce incorrect membership results.

How to eliminate wrong answers

Option A is wrong because it uses 'US' as the country value, but Microsoft Entra ID stores the country attribute as the full display name 'United States', not the two-letter ISO code. Option B is wrong because it capitalizes 'And' as 'And', but dynamic group rules require the logical operator to be all lowercase 'and'. Option D is wrong because it capitalizes 'AND' as 'AND', but the rule syntax mandates the lowercase 'and' operator.

156
Multi-Selectmedium

You are the Microsoft 365 administrator for a company with a Microsoft 365 E3 tenant. The security team requires that you reduce the attack surface for email by blocking auto-forwarding to external domains and by ensuring that any email sent from an external sender that spoofs your custom domain is rejected. You must implement the controls natively in Microsoft 365 Defender. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create an outbound anti-spam policy and set the Automatic forwarding rule to Off, then apply the policy to all recipients.
B.Create an anti-phishing policy and enable the mailbox intelligence setting for all users.
C.Configure the anti-phishing policy's Spoof intelligence by adding your custom domain as an allowed sender so that internal spoofing is permitted.
D.Ensure the default anti-phishing policy's anti-spoofing protection is enabled and that no allowed sender entry exists for your custom domain in the Tenant Allow/Block List.
E.Add your custom domain to the Domain impersonation section of the anti-phishing policy and set the action to Quarantine the message.
AnswersA, D

The outbound anti-spam policy contains the Automatic forwarding setting that controls whether users can auto-forward email to external domains. Setting it to Off blocks this exfiltration path, and applying the policy to all recipients ensures the control is tenant-wide. This directly addresses the requirement to prevent automatic external forwarding.

Why this answer

Blocking external auto-forwarding is done through the Automatic forwarding setting in an outbound anti-spam policy applied to all recipients. Rejecting spoofed mail that claims to be from your own domain relies on the anti-spoofing intelligence built into the default anti-phishing policy, which acts on your accepted domains, provided no allow entry in the Tenant Allow/Block List overrides the verdict.

Exam trap

The trap here is mixing up domain impersonation, which targets lookalike domains, with anti-spoofing intelligence, which handles exact spoofs of domains you own.

157
Multi-Selecthard

You are implementing Microsoft Defender for Office 365. You need to configure anti-phishing policies to protect against user impersonation. Which THREE settings should you configure?

Select 3 answers
A.Enable impersonation protection for domains you own.
B.Enable mailbox intelligence to detect impersonation based on user behavior.
C.Set the bulk email threshold.
D.Enable impersonation protection for users who are defined as protected users.
E.Configure spoof intelligence to allow or block senders.
AnswersA, B, D

Enabling impersonation protection for domains you own directly instructs Defender for Office 365 to inspect messages where the sender address visually mimics any domain associated with your tenant. In the anti-phishing policy, toggling on this setting and optionally listing additional domains subjects such forged domain messages to the configured action (quarantine, redirect, or mailbox rule). Because the requirement centers on defending against attackers who abuse your own domain as the sender, this is the primary and correct configuration to implement.

Why this answer

Enabling impersonation protection for domains you own allows Defender for Office 365 to detect and act on attempts to spoof your organization's domain in the From address. This setting ensures that emails claiming to be from your domain are inspected for impersonation patterns, such as lookalike domains or display name spoofing, and can be automatically quarantined or have safety tips applied.

Exam trap

The trap here is that candidates confuse anti-phishing settings with anti-spam or spoof intelligence settings, mistakenly selecting bulk email threshold or spoof intelligence when the question explicitly targets user impersonation protection.

158
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a custom Line-of-Business (LOB) app to a group of devices. The app is not in the Microsoft Store. What is the recommended method to deploy the app?

A.Add the app as a Microsoft Store app (business) in Intune.
B.Use Group Policy to deploy the app via a network share.
C.Publish the app to the Microsoft Store for Business and assign it.
D.Upload the app package to Intune as a Line-of-Business app and assign it to the device group.
AnswerD

Upload the app package to Intune as a Line-of-Business app and assign it to the device group. This is the standard Intune method for side-loading a custom internal application: you navigate to Apps > All Apps > Add, choose the 'Line-of-business app' type, upload the MSI or APPX installable package, and then configure the assignment as Required to an Azure AD device group. Intune stores the package in Azure and handles download and installation on each enrolled Windows 10 device, making it the correct native deployment mechanism for a custom LOB application.

Why this answer

Intune natively supports deploying custom Line-of-Business (LOB) apps by uploading the app package (e.g., .msi, .exe, .appx) directly into the Intune console and assigning it to a device group. This method is the recommended approach for apps not available in the Microsoft Store, as it leverages Intune's mobile device management (MDM) capabilities to push the app to Windows 10 devices without requiring external infrastructure like Group Policy or the Microsoft Store for Business.

Exam trap

The trap here is that candidates may confuse the Microsoft Store for Business (now Microsoft Store) as a viable publishing platform for custom LOB apps, not realizing that the store only accepts apps that meet Microsoft's submission requirements and is not designed for internal, proprietary applications.

How to eliminate wrong answers

Option A is wrong because adding the app as a Microsoft Store app (business) in Intune is intended for apps that are already available in the Microsoft Store for Business, not for custom LOB apps that are not in the store. Option B is wrong because Group Policy deployment via a network share is a traditional on-premises method that does not integrate with Intune's cloud-based MDM, and it requires devices to be domain-joined and connected to the corporate network, which is not recommended for modern, cloud-managed environments. Option C is wrong because publishing a custom LOB app to the Microsoft Store for Business is not supported; the store only accepts apps that meet specific submission criteria and are not intended for internal, proprietary line-of-business applications.

159
MCQhard

You manage a Microsoft 365 tenant for a company that uses Microsoft Defender for Office 365 Plan 2. The security team reports that several users clicked a link in a phishing email and entered credentials on a fake sign-in page. You must identify which users were compromised and remediate their accounts as quickly as possible. What should you do?

A.Use the Compromised users report in Microsoft 365 Defender to identify affected users, then select the users and choose to force a password reset and revoke their sessions.
B.Run the Get-MessageTraceV2 cmdlet in Exchange Online PowerShell for the phishing message and disable the accounts of every recipient.
C.Review the Attack simulation training report for the tenant and export the list of users who failed the simulation.
D.Open the Threat Explorer in Microsoft 365 Defender, filter by the sender address, and manually review the message trace for each recipient.
AnswerA

In tenants with Microsoft Defender for Office 365 Plan 2, the compromised users report surfaces users whose credentials were entered on a phishing page detected by the service. From the report, an administrator can confirm the users, then force a password reset and revoke active sessions to contain the compromise quickly.

Why this answer

The Compromised users report in Microsoft 365 Defender uses signals from Defender for Office 365 to detect when a user enters credentials on a phishing site. Because the tenant has Plan 2, the report is available and includes the affected users. From the report, the administrator can force a password reset and revoke sessions, which are the recommended containment actions.

Exam trap

The trap here is reaching for message trace or Threat Explorer, which show delivery and URL data but cannot reveal which recipients actually submitted credentials on the phishing page.

160
Drag & Dropmedium

Drag and drop the steps to configure role-based access control (RBAC) in Microsoft 365 Defender in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

RBAC roles are created/edited in Defender, permissions assigned, and then assigned to users/groups.

161
Multi-Selecteasy

Your organization needs to manage guest access to Microsoft Teams. Which TWO methods can you use to control guest access?

Select 2 answers
A.Use sensitivity labels to restrict guest access.
B.Configure SharePoint Online external sharing settings.
C.Enable guest access in the Teams admin center.
D.Set conditional access policies for guest users.
E.Configure external collaboration settings in Microsoft Entra ID.
AnswersC, E

In the Microsoft Teams admin center, the Org-wide settings > Guest access section includes an 'Allow guest access in Microsoft Teams' toggle that must be set to On. This setting is the Teams-specific control that admits guest accounts into the team membership and lets them participate in channels and chats. Without this toggle enabled, guests cannot be added to a team even if Microsoft Entra ID allows B2B collaboration invitations. Thus, enabling guest access in the Teams admin center is a required step to support guest collaboration in Teams.

Why this answer

Enabling guest access in the Teams admin center is a required step to allow guest users to join Teams. Without this toggle enabled, guest access is blocked at the Teams level regardless of other settings. This setting works in conjunction with Microsoft Entra ID external collaboration settings to control guest access.

Exam trap

The trap here is that candidates often confuse the separate layers of control—Teams-specific settings (admin center) versus tenant-wide identity settings (Entra ID)—and may think that only one of these two correct options is needed, or that SharePoint settings (Option B) are sufficient for Teams guest access.

162
MCQeasy

An administrator adds the custom domain 'fabrikam.com' to a new Microsoft 365 tenant. After adding the domain, the status shows 'Pending verification'. Which type of DNS record must be added to the public DNS zone to complete domain ownership verification?

A.MX record
B.TXT record
C.CNAME record
D.SPF record
AnswerB

Microsoft 365 proves domain ownership by reading a unique TXT value from the domain's public DNS zone. The tenant compares the returned string against the supplied token, and only a matching TXT record moves the domain from Pending verification to verified.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record with a specific verification value provided by the Microsoft 365 admin center to the public DNS zone. This proves you control the domain because only the domain owner can modify DNS records. Other record types like MX, CNAME, or SPF are used for mail routing or service configuration, not for ownership verification.

Exam trap

The trap here is that candidates confuse the verification TXT record with other TXT-based records like SPF or DKIM, or assume any DNS record type can be used for verification, but Microsoft specifically requires a TXT record with a unique token for domain ownership proof.

How to eliminate wrong answers

Option A is wrong because MX records are used to specify mail exchange servers for email routing, not for domain ownership verification. Option C is wrong because CNAME records alias one domain name to another and are not used for verification; they are typically used for service-specific configurations like autodiscover. Option D is wrong because SPF records are a type of TXT record used to authorize sending servers for email authentication, but the verification process requires a specific TXT record with a unique token, not an SPF record.

163
MCQmedium

You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P1 and Microsoft 365 E3. A new security policy requires that when users sign in from outside the corporate network, they must use Microsoft Entra multifactor authentication. However, users signing in from the corporate office network must not be prompted for MFA. The corporate office has a public IP address range of 203.0.113.0/24. You create a named location called 'Corporate Office' with this IP range. What should you do next to meet the requirement?

A.Create a conditional access policy that targets all users and all cloud apps, set the condition to exclude the 'Corporate Office' named location, and require multifactor authentication.
B.Create a conditional access policy that targets all users and all cloud apps, set the condition to include the 'Corporate Office' named location, and require multifactor authentication.
C.Configure the 'Corporate Office' named location as trusted and enable security defaults.
D.Enable Microsoft Entra multifactor authentication per user for all users, and configure the corporate IP range as trusted IPs in the MFA service settings.
AnswerA

This policy applies MFA to all users and cloud apps but excludes the trusted corporate IP range. Sign-ins from outside the corporate network will not match the exclusion and will trigger MFA, while sign-ins from the office IP range will be excluded and will not require MFA. This meets the requirement exactly.

Why this answer

A conditional access policy is the correct tool to enforce MFA based on network location. By excluding a named location containing the corporate IP range, the policy applies MFA only when users sign in from outside that range. This satisfies the security policy while avoiding unnecessary prompts for on-premises users.

Exam trap

The trap here is confusing the include and exclude conditions in conditional access, or thinking that trusted IPs in per-user MFA can achieve location-based enforcement.

164
MCQmedium

A company has a Microsoft 365 tenant that uses the default contoso.onmicrosoft.com domain. The IT team wants to add a new custom domain, contoso.com, and ensure that all existing users' primary email addresses automatically change to the new domain. They also want to prevent users from signing in with the onmicrosoft.com domain. What should the administrator do first?

A.Modify the default email address policy in Exchange Online to use contoso.com as the primary SMTP suffix.
B.Create a new mail-enabled security group for all users and assign the contoso.com SMTP address to the group.
C.Run the Set-MsolUserPrincipalName PowerShell cmdlet to change each user's UPN to contoso.com.
D.Add contoso.com as a custom domain in the Microsoft 365 admin center and verify ownership by adding a TXT record to the public DNS zone.
AnswerD

Adding and verifying the custom domain is the mandatory first step before it can be used for email addresses or sign-in. Verification proves domain ownership via a DNS TXT record. Until the domain is verified, you cannot assign it to users, set it as default, or change UPN suffixes. This action directly enables the subsequent steps of updating user principal names and email addresses.

Why this answer

Before any custom domain can be used in Microsoft 365, it must be added and verified in the admin center. Verification typically involves adding a TXT record to the domain's DNS. Only after verification can the domain be assigned to users, set as default, or used for sign-in.

Changing UPNs or email address policies requires the domain to exist first.

Exam trap

The trap here is assuming that changing a user's UPN or email address policy will automatically add and verify a new domain, but domain verification must occur first.

165
MCQeasy

An organization has just purchased Microsoft 365 Business Standard licenses. The administrator adds a new user through the admin center. By default, does the new user receive a welcome email with sign-in instructions?

A.Yes, always, regardless of how the user is created.
B.Yes, if the administrator does not clear the 'Send welcome email' checkbox during user creation.
C.No, the administrator must manually send the welcome email using a script.
D.No, welcome emails are only sent when using the 'Add multiple users' option.
AnswerB

Correct — when an administrator adds a user through the admin center, either individually or in bulk, the 'Send welcome email' checkbox appears on the 'Finish' or 'Settings' page and is checked by default. As long as that box remains checked during the creation process, Microsoft 365 automatically sends the welcome email to the user's designated email address with the temporary password and sign-in information. If the administrator unchecks the box, no email is sent and the admin must distribute credentials another way.

Why this answer

When an administrator adds a new user through the Microsoft 365 admin center, the default behavior is to send a welcome email containing the user's sign-in name and temporary password. The administrator can opt out by clearing the 'Send welcome email in email' checkbox during the creation process. Therefore, the user receives the email unless the administrator explicitly deselects that option.

Exam trap

The trap here is that candidates may assume the welcome email is always sent or never sent, overlooking the specific checkbox control that allows the administrator to suppress the email during user creation.

How to eliminate wrong answers

Option A is wrong because the welcome email is not always sent; it depends on the checkbox state during user creation, and if the user is created via other methods (e.g., PowerShell, bulk CSV import), the email may not be sent by default. Option C is wrong because the administrator does not need to manually send the email using a script; the admin center provides a built-in checkbox to control sending, and the email is sent automatically unless the checkbox is cleared. Option D is wrong because the welcome email is sent for single user creation as well, not only when using the 'Add multiple users' option; the checkbox exists in both single and bulk creation flows.

166
MCQhard

You have a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover unsanctioned cloud apps used by users. What should you configure?

A.Conditional Access App Control
B.Microsoft Purview Data Loss Prevention
C.Microsoft Defender for Endpoint App Control
D.Microsoft Defender for Cloud Apps Cloud Discovery
AnswerD

Microsoft Defender for Cloud Apps Cloud Discovery parses your network traffic logs, either uploaded manually or forwarded via integrated proxies and Defender for Endpoint, to identify and score the cloud apps your users access. It compares traffic against a catalog of over 31,000 apps and even detects unknown apps heuristically, enabling you to mark them as sanctioned or unsanctioned. This is the correct tool for discovering the full landscape of apps in your environment.

Why this answer

Microsoft Defender for Cloud Apps Cloud Discovery is the correct feature for identifying unsanctioned cloud apps used in your environment. It analyzes traffic logs from your network or endpoints to discover all cloud app usage, categorizes them by risk, and allows you to sanction or unsanction them. This directly fulfills the requirement to discover unsanctioned cloud apps.

Exam trap

The trap here is that candidates confuse Conditional Access App Control (a policy enforcement mechanism for sanctioned apps) with Cloud Discovery (the actual discovery and risk assessment feature), leading them to select Option A instead of the correct answer.

How to eliminate wrong answers

Option A is wrong because Conditional Access App Control is a session-level policy enforcement feature that works with sanctioned apps to control access and data exfiltration, not a discovery tool for finding unsanctioned apps. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent sensitive data from being shared or leaked, not to discover or inventory cloud app usage. Option C is wrong because Microsoft Defender for Endpoint App Control (Windows Defender Application Control) is a host-based security feature that controls which executables can run on Windows devices, not a cloud app discovery mechanism.

167
MCQmedium

The exhibit shows a KQL query used in Microsoft 365 Defender. The query returns no results for admin@contoso.com. What is the most likely reason?

A.The user does not have the Global Administrator role.
B.The KQL query syntax is invalid.
C.The role name in the query is misspelled.
D.Microsoft Defender for Identity is not enabled for the tenant.
AnswerD

IdentityInfo is not derived from the Microsoft Graph or role directory alone; it is continuously synchronized by Microsoft Defender for Identity (MDI) sensors from on-premises Active Directory and Azure AD. MDI enriches identities with role, group, and resource access data. When MDI is not onboarded or properly licensed, the IdentityInfo table remains empty or contains only incomplete data, so any query filtering it returns no rows. This is the root cause consistent with an empty result set and a valid query, making it the only correct answer here.

Why this answer

The KQL query uses the `IdentityLogonEvents` table, which is populated by Microsoft Defender for Identity (MDI). If MDI is not enabled for the tenant, this table contains no data, so the query returns no results regardless of the user's role or query syntax. The query itself is syntactically correct and the role name 'GlobalAdministrator' is valid, but without MDI being provisioned, the table is empty.

Exam trap

The trap here is that candidates often assume a query returning no results must have a syntax error or a misspelled value, when in fact the underlying data source (Defender for Identity) may not be provisioned, causing the table to be empty.

How to eliminate wrong answers

Option A is wrong because the query filters on the `AccountUpn` field, not on administrative roles; even if the user lacks the Global Administrator role, the query would still return logon events for that user if MDI were enabled. Option B is wrong because the KQL syntax is valid: it correctly uses the `where` operator with a string comparison and a logical `and` to filter on `ActionType`. Option C is wrong because 'GlobalAdministrator' is the correct role name as stored in the `AccountSid` or related fields in Defender for Identity; a misspelling would cause a syntax error or no match, but the query returns no results for a valid user, indicating the data source itself is missing.

168
MCQmedium

A company is planning to migrate from on-premises Exchange to Exchange Online and needs to ensure that mail flow can coexist between the two environments during the transition. Which tool should the administrator use to configure this hybrid deployment?

A.Azure AD Connect
B.Exchange Hybrid Configuration Wizard
C.Microsoft 365 Admin Center
D.Exchange Admin Center
AnswerB

The Exchange Hybrid Configuration Wizard automates creation of the hybrid configuration, including connectors, accepted domains, OAuth and the free/busy sharing needed for coexistence. It is the supported tool for establishing mail flow between on-premises Exchange and Exchange Online during migration.

Why this answer

The Exchange Hybrid Configuration Wizard (HCW) is the correct tool because it automates the configuration of coexistence features between on-premises Exchange and Exchange Online, including mail flow routing, free/busy sharing, and OAuth authentication. It generates the necessary connectors and settings to support a hybrid deployment, ensuring seamless mail flow during migration.

Exam trap

The trap here is that candidates often confuse Azure AD Connect's directory synchronization role with hybrid mail flow configuration, assuming it handles all hybrid setup, when in fact it only syncs objects and does not configure Exchange-specific routing or coexistence.

How to eliminate wrong answers

Option A is wrong because Azure AD Connect synchronizes directory objects (users, groups) but does not configure mail flow or hybrid coexistence settings between Exchange environments. Option C is wrong because the Microsoft 365 Admin Center provides high-level tenant management and licensing but lacks the granular Exchange-specific hybrid configuration capabilities. Option D is wrong because the Exchange Admin Center (EAC) in Exchange Online or on-premises can manage individual connectors and settings but does not provide the guided, automated workflow of the HCW for establishing a full hybrid deployment.

169
MCQeasy

A new administrator needs to automatically assign Microsoft 365 E5 licenses to all users in the Sales department. The Sales department is identified by the 'department' attribute in Azure AD. Which licensing method should the administrator use to minimize manual effort?

A.Manual license assignment per user
B.Group-based licensing using a dynamic group
C.PowerShell script to assign licenses
D.Bulk license assignment via CSV file
AnswerB

Dynamic groups evaluate the 'department' attribute through membership rules, so users added to Sales are licensed automatically without manual intervention. Group-based licensing then assigns the E5 licence and removes it when users leave, satisfying the requirement to minimise ongoing administrative effort.

Why this answer

Group-based licensing using a dynamic group is the correct method because it automatically assigns Microsoft 365 E5 licenses to all users in the Sales department based on the 'department' attribute in Azure AD. Dynamic groups evaluate membership rules in real time, so when a user's department attribute is set to 'Sales', the license is assigned without manual intervention. This minimizes administrative effort by eliminating the need for per-user or batch operations.

Exam trap

The trap here is that candidates often choose PowerShell scripting (Option C) thinking it is the most automated method, but they overlook that group-based licensing provides true zero-touch, attribute-driven automation without requiring custom code or scheduled tasks.

How to eliminate wrong answers

Option A is wrong because manual license assignment per user requires an administrator to individually assign licenses to each Sales department user, which is labor-intensive and does not scale. Option C is wrong because a PowerShell script, while automatable, still requires manual execution or scheduling and does not provide real-time, attribute-based automatic assignment like group-based licensing does. Option D is wrong because bulk license assignment via CSV file is a one-time operation that does not automatically handle new users or attribute changes, requiring repeated manual exports and imports.

170
MCQhard

You are a Microsoft 365 administrator. Users report that they cannot create Microsoft Teams meetings using the Teams desktop client. They receive an error: 'Meeting creation is disabled by your IT administrator.' You need to enable meeting creation. You check the Teams admin center and find that meeting policies are set to 'Off' for 'Allow private meeting scheduling'. However, after changing it to 'On', users still get the error. What is the most likely cause?

A.The user does not have an OAuth 2.0 token.
B.The global meeting policy is overriding the user-level policy.
C.The user's mailbox is still on-premises and not migrated to Exchange Online.
D.The user does not have a Microsoft Teams license assigned.
AnswerC

Teams meeting schedules are stored in the user's Exchange calendar. When the user mailbox remains on-premises in a hybrid deployment, the Teams meeting policy is ineffective because the online meeting workspace is controlled by Exchange on-premises, not by Exchange Online. Only after the mailbox is migrated to Exchange Online will Teams be able to provision the meeting workspace and enforce the assigned meeting policy.

Why this answer

The error persists because the user's mailbox is still on-premises and not migrated to Exchange Online. Microsoft Teams relies on Exchange Online for scheduling features, including private meeting creation. Even with the meeting policy set to 'On', if the mailbox is on-premises, the Teams client cannot communicate with Exchange Online to create the meeting, resulting in the error.

Exam trap

The trap here is that candidates often assume changing the meeting policy in the Teams admin center is sufficient, overlooking the critical dependency on Exchange Online for Teams calendar features, which is a common misconfiguration in hybrid environments.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 tokens are used for authentication and authorization, not for enabling or disabling meeting creation; the error is policy-related, not token-related. Option B is wrong because the global meeting policy only applies if no user-level policy is assigned; if a user-level policy is explicitly set to 'On', it should override the global policy, so this would not cause the error. Option D is wrong because if the user lacked a Teams license, they would not be able to access the Teams desktop client at all, or would see a different error about licensing, not a specific meeting creation disabled error.

171
MCQeasy

Your company is deploying Microsoft 365 for a new subsidiary with 500 users. You need to configure the initial tenant with a custom domain (contoso.com) and verify ownership. What is the first step you must perform?

A.Delegate the contoso.com zone to Microsoft 365 DNS servers.
B.Create user accounts with the custom domain before verification.
C.Add a TXT record provided by Microsoft 365 to the contoso.com DNS zone.
D.Set contoso.com as the default domain in the Microsoft 365 admin center.
AnswerC

Adding the TXT record provided by the Microsoft 365 domain setup wizard is the correct verification method. The wizard generates a unique TXT record value that you must publish in the public DNS zone of contoso.com; Microsoft 365 then queries the DNS to confirm the record exists and matches, proving your control over the domain. This TXT record is a one-time verification token and is separate from any SPF or DKIM TXT records. Once Microsoft 365 detects the record, the domain status changes to 'Verified' and you can proceed with configuring services and creating users.

Why this answer

To verify ownership of a custom domain in Microsoft 365, you must prove you control the domain's DNS zone. Microsoft provides a unique TXT record value that you add to the public DNS zone of contoso.com. Once the TXT record propagates, Microsoft queries it and confirms ownership, allowing you to proceed with domain configuration.

Exam trap

The trap here is that candidates may confuse the order of operations, thinking they can set the domain as default or create users first, but Microsoft 365 strictly requires domain ownership verification before any domain-based configuration can proceed.

How to eliminate wrong answers

Option A is wrong because delegating the entire contoso.com zone to Microsoft 365 DNS servers is not the first step; delegation is optional and only performed after domain verification if you want Microsoft to manage your DNS records. Option B is wrong because you cannot create user accounts with a custom domain before the domain is verified; Microsoft 365 will reject the domain until ownership is proven. Option D is wrong because setting contoso.com as the default domain requires the domain to already be verified; attempting to set it before verification will fail.

172
MCQeasy

A company wants to prevent their Microsoft 365 tenant from allowing external users to be invited by default. Only specific administrators should be able to invite guests. Which setting should be changed?

A.External Identities – External collaboration settings
B.Conditional Access policy to block external users
C.Tenant restrictions
D.B2B direct connect
AnswerA

In Entra ID (Azure AD), navigate to External Identities > External collaboration settings and change the Guest invite settings to 'Only users assigned to specific admin roles can invite guests' (or 'No one can invite guests'). This is the administrative toggle that directly restricts who can issue B2B invitations, so it is the correct control to prevent the tenant from broadcasting external-user invitation privileges.

Why this answer

The correct setting is under External Identities – External collaboration settings, specifically the 'Guest invite settings' option. By default, this is set to 'Anyone in the organization can invite guest users including guests and non-admins'. Changing it to 'Only users assigned to specific admin roles can invite guest users' restricts guest invitations to designated administrators, meeting the requirement to prevent default external user invitations.

Exam trap

The trap here is that candidates often confuse 'blocking external users' via Conditional Access (Option B) with controlling the invitation process, but Conditional Access only applies after the user is already in the directory, not to the invitation permission itself.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies control access conditions (like location or device compliance) after a user is already in the tenant, not the ability to invite external users. Option C is wrong because Tenant restrictions control inbound/outbound access to external tenants via HTTP headers, not the invitation process within the same tenant. Option D is wrong because B2B direct connect is a feature for Teams Connect shared channels that allows external users to access resources without being invited as guests; it does not control guest invitation settings.

173
MCQhard

Contoso is a multinational company with 50,000 users. They have a Microsoft 365 E5 subscription and use Microsoft Entra ID for identity. They recently deployed Microsoft Copilot for Microsoft 365 to 10,000 users. The security team wants to ensure that Copilot responses do not expose sensitive information. They also need to monitor Copilot usage for unusual activity. The company uses Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps. You need to configure the environment to meet these requirements. Which action should you take?

A.Create a Microsoft Purview DLP policy that includes Copilot as a location.
B.Configure a Conditional Access policy to restrict Copilot to managed devices.
C.Enable session monitoring in Microsoft Defender for Cloud Apps for Copilot.
D.Create sensitivity labels and auto-labeling policies for Copilot.
AnswerA

Correct: A Microsoft Purview DLP policy that includes Copilot as a location is the right control because it directly inspects both the prompts users enter and the responses Copilot generates for sensitive content—such as credit card numbers, health records, or confidential intellectual property. When matched, the policy can block the interaction or apply a restrictive action, preventing sensitive data from being exposed through AI conversations. This is the only option that combines content inspection with enforcement specifically for Copilot data flows.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can include Microsoft Copilot for Microsoft 365 as a location, allowing the security team to detect and prevent sensitive information from being exposed in Copilot responses. This directly addresses the requirement to ensure Copilot responses do not expose sensitive data by scanning and blocking content based on sensitivity labels or sensitive info types.

Exam trap

The trap here is that candidates often confuse monitoring (Defender for Cloud Apps session monitoring) with prevention (DLP), or assume that sensitivity labels alone can block sensitive data in Copilot responses without a DLP policy explicitly targeting Copilot as a location.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies restrict access based on device compliance or location, but they do not prevent sensitive information from appearing in Copilot responses; they only control who can access Copilot, not what data is exposed. Option C is wrong because session monitoring in Microsoft Defender for Cloud Apps provides visibility into user sessions and can detect anomalous behavior, but it does not proactively block sensitive data in Copilot responses; it is more about monitoring usage for unusual activity, which is a separate requirement. Option D is wrong because creating sensitivity labels and auto-labeling policies for Copilot helps classify and protect data, but without a DLP policy that includes Copilot as a location, the labels alone do not enforce blocking or warning actions when sensitive data is shared via Copilot responses.

174
MCQmedium

A company adds and verifies the custom domain 'contoso.com' in their Microsoft 365 tenant. However, emails sent to new users at user@contoso.com bounce back. The existing MX record for contoso.com points to the on-premises mail server. What is the most likely cause of the bounce?

A.The domain verification failed and needs to be repeated
B.The MX record must be updated to point to Exchange Online
C.Users must be added to the domain in the admin center
D.The SPF record is missing or misconfigured
AnswerB

The MX record is the DNS instruction that tells sending mail servers where to deliver messages for your domain. When you add a verified custom domain to Microsoft 365, you must change this record from your previous email provider to the Exchange Online endpoint (for example, contoso-com.mail.protection.outlook.com). If you leave the old MX value in place, inbound mail continues to route to the legacy mail server, which has no mailbox for the recipient, causing the bounce. Correcting the MX record is the precise fix for bounced incoming mail after domain provisioning.

Why this answer

B is correct because the MX record for contoso.com still points to the on-premises mail server. When a user is created in Exchange Online with the domain contoso.com, inbound email is routed according to the MX record. Since the MX record directs mail to the on-premises server, which does not have a mailbox for the new user, the message bounces.

To deliver mail to Exchange Online, the MX record must be updated to point to Exchange Online (e.g., contoso-com.mail.protection.outlook.com).

Exam trap

The trap here is that candidates often confuse domain verification (a one-time DNS check) with ongoing mail routing (MX record), leading them to think verification failure is the cause, when in fact the MX record is the direct culprit.

How to eliminate wrong answers

Option A is wrong because domain verification is a one-time DNS TXT record check; once verified, it remains valid and does not cause email bounces for new users. Option C is wrong because users are already added to the domain in the admin center (the question states 'adds and verifies the custom domain'), and adding users does not affect mail routing. Option D is wrong because a missing or misconfigured SPF record can cause email to be rejected or marked as spam, but it does not cause a bounce due to the MX record pointing to the wrong server; the immediate cause is the MX record destination.

175
Multi-Selecteasy

Which TWO tools can be used to manage Microsoft 365 tenant settings and configurations?

Select 2 answers
A.Microsoft 365 admin center
B.Exchange admin center (EAC)
C.SharePoint admin center
D.Microsoft 365 PowerShell
E.Microsoft Intune admin center
AnswersA, D

The Microsoft 365 admin center is the primary web-based portal for tenant-wide administration. It provides centralized access to user and group management, license assignment, billing, service health, and security settings. As the main entry point for global admins, it can also delegate to specialized consoles for individual workloads, making it a correct answer for managing the tenant as a whole.

Why this answer

The Microsoft 365 admin center is the primary web-based portal for managing tenant-wide settings such as user licensing, domain management, service health, and security policies. It provides a unified dashboard for configuring core tenant configurations without requiring role-specific consoles.

Exam trap

The trap here is that candidates often confuse role-specific admin centers (like EAC or SharePoint admin center) with the tenant-wide Microsoft 365 admin center, assuming any admin center can manage all tenant settings, whereas each is scoped to its own service.

176
MCQeasy

A company has recently signed up for Microsoft 365 Business Premium. They want to change the default domain from onmicrosoft.com to a custom domain they own. Which step must be completed first before the custom domain can be used for user email addresses?

A.Add the custom domain in the Microsoft 365 admin center
B.Verify domain ownership by adding a TXT record to the domain's DNS
C.Create user accounts with the new domain as their primary email
D.Configure email exchange records (MX)
AnswerA

Adding the custom domain in the Microsoft 365 admin center is the mandatory first step to associate your existing DNS namespace with your tenant. From Domains > Add domain, you enter the domain name, which triggers Microsoft's verification wizard and generates the exact DNS records you must publish. Until this addition is completed, no downstream tasks like verification or user provisioning can begin.

Why this answer

Before a custom domain can be used for user email addresses in Microsoft 365, the domain must first be added to the tenant in the Microsoft 365 admin center. This step creates a domain object in Azure AD that allows Microsoft to associate the domain with your tenant and prepare for ownership verification. Without adding the domain first, subsequent steps like DNS verification or user creation cannot proceed because the system has no record of the domain.

Exam trap

The trap here is that candidates often confuse the order of operations, assuming DNS verification (Option B) is the first step, but Microsoft 365 requires the domain to be added to the tenant as a prerequisite before any DNS records can be validated.

How to eliminate wrong answers

Option B is wrong because verifying domain ownership by adding a TXT record is a required step, but it must occur after the domain is added in the admin center; you cannot verify a domain that hasn't been registered in the tenant. Option C is wrong because creating user accounts with the new domain as their primary email is a later step that requires the domain to be both added and verified first. Option D is wrong because configuring MX records is part of the final DNS configuration for mail routing, which depends on the domain being verified and the tenant ready to accept mail.

177
MCQmedium

Refer to the exhibit. You run the PowerShell commands shown. The output displays 10 mailboxes with various RecipientTypeDetails, including UserMailbox, SharedMailbox, and RoomMailbox. You need to ensure that only user mailboxes are returned. What should you modify?

A.Use the -Properties parameter to specify additional attributes
B.Change RecipientTypeDetails to RecipientType in the Select-Object
C.Add the parameter -Filter "RecipientTypeDetails -eq 'UserMailbox'"
D.Remove the -ShowProgress parameter
AnswerC

Adding the -Filter parameter with the OData query "RecipientTypeDetails -eq 'UserMailbox'" is the correct approach because it performs server-side filtering on the Get-Recipient cmdlet, returning only objects classified as user mailboxes. RecipientTypeDetails is a filterable property that distinguishes between mailbox types such as UserMailbox, SharedMailbox, RoomMailbox, and EquipmentMailbox. This ensures that the command returns exactly the intended result set, excluding all other recipient types, and is more efficient than pulling all recipients and filtering locally.

Why this answer

The Get-Mailbox cmdlet returns all mailbox types by default. To filter only user mailboxes, you must use the -Filter parameter with the condition 'RecipientTypeDetails -eq 'UserMailbox''. This ensures that only mailboxes with RecipientTypeDetails set to UserMailbox are returned, excluding shared, room, and other mailbox types.

Exam trap

The trap here is that candidates often assume RecipientTypeDetails is a property that can be filtered by simply selecting it in Select-Object, but Select-Object only controls output columns, not which objects are retrieved; filtering must be done at the query level with -Filter.

How to eliminate wrong answers

Option A is wrong because the -Properties parameter is used to specify additional attributes to return in the output, not to filter results; it does not limit which mailboxes are retrieved. Option B is wrong because RecipientType is a broader classification that does not differentiate between user, shared, or room mailboxes; changing to RecipientType would not filter to only user mailboxes. Option D is wrong because the -ShowProgress parameter controls whether progress is displayed during command execution and has no effect on the filtering of mailbox types.

178
MCQhard

Your company is required to retain all emails sent to and from executives for 7 years due to regulatory compliance. You need to implement this with minimal administrative overhead. What should you use?

A.Create a Microsoft Purview retention policy for the executive mailboxes
B.Configure Exchange journaling to export to an external system
C.Place each executive mailbox on Litigation Hold
D.Enable the archive mailbox for each executive
AnswerA

A Microsoft Purview retention policy applies a seven-year retention period to the executives' mailboxes tenant-wide, with no per-item or per-user manual work. This meets the regulatory requirement with minimal administrative overhead compared with litigation holds or labels.

Why this answer

A Microsoft Purview retention policy applied to the executive mailboxes retains all emails for 7 years with minimal administrative overhead. It is a centralized, policy-based solution that does not require per-mailbox configuration or external systems. This meets the regulatory requirement efficiently.

Exam trap

MS-102 often tests the difference between retention policies, retention labels, and Litigation Hold; candidates may incorrectly choose Litigation Hold or journaling when the requirement is a simple retention policy with minimal overhead.

How to eliminate wrong answers

Option B is wrong because Exchange journaling requires an external system to store and manage the journaled emails, increasing administrative overhead and complexity. Option C is wrong because Litigation Hold is designed for legal holds, not for regulatory retention, and it must be applied per mailbox, increasing overhead. Option D is wrong because enabling an archive mailbox only provides additional storage; it does not enforce a 7-year retention period.

179
MCQhard

Refer to the exhibit. You are reviewing the service principal for Microsoft Graph in your tenant. The passwordCredentials array is empty. What does this indicate?

A.The service principal is using federated credentials.
B.The service principal uses certificate-based authentication.
C.The Microsoft Graph application is disabled.
D.No client secret is configured for the service principal.
AnswerD

A `passwordCredentials` array with no entries in the service principal means there are no password credential objects, and therefore no client secret is configured for that service principal. Client secrets are created and stored in this property as `passwordCredentials` objects, so an empty array is the expected representation when a secret has never been created, has expired, or has been deliberately removed. Without a client secret, app-only authentication would need another credential such as a certificate or managed identity, but the displayed data directly supports only the no-client-secret conclusion.

Why this answer

The passwordCredentials array being empty indicates that no client secret (password) has been configured for the service principal. Client secrets are one method of authentication for service principals, and their absence means that this particular authentication method is not set up. This does not imply the service principal is disabled or that other authentication methods like certificates or federated credentials are in use.

Exam trap

Microsoft often tests the misconception that an empty passwordCredentials array means the service principal is disabled or that no authentication is possible, when in fact other authentication methods like certificates or federated credentials may still be configured.

How to eliminate wrong answers

Option A is wrong because federated credentials are stored in the federatedIdentityCredentials array, not in passwordCredentials; an empty passwordCredentials array does not indicate federated credentials are being used. Option B is wrong because certificate-based authentication is indicated by the keyCredentials array, not passwordCredentials; an empty passwordCredentials array does not imply certificates are configured. Option C is wrong because the Microsoft Graph application being disabled is a separate property (accountEnabled) and is not indicated by the passwordCredentials array being empty.

180
MCQeasy

After adding a custom domain name to a Microsoft 365 tenant, what is the first step the administrator must complete before users can sign in using the custom domain?

A.Add the domain as an accepted domain in Exchange Online
B.Set the custom domain as the default domain for new users
C.Verify domain ownership by adding a DNS TXT record
D.Create user accounts with usernames ending with the custom domain
AnswerC

The first mandatory step after adding a custom domain is to prove you control it by publishing a DNS TXT record containing the unique token Microsoft provides in the domain setup wizard. Microsoft validates the TXT record at the domain's DNS provider, and until this succeeds, the domain shows 'Not verified' in the Microsoft 365 admin center. Only after this verification can you proceed with configuring the domain for email or user accounts.

Why this answer

Before a custom domain can be used for user sign-ins or email routing in Microsoft 365, the administrator must prove ownership of the domain. This is done by adding a specific DNS TXT record provided by the Microsoft 365 domain setup wizard. Until the TXT record is verified, the domain remains unverified and cannot be used for any Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking they can add the domain to Exchange Online or create users first, but Microsoft 365 strictly enforces domain verification as the prerequisite for all subsequent domain-related configurations.

How to eliminate wrong answers

Option A is wrong because adding the domain as an accepted domain in Exchange Online is a later step that requires the domain to already be verified; you cannot add an unverified domain as an accepted domain. Option B is wrong because setting the custom domain as the default domain for new users also requires the domain to be verified first; the system will not allow an unverified domain to be set as default. Option D is wrong because creating user accounts with usernames ending with the custom domain is only possible after the domain is verified; the Microsoft 365 authentication system will reject unverified domains during user creation.

181
MCQmedium

Your organization has a hybrid identity deployment with Microsoft Entra Connect. You have synchronized all on-premises Active Directory users to Microsoft Entra ID. You need to enable Microsoft Entra ID Password Protection to automatically block weak passwords. You have installed the Password Protection proxy on a server and registered it. You also need to enforce the password protection policy for on-premises users. What additional step is required?

A.Install the Password Protection DC agent on each domain controller.
B.Install the Password Protection proxy on all domain controllers.
C.Enable the password filter in the Microsoft Entra Connect configuration.
D.Configure a Group Policy to require password complexity.
AnswerA

The DC agent is the enforcement engine for Password Protection in a hybrid environment. It must be installed on every domain controller because it hosts the password filter DLL that intercepts and validates password changes against the banned password list. Without it, a password change processed by a DC lacking the agent would bypass the policy entirely, so placing it on each DC is the required configuration.

Why this answer

The Password Protection DC agent is required on each domain controller to intercept and validate password changes against the Microsoft Entra ID Password Protection policy. Without this agent, the proxy server alone cannot enforce the policy for on-premises users, as the DC agent is the component that applies the password filter during password change operations.

Exam trap

The trap here is that candidates often assume the proxy server alone enforces the policy, but the proxy only facilitates communication, while the DC agent is the enforcement point on each domain controller.

How to eliminate wrong answers

Option B is wrong because the Password Protection proxy is not installed on domain controllers; it is installed on a separate server to communicate with Microsoft Entra ID, while the DC agent is installed on domain controllers to enforce the policy. Option C is wrong because Microsoft Entra Connect does not include a password filter for on-premises password protection; the password filter is part of the DC agent, not the Connect configuration. Option D is wrong because configuring a Group Policy for password complexity does not enable Microsoft Entra ID Password Protection; it only enforces local Windows password policies, which are separate from the cloud-based weak password detection.

182
MCQmedium

Your organization uses Microsoft 365 and wants to ensure that only compliant devices can access Exchange Online. You have Microsoft Intune for device management. What should you configure?

A.Configure devices to be Azure AD Joined
B.Create a Conditional Access policy with 'Require device to be marked as compliant'
C.Create an app protection policy in Intune
D.Create a device compliance policy in Intune
AnswerB

A Conditional Access policy requiring device compliance integrates with Microsoft Intune’s compliance policies to block non-compliant devices from Exchange Online access. This satisfies the stem’s requirement that only compliant devices connect, because Intune evaluates device health (e.g., encryption, jailbreak status) and reports the result to Microsoft Entra ID, which enforces the access grant during authentication.

Why this answer

To enforce that only compliant devices can access Exchange Online, you need a Conditional Access policy that includes the 'Require device to be marked as compliant' grant control. This policy evaluates the device compliance status reported by Intune and blocks or grants access accordingly. Without this Conditional Access policy, even compliant devices are not forced to meet compliance requirements before accessing Exchange Online.

Exam trap

The trap here is that candidates often confuse creating a device compliance policy (which only defines rules) with the Conditional Access policy that actually enforces those rules, leading them to select Option D instead of B.

How to eliminate wrong answers

Option A is wrong because Azure AD Join alone does not enforce compliance; it only registers the device in Azure AD, and without a Conditional Access policy, any joined device can access Exchange Online regardless of compliance. Option C is wrong because an app protection policy (MAM) manages data protection at the app level without requiring device enrollment or compliance, and it does not block access from non-compliant devices. Option D is wrong because a device compliance policy defines the compliance rules (e.g., encryption, OS version) but does not enforce access control; it is the Conditional Access policy that uses the compliance status to grant or deny access.

183
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only compliant devices can access Microsoft 365 resources. What should you configure?

A.Configure an app protection policy in Intune.
B.Create a device compliance policy in Intune.
C.Configure a Windows Hello for Business policy in Intune.
D.Create a conditional access policy in Microsoft Entra ID requiring compliant devices.
AnswerD

To demand that managed Windows 10 devices be compliant before they access cloud resources, create a Conditional Access policy in Microsoft Entra ID. In the Grant section, select the 'Require device to be marked as compliant' control; this reads the last-known compliance status that Intune reports to Microsoft Entra ID and blocks sign-in if the device is not compliant or is unknown. This grant control works alongside your Intune compliance policies to enforce access decisions at sign-in time. This is the only option listed that actually enforces a device-compliancy requirement.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) are the mechanism that enforces access controls based on signals such as device compliance. By creating a policy that requires compliant devices, you ensure that only devices meeting your compliance standards can access Microsoft 365 resources. This works in conjunction with Intune compliance policies, but the enforcement point is the Conditional Access policy.

Exam trap

The trap here is that candidates often confuse the role of Intune compliance policies (which only define and report compliance) with Conditional Access policies (which enforce access decisions), leading them to select Option B instead of D.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection at the application level without requiring device enrollment or compliance; they do not block access to Microsoft 365 resources based on device compliance. Option B is wrong because a device compliance policy in Intune defines the compliance requirements (e.g., encryption, OS version) but does not itself enforce access restrictions; it only marks the device as compliant or non-compliant. Option C is wrong because Windows Hello for Business policy configures biometric or PIN-based authentication on devices, but it does not control access to Microsoft 365 resources based on device compliance.

184
MCQeasy

Refer to the exhibit. You have a Conditional Access policy configured as shown. What is the effect of this policy?

A.It requires multi-factor authentication for trusted IPs.
B.It blocks access from all locations.
C.It blocks access from untrusted IP addresses.
D.It blocks access from trusted IP addresses.
AnswerD

This is correct. The policy is scoped to the location condition 'All trusted IPs' and its access control is set to Block. When a user signs in from an IP address that falls within the configured trusted-IP range, the policy condition is satisfied and access is denied. This demonstrates that a 'trusted' network can still be blocked in Conditional Access when the grant control is Block rather than a permissive Grant control.

Why this answer

The policy is configured to 'Block access' for 'All users' and 'All cloud apps' when the location condition is set to 'Trusted IPs'. This means that when a user attempts to access from an IP address defined as trusted in the organization's named locations, access is explicitly blocked. The effect is that trusted IP addresses are blocked, not untrusted ones.

Exam trap

The trap here is that candidates mistakenly think 'Block access' combined with 'Trusted IPs' blocks untrusted IPs, when in fact the policy explicitly blocks the trusted IPs, leaving untrusted IPs unaffected by this policy.

How to eliminate wrong answers

Option A is wrong because the policy is set to 'Block access', not 'Grant access requiring multi-factor authentication', so it does not enforce MFA for any location. Option B is wrong because the policy only applies to the 'Trusted IPs' location condition, not to 'All locations' or 'Any location', so it does not block access from all locations. Option C is wrong because the policy targets 'Trusted IPs', not 'Untrusted IPs'; untrusted IPs are not affected by this policy and would fall through to other policies or default behavior.

185
MCQhard

A company has a Microsoft 365 E5 tenant with 10,000 users. You need to delegate the ability to manage Microsoft Entra ID roles to a group of support engineers. The solution must follow the principle of least privilege and allow engineers to assign only specific roles to users. What should you do?

A.Assign the engineers the Privileged Role Administrator role
B.Add the engineers to the Global Administrator role in Microsoft Entra ID
C.Create a group in Microsoft Entra ID and assign it the User Administrator role, then use PIM to elevate
D.Create a custom role in Microsoft Entra ID with permissions to assign specific roles, and use PIM to enable just-in-time access
AnswerD

Creating a custom role in Microsoft Entra ID with the specific permission to assign roles (e.g., microsoft.directory/roleAssignments/allProperties/assign) scoped to a limited set of roles, and using PIM for just-in-time access, is the correct approach. This gives engineers exactly the permission they need, only when they need it, with approval workflow, MFA, and audit logging. It balances operational efficiency with least-privilege security and is a recommended pattern for delegating role assignments in large enterprises.

Why this answer

It follows the principle of least privilege by creating a custom role that grants only the specific permissions needed to assign designated roles, and using Privileged Identity Management (PIM) for just-in-time (JIT) access ensures engineers are elevated only when required. This approach avoids granting standing administrative privileges and allows granular control over which roles can be assigned, meeting the requirement to delegate role management without over-provisioning.

Exam trap

The trap here is that candidates often confuse the Privileged Role Administrator role (which can assign any role) with a custom role that limits assignments to specific roles, or mistakenly think that adding engineers to a built-in role like User Administrator with PIM elevation is sufficient, when in fact PIM does not change the underlying permissions of the role itself.

How to eliminate wrong answers

Option A is wrong because the Privileged Role Administrator role grants full control over all role assignments in Microsoft Entra ID, including the ability to assign any role (including Global Administrator), which violates the principle of least privilege by providing excessive permissions. Option B is wrong because the Global Administrator role has unrestricted access to all tenant settings and resources, far exceeding the need to manage only specific role assignments, and is a classic over-privileged assignment. Option C is wrong because the User Administrator role only allows management of users and groups, not the assignment of Microsoft Entra ID roles to users; it does not include permissions to delegate role management, and using PIM with this role does not grant the ability to assign other roles.

186
MCQmedium

Refer to the exhibit. An administrator runs the KQL query in Microsoft Defender for Endpoint. The result set is empty. What is the most likely reason?

A.The device is not onboarded to Microsoft Defender for Endpoint.
B.The query is case-sensitive and the account name is 'Admin' with a capital A.
C.No logon events with the account name 'admin' exist in the past 7 days.
D.There are no logon events in the last 7 days.
AnswerC

This is correct because the KQL query filters logon events by AccountName == 'admin' and a time range of the last 7 days. When the query executes, it scans the events table and returns only rows where the account name matches exactly and the timestamp falls within the period. An empty result set directly indicates that no logon events with the account name 'admin' occurred in those 7 days. It does not imply that no logon events happened at all, only that none matched the specified account and time filter.

Why this answer

The KQL query filters for logon events where the AccountName equals 'admin' (lowercase). If no such events occurred in the last 7 days, the result set will be empty. This is the most likely reason because the query explicitly restricts the time range and account name, and an empty result does not indicate a broader issue with onboarding or case sensitivity.

Exam trap

The trap here is that candidates may assume an empty result set always indicates a configuration or onboarding problem, rather than recognizing that the query's specific filter (account name and time range) simply returned no matching data.

How to eliminate wrong answers

Option A is wrong because if the device were not onboarded to Microsoft Defender for Endpoint, the query would return an error or no data at all, but the question states the result set is empty, which is consistent with a valid query returning zero matching records. Option B is wrong because KQL is case-sensitive by default, but the query uses 'admin' (lowercase) and the exhibit shows the account name is 'admin' (lowercase), so case sensitivity is not the issue; the query would match 'admin' exactly. Option D is wrong because the query specifically filters for the account name 'admin', so even if there are other logon events in the last 7 days, they would not appear unless they match the account name; an empty result does not imply no logon events at all.

187
MCQeasy

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company wants to allow users to reset their own passwords without contacting the help desk. You need to enable self-service password reset (SSPR) for all users. What should you do?

A.Configure a conditional access policy that requires password change on next sign-in for all users.
B.In the Microsoft Entra admin center, enable password reset for all users and require users to register authentication methods.
C.Enable Azure AD Connect password writeback and configure password reset in the on-premises Active Directory.
D.Assign Microsoft 365 E5 licenses to all users to enable self-service password reset.
AnswerB

Enabling SSPR in the Microsoft Entra admin center allows users to reset their passwords if they have registered authentication methods. This is the primary step to enable self-service password reset. Requiring registration ensures users have the necessary methods. This configuration meets the requirement without additional licenses, as SSPR is included in Microsoft Entra ID Free and above.

Why this answer

To enable self-service password reset, you must configure it in the Microsoft Entra admin center and require users to register authentication methods. This allows users to reset their own passwords without help desk intervention. SSPR is included in all Microsoft Entra ID editions, so no additional licensing is needed.

Conditional access password change and on-premises writeback are not prerequisites for cloud-only SSPR.

Exam trap

The trap here is thinking that SSPR requires premium licensing or hybrid configuration; it is a baseline feature that only needs to be enabled and configured with authentication methods.

188
MCQeasy

An administrator needs to configure email notifications for Exchange Online service health incidents to be sent to a specific IT support mailbox. Where should the administrator configure these notifications in the Microsoft 365 admin center?

A.Health > Service health > Customize notifications
B.Organization profile > Notifications > Service health
C.Mail flow connectors
D.Settings > Service settings
AnswerA

Service health notifications for Exchange Online are configured from Health > Service health > Customize notifications. This opens a panel where you can select specific services (such as Exchange Online) and choose which email addresses should receive incident notifications, ensuring that only relevant admins are alerted. It also allows you to set filters for issue types like high-impact incidents or advisories.

Why this answer

The 'Customize notifications' link under Health > Service health in the Microsoft 365 admin center is the dedicated interface for configuring email notifications for service health incidents, including Exchange Online. This allows administrators to specify which email addresses (such as an IT support mailbox) receive alerts for service incidents, advisories, and other health events, with granular control over which services and severity levels trigger notifications.

Exam trap

The trap here is that candidates confuse the 'Notifications' section under Organization profile (which handles admin email notifications for password resets or license assignments) with the service health notification settings, leading them to select Option B instead of navigating to the correct Health > Service health path.

How to eliminate wrong answers

Option B is wrong because 'Organization profile > Notifications > Service health' is not a valid path in the Microsoft 365 admin center; the actual notification settings for service health are located under Health > Service health, not under Organization profile. Option C is wrong because 'Mail flow connectors' are used to configure email routing between Exchange Online and on-premises or third-party email systems, not for setting up service health notifications. Option D is wrong because 'Settings > Service settings' is a generic path that does not exist in the current Microsoft 365 admin center UI; service health notifications are managed under the Health section, not under Settings.

189
MCQeasy

A company purchases Microsoft 365 E5 licenses for 500 users. The administrator wants to automatically assign licenses to new users based on their group membership. Which method should the administrator use?

A.Run a PowerShell script to assign licenses individually
B.Configure group-based licensing in Microsoft Entra ID
C.Manually assign licenses in the Microsoft 365 admin center for each user
D.Use a volume licensing product key to activate licenses
AnswerB

Group-based licensing in Microsoft Entra ID assigns M365 E5 licenses automatically to all users in a group, including new members added later. When a user leaves the group, the license is automatically removed, and the system logs any assignment errors (e.g., insufficient quota or conflicting service plans) in the user's object. This is the recommended and native method for managing per-user subscriptions like M365 E5 because it runs in the background and requires no manual effort once the group is configured.

Why this answer

Group-based licensing in Microsoft Entra ID (formerly Azure AD) allows automatic assignment and removal of licenses based on group membership. When a user is added to a licensed group, the license is automatically assigned; when removed, the license is revoked. This eliminates manual effort and ensures consistent licensing for all 500 users.

Exam trap

The trap here is that candidates often confuse group-based licensing with manual or scripted methods, assuming that PowerShell or the admin center are the only ways to assign licenses, but Microsoft Entra ID's group-based licensing is the correct automated solution for this scenario.

How to eliminate wrong answers

Option A is wrong because running a PowerShell script to assign licenses individually is a manual, scripted approach that does not scale well for 500 users and lacks the automatic, membership-driven assignment required. Option C is wrong because manually assigning licenses in the Microsoft 365 admin center for each user is time-consuming and error-prone, not leveraging automation. Option D is wrong because volume licensing product keys are used for on-premises or subscription activation, not for assigning Microsoft 365 E5 licenses to users in a cloud tenant.

190
MCQeasy

Refer to the exhibit. You run this PowerShell command in your Microsoft 365 tenant. What is the purpose of the command?

A.To list all users with sign-in blocked
B.To list all unlicensed users with a specific usage location
C.To list all unlicensed users in the tenant
D.To list all users who have a license assigned
AnswerC

The Where-Object clause {$_.AssignedLicenses.Count -eq 0} correctly targets users whose AssignedLicenses collection has zero entries, meaning no license SKU has been assigned to the account. Because the cmdlet enumerates all user objects in the directory (with the -All switch or through Graph pagination), the result is the complete set of unlicensed users in the tenant. This is the intended purpose of the command.

Why this answer

The PowerShell command `Get-MgUser -Filter 'assignedLicenses/$count eq 0' -ConsistencyLevel eventual` retrieves all users in the Microsoft 365 tenant who have no licenses assigned. The `assignedLicenses/$count eq 0` filter checks that the count of assigned licenses is zero, and `-ConsistencyLevel eventual` is required for advanced queries on directory objects. This directly corresponds to listing all unlicensed users in the tenant.

Exam trap

The trap here is that candidates may confuse the `assignedLicenses/$count eq 0` filter with a filter for unlicensed users in a specific location or with sign-in status, but the command lacks any additional filters for usage location or account status.

How to eliminate wrong answers

Option A is wrong because the command does not filter by `accountEnabled` or `SignInActivity`, which are required to identify users with sign-in blocked. Option B is wrong because the command does not include any filter for `usageLocation`; it only checks for unlicensed users without specifying a location. Option D is wrong because the command explicitly filters for users where `assignedLicenses/$count eq 0`, meaning it returns users without licenses, not those with licenses assigned.

191
MCQhard

You are reviewing a Conditional Access policy in Microsoft Entra ID. The exhibit shows the policy configuration. You need to allow users to access Office 365 applications from personal devices that are not enrolled in Microsoft Intune. However, the policy currently blocks access because it requires a compliant device. Users are prompted for MFA but then blocked due to device compliance. What should you modify in the policy?

A.Add a session control for sign-in frequency.
B.Remove "compliantDevice" from the builtInControls grant control list.
C.Remove the cloudAppSecurity session control.
D.Change cloudAppSecurityType to "blockDownloads".
AnswerB

Removing compliantDevice from the grant controls leaves MFA as the only requirement, so personal unenrolled devices satisfy the policy. The block stems solely from the device compliance grant, not from the MFA prompt, so deleting that control restores access without altering assignment scope.

Why this answer

The policy currently uses the 'Require compliant device' grant control, which blocks access from devices not enrolled in Intune or not meeting compliance policies. Removing 'compliantDevice' from the builtInControls list allows access from personal, non-enrolled devices while still enforcing MFA. This directly resolves the scenario where users pass MFA but are blocked by device compliance.

Exam trap

The trap here is that candidates often confuse session controls (like app enforcement or sign-in frequency) with grant controls (like device compliance), leading them to incorrectly modify session settings instead of removing the device compliance requirement.

How to eliminate wrong answers

Option A is wrong because sign-in frequency controls how often users must re-authenticate, not device compliance or enrollment status, so it would not unblock non-compliant devices. Option C is wrong because removing the cloudAppSecurity session control affects session monitoring and control (e.g., for data exfiltration), not device compliance requirements, so it would not resolve the block. Option D is wrong because changing cloudAppSecurityType to 'blockDownloads' restricts file download actions in sessions, but does not alter the device compliance grant control that is causing the block.

192
MCQmedium

You are a Microsoft 365 administrator. A user reports that they cannot send emails to a specific external domain. You check the Exchange Admin Center and see that the domain is not blocked. What should you check next?

A.Verify that the user has a full mailbox and is not over the send limit.
B.Review the outbound spam filter policy.
C.Check the mail flow rules (transport rules) in Exchange Online.
D.Check the spam filter policy to see if the domain is on the blocked sender list.
AnswerC

Mail flow rules (transport rules) can contain conditions that match the recipient domain and actions such as reject, redirect, or silently drop the message. If a user can send to all domains except one, a transport rule targeting that domain is the most direct cause, especially after the blocked sender list is ruled out. Reviewing these rules in the Exchange admin center under Mail flow > Rules will reveal any applicable rule and its action.

Why this answer

Mail flow rules (transport rules) in Exchange Online can block or redirect messages based on conditions like sender, recipient domain, or message content, even if the domain is not listed in any block list. Since the domain is not blocked in the spam filter or outbound policies, a transport rule is the most likely cause of the issue, as it can silently reject or quarantine messages without appearing in the standard block lists.

Exam trap

The trap here is that candidates often assume domain blocking only occurs in the spam filter or outbound policies, overlooking that transport rules can enforce granular domain-based restrictions that are invisible in those sections.

How to eliminate wrong answers

Option A is wrong because send limits (e.g., 10,000 recipients per day) apply to all external domains equally, not to a specific domain, and the user would typically receive a non-delivery report (NDR) if over the limit. Option B is wrong because the outbound spam filter policy controls bulk email thresholds and sending limits for outbound spam, not the ability to send to a specific domain. Option D is wrong because the spam filter policy's blocked sender list applies to inbound messages (from external senders to your users), not outbound messages sent by your users to external domains.

193
MCQeasy

Your company uses Microsoft 365 Business Premium. You need to ensure that all company-owned Windows 10 devices are automatically enrolled in Microsoft Intune when users sign in with their work account. The devices are Azure AD joined. You have configured automatic enrollment in Intune. However, some devices are not enrolling. You need to troubleshoot the issue. What should you check first?

A.Ensure that devices are Azure AD joined and not domain joined.
B.Check the Windows 10 version; version 1607 or later is required.
C.Verify that each user has an appropriate Microsoft Intune license assigned.
D.Check that the MDM authority is set to Microsoft Intune in Microsoft Entra ID.
AnswerC

Intune licenses are assigned per user, and Microsoft 365 Business Premium includes Intune as part of the subscription. When a user without an Intune license attempts to enroll, the device will not appear in Intune even if automatic enrollment and MDM authority are correctly configured. Verifying each user has an appropriate license (or the Business Premium license) is the first and definitive check when auto-enrollment is failing.

Why this answer

Automatic enrollment in Microsoft Intune requires each user to have an appropriate Intune license (e.g., Microsoft 365 Business Premium includes Intune). Without a license, the device will not be able to enroll even if all other prerequisites are met. The license is checked during the enrollment process, and if missing, enrollment fails silently.

Exam trap

The trap here is that candidates often assume device-level prerequisites (like Azure AD join or OS version) are the most common cause, but Microsoft Intune enrollment is user-license-driven, and missing licenses are a frequent real-world issue that is easy to overlook.

How to eliminate wrong answers

Option A is wrong because the question states the devices are already Azure AD joined, so this is not a missing prerequisite; checking this again would not resolve the issue. Option B is wrong because Windows 10 version 1607 or later is a requirement, but the question does not indicate that devices are running an older version; this is a secondary check, not the first step. Option D is wrong because the MDM authority is automatically set to Microsoft Intune when you configure automatic enrollment in the Microsoft Entra admin center; if it were not set, no devices would enroll, but the question states that some devices are enrolling, so this is not the immediate issue.

194
MCQmedium

An organization uses a third-party SaaS application that supports SAML-based single sign-on. The application is not in the Azure AD gallery. What is the first step to configure SSO?

A.Create a new enterprise application from the 'Non-gallery application' option in Azure AD
B.Configure Azure AD Connect to sync on-premises users
C.Add the application in the Microsoft 365 admin center under 'Integrated apps'
D.Create a custom role in Azure AD for the application
AnswerA

In Azure AD, when a third-party SaaS application supports SAML 2.0 but is not pre-configured in the gallery, the correct first administrative action is to select "Create a new application" and choose "Non-gallery application" from the Azure AD Enterprise applications blade. This action provisions a dedicated service principal in your tenant that accepts SAML requests and provides the Azure AD identifier, reply URL, and certificate required to complete SAML SSO configuration on the SaaS vendor's side. This templates the identity provider relationship before you can assign users or test SSO.

Why this answer

The correct first step is to create a new enterprise application from the 'Non-gallery application' option in Azure AD. This allows you to configure SAML-based SSO for any third-party application that supports SAML 2.0, even if it is not listed in the Azure AD gallery. The non-gallery application template provides the necessary endpoints and metadata to establish trust between Azure AD and the SaaS application.

Exam trap

The trap here is that candidates often confuse the 'Integrated apps' section in the Microsoft 365 admin center with Azure AD enterprise applications, but the former is for managing add-ins and the latter is the correct location for SAML SSO configuration.

How to eliminate wrong answers

Option B is wrong because Azure AD Connect is used to synchronize on-premises Active Directory users to Azure AD, not to configure SSO for a third-party SaaS application. Option C is wrong because the Microsoft 365 admin center 'Integrated apps' section is for managing Microsoft 365 add-ins and integrations, not for configuring SAML-based SSO with external applications. Option D is wrong because custom roles in Azure AD are for managing administrative permissions, not for configuring application SSO.

195
MCQhard

Your organization has a Microsoft 365 E5 tenant. You want to ensure that all users are automatically signed in to Microsoft 365 apps using single sign-on (SSO) when they are on the corporate network. You have Azure AD joined the devices. What additional configuration is required?

A.Enable Azure AD Seamless Single Sign-On.
B.No additional configuration is required; Azure AD joined devices provide SSO automatically.
C.Configure Azure AD Application Proxy for each app.
D.Deploy a trusted certificate for the corporate network.
AnswerB

When a Windows device is Azure AD joined, it automatically receives a Primary Refresh Token (PRT) after the user signs in with their Azure AD credentials. This PRT is exchanged for access tokens to Microsoft 365 apps and other cloud resources without any additional sign-in prompts, providing seamless SSO across sessions. No extra configuration such as federation, password hash sync, or pass-through authentication is needed because the device and user are already registered with Azure AD.

Why this answer

Azure AD joined devices are already registered with Azure AD and use the Primary Refresh Token (PRT) to enable seamless SSO for Microsoft 365 apps without any additional configuration. When a user signs into a Windows 10/11 device that is Azure AD joined, the PRT is obtained during the initial authentication and is automatically used for browser and app sign-ins on the corporate network. Therefore, no extra steps like enabling Seamless SSO or deploying certificates are needed.

Exam trap

The trap here is that candidates often confuse Azure AD Seamless SSO (which is for non-Azure AD joined devices) with the built-in SSO capability of Azure AD joined devices, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because Azure AD Seamless Single Sign-On is a separate feature for non-Azure AD joined devices (e.g., domain-joined or non-joined devices) that relies on Kerberos delegation; it is unnecessary when devices are already Azure AD joined, as the PRT handles SSO natively. Option C is wrong because Azure AD Application Proxy is designed for publishing on-premises apps externally, not for enabling SSO on the corporate network for Microsoft 365 apps. Option D is wrong because deploying a trusted certificate is not required for SSO on Azure AD joined devices; the PRT-based SSO uses Azure AD's token infrastructure and does not depend on a locally trusted certificate for authentication.

196
MCQmedium

An administrator wants to prevent users from inviting guest users from the domain 'contoso.com' to the tenant. The administrator needs to block all invitations for that specific domain while allowing invitations from all other external domains. Which setting in Microsoft Entra ID should be configured?

A.Cross-tenant access settings
B.External collaboration settings
C.User settings
D.Domain federation
AnswerB

External collaboration settings in Microsoft Entra ID contain the 'Collaboration restrictions' section where you can choose to allow invitations only to specified domains or block invitations to specific domains. Adding contoso.com to the 'Block invitations to the specified domains' list prevents users from inviting guest users whose email addresses use that domain. This is the correct administrative control for domain-based B2B invite restriction.

Why this answer

External collaboration settings in Microsoft Entra ID (formerly Azure AD) allow administrators to configure domain-based restrictions for B2B collaboration invitations. By adding 'contoso.com' to the 'Deny list' under 'Cross-tenant access settings' or specifically within the 'External collaboration settings' blade, invitations to that domain are blocked while all other external domains remain allowed. This setting directly controls the guest invitation behavior at the domain level.

Exam trap

The trap here is that candidates often confuse 'Cross-tenant access settings' (which manage tenant-to-tenant trust and access) with 'External collaboration settings' (which control domain-level invitation restrictions), leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Cross-tenant access settings control inbound and outbound access for specific tenants, not domain-based invitation blocking for all external domains; they are used for granular trust and access policies between tenants. Option C is wrong because User settings in Entra ID manage user permissions like self-service group creation or sign-in restrictions, not domain-level guest invitation blocking. Option D is wrong because Domain federation configures trust relationships for authentication (e.g., SAML/WS-Fed) with external identity providers, not invitation restrictions for specific domains.

← PreviousPage 3 of 3 · 196 questions total

Ready to test yourself?

Try a timed practice session using only Deploy and manage a Microsoft 365 tenant questions.