Courseiva

CCNA Implement and manage Microsoft Entra identity and access Questions

75 of 129 questions · Page 1/2 · Implement and manage Microsoft Entra identity and access · Answers revealed

1
Multi-Selecthard

You are deploying Microsoft Entra ID Governance. Which THREE capabilities should you include to meet compliance requirements for access recertification and lifecycle management?

Select 3 answers
A.Identity Protection
B.Access Reviews
C.B2B Collaboration
D.Lifecycle Workflows
E.Entitlement Management
AnswersB, D, E

Access Reviews periodically recertify group membership, application access and privileged role assignments, producing reviewer decisions and audit records. This directly satisfies the compliance requirement for access recertification within Microsoft Entra ID Governance, complementing entitlement management and lifecycle workflows.

Why this answer

Access Reviews (B) is correct because it is the Entra ID Governance capability that drives access recertification, letting reviewers periodically attest to group memberships, application assignments, and privileged role assignments so stale or excessive access is removed. Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks—such as pre-hire provisioning, attribute-based updates, and post-termination access removal—which is exactly the lifecycle management requirement. Entitlement Management (E) is correct because access packages, catalogs, and assignment policies govern who can request and retain access, with expiration and approval controls that support recertification and lifecycle governance.

Identity Protection (A) is not included because it is a risk-detection and conditional access signal service, not a recertification or lifecycle tool, and B2B Collaboration (C) is not included because it only enables external guest access rather than providing the required governance capabilities.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access with governance recertification, or assume B2B Collaboration covers lifecycle management, when in fact only Access Reviews, Lifecycle Workflows, and Entitlement Management directly address compliance-driven access recertification and lifecycle automation.

2
MCQmedium

Your company is implementing a Zero Trust security model. You need to ensure that all user access requests to corporate resources are verified continuously, not just at the initial sign-in. Which Microsoft Entra ID feature should you use?

A.Continuous Access Evaluation (CAE)
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra Verified ID
AnswerA

Continuous Access Evaluation (CAE) is the feature that enforces zero trust continuous verification by allowing Entra ID and resource providers to respond in real time to critical events. When a user is disabled, a password is changed, or a conditional access policy is updated, CAE revokes access within seconds—even if the token itself is still technically valid. It does this through a shared token validation mechanism: resource providers like Exchange Online and SharePoint Online consult a revocation table and reject tokens for sessions that have been terminated, instead of waiting for token expiration. This gives administrators immediate, policy-driven access revocation that aligns exactly with the scenario described.

Why this answer

Continuous Access Evaluation (CAE) is the correct choice because it enforces real-time token validation and policy enforcement for every access request, not just at initial authentication. CAE works by having critical events (e.g., user disablement, IP address change, or risk elevation) trigger a revocation message to the resource provider, which then immediately blocks access—even if the token is still valid. This aligns directly with the Zero Trust principle of 'verify explicitly and continuously' rather than relying on a one-time sign-in.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access policies with continuous enforcement, but Identity Protection only triggers a block at sign-in or via a conditional access policy check, not mid-session for every subsequent request.

How to eliminate wrong answers

Option B (Microsoft Entra Identity Protection) is wrong because it focuses on detecting and responding to identity-based risks (e.g., leaked credentials, anomalous sign-ins) but does not provide continuous, real-time access enforcement for every resource request—it is a risk-detection and remediation tool, not a session-level enforcement mechanism. Option C (Microsoft Entra Privileged Identity Management) is wrong because it manages just-in-time privileged role activation and approval workflows, not continuous verification of all user access requests; it addresses privilege escalation, not ongoing access validation. Option D (Microsoft Entra Verified ID) is wrong because it is a decentralized identity solution for verifying credentials (e.g., employment or education claims) via verifiable credentials, not a mechanism for continuously evaluating access tokens or enforcing policy at runtime.

3
Multi-Selecthard

Which THREE are features of Microsoft Entra ID Governance? (Choose three.)

Select 3 answers
A.Password protection
B.Entitlement management
C.Conditional access policies
D.Access reviews
E.Privileged Identity Management (PIM)
AnswersB, D, E

Entitlement management is a core Microsoft Entra ID Governance feature that creates and manages access packages containing groups, apps, and SharePoint sites. It lets administrators define policies for requesting access, including approvals, separation-of-duties checks, and automatic expiration, so access is granted consistently and governed through the resource's lifecycle. By automating the full access-assignment lifecycle and supporting connected organizations for external collaboration, entitlement management directly achieves identity governance objectives.

Why this answer

Entitlement management is a core feature of Microsoft Entra ID Governance that enables organizations to manage the lifecycle of access for internal and external users through access packages, catalogs, and policies. It automates access requests, approvals, and assignments, ensuring users have the right access to resources like groups, apps, and SharePoint sites.

Exam trap

The trap here is that candidates confuse security features like password protection or conditional access with governance features, but Entra ID Governance specifically focuses on identity lifecycle, access requests, reviews, and privileged role management (PIM).

4
MCQmedium

Refer to the exhibit. You need to ensure that users accessing Exchange Online from unmanaged devices are blocked. What should you modify in the policy?

A.Remove the MFA control
B.Add the 'approvedClientApp' grant control with OR
C.Add a session control for app protection policies
D.Change the operator from OR to AND
AnswerD

Changing the operator from OR to AND makes both grant controls mandatory, so a user must both complete MFA and use a compliant device. Since an unmanaged device cannot be marked as compliant, it will be blocked, while managed devices still benefit from MFA, exactly fulfilling the stated access requirement.

Why this answer

The exhibit shows a conditional access policy with two grant controls: 'Require multi-factor authentication' and 'Require device to be marked as compliant', connected by OR. With OR, users can satisfy either control, so unmanaged devices can still authenticate via MFA alone. Changing the operator to AND forces both MFA and device compliance, blocking access from unmanaged devices that cannot be compliant.

Exam trap

The trap here is that candidates overlook the OR operator and assume both controls are already required, not realizing that OR creates an alternative path that allows unmanaged devices to authenticate with just MFA.

How to eliminate wrong answers

Option A is wrong because removing the MFA control would leave only the device compliance requirement, which still blocks unmanaged devices but weakens security by removing MFA for managed devices. Option B is wrong because adding 'approvedClientApp' with OR would introduce another alternative path, making it even easier for unmanaged devices to bypass the block. Option C is wrong because session controls for app protection policies apply after access is granted (to restrict data exfiltration), not to block initial access from unmanaged devices.

5
MCQeasy

You need to allow external users from a specific partner organization to access a SharePoint Online site using their own Microsoft Entra ID credentials. Which feature should you configure?

A.Direct Federation
B.Self-service password reset
C.Microsoft Entra B2C
D.Microsoft Entra B2B collaboration
AnswerD

Microsoft Entra B2B collaboration is the correct solution because it enables you to invite external users from a partner organization into your tenant as guest accounts, where they authenticate using their own corporate credentials from their home identity provider. B2B collaboration creates a lightweight guest user object in your directory, then federates authentication back to the partner's Entra tenant or other supported IdP, so you do not need to manage or store their passwords. It allows you to apply conditional access, MFA, and access reviews to those guest accounts, and you can grant granular permissions to specific apps or SharePoint sites, which directly meets the requirement of allowing external users from a specific partner org.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it allows you to invite external users from a partner organization to access your SharePoint Online site using their own Microsoft Entra ID (or other identity provider) credentials. B2B collaboration uses cross-tenant trust to authenticate the external user against their home tenant, enabling seamless access without creating local accounts.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C, mistakenly thinking B2C is for business partners, when in fact B2C is for consumer-facing identity management, not for granting access to enterprise resources like SharePoint Online.

How to eliminate wrong answers

Option A is wrong because Direct Federation (also known as direct federation with SAML/WS-Fed identity providers) is used for external identities that are not managed in Microsoft Entra ID, such as those from a generic SAML 2.0 IdP, and does not specifically enable partner users to use their own Microsoft Entra ID credentials. Option B is wrong because Self-service password reset (SSPR) is an internal feature that allows users in your own tenant to reset their passwords, not a mechanism for granting external users access to resources. Option C is wrong because Microsoft Entra B2C (Business-to-Consumer) is designed for customer-facing applications where users sign up with social or local accounts, not for granting partner organizations access to SharePoint Online using their corporate Microsoft Entra ID credentials.

6
MCQhard

You are troubleshooting an issue where users from a partner organization cannot access a shared app in your Microsoft Entra ID tenant. The partner uses Microsoft Entra ID with a custom domain. You have configured cross-tenant access settings. Which setting is most likely misconfigured?

A.Outbound cross-tenant access settings for the partner's tenant ID
B.The app's user assignment and provisioning configuration
C.Default inbound cross-tenant access settings for the partner's tenant ID
D.The partner's inbound cross-tenant access settings for your tenant
AnswerC

Default inbound cross-tenant access settings for the partner's tenant ID are the correct place to check because these settings determine whether external partner users are allowed to authenticate into your tenant and access your applications. Azure AD evaluates cross-tenant access policies individually for each external tenant, and the default inbound policy applies unless a tenant-specific override exists, so a block here would prevent partner users from signing in.

Why this answer

The default inbound cross-tenant access settings control how external users from other tenants access your tenant's resources. Since the partner cannot access the shared app, the most likely misconfiguration is that the default inbound settings for the partner's tenant ID are set to block access, or the partner's tenant ID is not explicitly allowed in the inbound settings. This overrides any app-level permissions, as cross-tenant access settings act as a gate before user assignment is evaluated.

Exam trap

The trap here is that candidates often focus on app-level configuration (user assignment or provisioning) or confuse inbound/outbound directions, overlooking that cross-tenant access settings act as a mandatory first gate that must explicitly allow the partner's tenant ID before any app access can occur.

How to eliminate wrong answers

Option A is wrong because outbound cross-tenant access settings control how your users access resources in the partner's tenant, not how partner users access your app. Option B is wrong because user assignment and provisioning configuration are app-level settings that only apply after cross-tenant access is allowed; if inbound access is blocked, the app settings are irrelevant. Option D is wrong because the partner's inbound cross-tenant access settings control access to their own resources, not to your tenant's app; you configure settings for your tenant, not the partner's.

7
Multi-Selecteasy

Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)

Select 2 answers
A.Windows Hello for Business
B.Microsoft Authenticator with notification
C.Password Hash Synchronization
D.FIDO2 security keys
E.SMS-based one-time passcode
AnswersA, D

Windows Hello for Business is a passwordless sign-in method built into Windows devices that uses biometrics or a PIN tied to the user's device through an asymmetric key pair. The private key is protected by the TPM and never leaves the device, while the public key is registered in Microsoft Entra ID. This satisfies passwordless authentication because no shared secret is transmitted over the network, and it supports both cloud and hybrid deployments.

Why this answer

Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.

Exam trap

The trap here is that Microsoft Authenticator with notification is often marketed as 'passwordless' in casual contexts, but Microsoft's official documentation strictly classifies it as a multi-factor authentication method, not a passwordless one, because it still requires a password as the first factor.

8
MCQeasy

Your company uses Microsoft Entra ID and wants to use Microsoft's recommendation to protect against password spray attacks. Which feature should you enable?

A.Smart Lockout
B.Identity Protection
C.Password Hash Synchronization
D.Multifactor Authentication
AnswerA

Smart Lockout in Microsoft Entra ID uses adaptive machine learning to detect and block password spray and brute-force attacks by locking an account after a defined number of failed sign-in attempts. It learns the user's normal sign-in patterns, such as frequently used IP addresses and devices, and adjusts lockout thresholds accordingly, so legitimate users are less likely to be locked out while attackers are effectively denied access. This is precisely the account lockout capability the company needs to prevent attackers from cycling through passwords.

Why this answer

Smart Lockout is Microsoft's recommended feature to protect against password spray attacks because it intelligently locks out bad actors after a threshold of failed attempts while allowing legitimate users to continue. It uses adaptive logic to distinguish between real users and attackers by considering the sign-in pattern and IP address, making it the correct choice for this specific threat.

Exam trap

The trap here is that candidates often confuse Identity Protection (which detects risky sign-ins) with the direct mitigation feature Smart Lockout, or they assume MFA alone is sufficient to stop password spray attacks, when in fact Smart Lockout is the specific Microsoft-recommended control for this attack vector.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it is a broader risk-detection and remediation service that identifies compromised identities and risky sign-ins, but it does not directly lock out attackers during a password spray attack; it relies on policies like Conditional Access to act on risks. Option C (Password Hash Synchronization) is wrong because it is a synchronization mechanism for password hashes from on-premises AD to Entra ID, not a security feature that mitigates password spray attacks. Option D (Multifactor Authentication) is wrong because while MFA adds a second layer of verification, it does not prevent the initial password spray attempts from being made, and Microsoft recommends Smart Lockout as the primary defense against this brute-force pattern.

9
MCQhard

Your company is deploying Microsoft Copilot for Microsoft 365. You need to ensure that only users who have completed a specific training course can use Copilot. What should you configure?

A.Use Terms of Use to require acceptance of training policy
B.Configure Authentication strengths to require training certificate
C.Create a Conditional Access policy that requires a custom attribute indicating training completion
D.Assign Copilot licenses only to users who completed training
AnswerC

This is correct because Microsoft Entra ID supports custom security attributes that can be assigned to user or resource objects, and Conditional Access policies can evaluate these attributes during sign-in. After training is completed, an administrator can set a custom attribute like 'CopilotTrainingCompleted=TRUE' via Graph API or automated workflow; the CA policy then grants access to the Copilot app only when that attribute is present. This provides a true runtime enforcement tied to the user's current directory state, rather than a static license or a one-time agreement.

Why this answer

A Conditional Access policy can evaluate a custom security attribute assigned to a user or group to enforce access controls. By requiring a custom attribute that indicates training completion, you can block or grant access to Copilot for Microsoft 365 based on that attribute. This approach integrates directly with Microsoft Entra ID's policy engine, allowing granular, attribute-based access control without relying on license assignment or user acceptance.

Exam trap

The trap here is that candidates often confuse license-based assignment (Option D) with attribute-based access control, assuming that simply not assigning a license is sufficient, but Microsoft Copilot for Microsoft 365 can still be accessed via trial or free features if not blocked by a Conditional Access policy; the exam tests your understanding that Conditional Access policies are the correct mechanism for enforcing granular, attribute-driven access restrictions.

How to eliminate wrong answers

Option A is wrong because Terms of Use (ToU) only require a user to accept a policy statement; they do not verify or enforce completion of a specific training course, nor can they evaluate dynamic attributes like training status. Option B is wrong because Authentication strengths control which authentication methods (e.g., FIDO2, certificate-based auth) are allowed during sign-in, not whether a user has completed training; a training certificate is not a standard authentication method and cannot be evaluated by Conditional Access as a condition. Option D is wrong because assigning Copilot licenses only to users who completed training is a manual, administrative approach that does not enforce ongoing compliance; a user could complete training, receive a license, and then later lose the training status without automatic revocation, and it does not integrate with Entra ID's policy engine for real-time enforcement.

10
MCQmedium

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You need to configure a conditional access policy that blocks access from devices that are not compliant with your organization's device compliance policies, as defined by Microsoft Intune. Which assignment should you configure in the policy?

A.Grant > Require hybrid Azure AD joined device
B.Grant > Require multifactor authentication
C.Grant > Require device to be marked as compliant
D.Grant > Require approved client app
AnswerC

Requiring the device to be marked as compliant evaluates the actual compliance status reported by Intune. This ensures the device meets organizational policies, such as OS version, disk encryption, and threat level. It is the precise control for enforcing device compliance in Conditional Access.

Why this answer

The 'Require device to be marked as compliant' grant control in a Conditional Access policy enforces access decisions based on the compliance status reported by Microsoft Intune. When a device is marked as non-compliant by Intune (e.g., missing required updates or having an unapproved app), the policy blocks access. This directly meets the requirement to block devices that do not meet the organization's device compliance policies.

Exam trap

The trap here is that candidates often confuse 'device compliance' with 'hybrid Azure AD join' or 'MFA', assuming any of those controls enforce device health, but only the 'Require device to be marked as compliant' grant directly uses Intune's compliance evaluation.

How to eliminate wrong answers

Option A is wrong because 'Require hybrid Azure AD joined device' controls access based on domain join status, not Intune compliance; a hybrid joined device could still be non-compliant with Intune policies. Option B is wrong because 'Require multifactor authentication' addresses identity verification, not device health or compliance; a non-compliant device can still satisfy MFA. Option D is wrong because 'Require approved client app' restricts access to specific applications (e.g., Outlook mobile) but does not evaluate the device's compliance with Intune policies.

11
MCQmedium

A company uses Microsoft Entra ID and has enabled self-service password reset (SSPR). Users are required to register for SSPR. Management wants to ensure that users from the HR department, who handle sensitive data, must use two methods for authentication during SSPR, while other users can use one method. What is the best way to achieve this?

A.Create a separate SSPR policy for the HR department using PowerShell
B.Use Microsoft Entra ID Governance to create an access package that requires two methods
C.Assign the HR users to a group and configure the SSPR policy for that group in the Entra admin center
D.This is not possible because SSPR authentication method requirements are tenant-wide
AnswerD

The requirement for two authentication methods to reset a password is a tenant-wide SSPR setting that cannot be overridden for a subset of users. In Microsoft Entra, the SSPR policy, including the number of methods required and the authentication methods available, is global. To enforce a different number of methods for HR, you would need a separate tenant or an alternative mechanism like Conditional Access MFA, which is not the same as SSPR's method count.

Why this answer

SSPR authentication method requirements in Microsoft Entra ID are configured at the tenant level, not per user or group. This means you cannot specify that one group of users must use two methods while others use one; the number of methods required applies uniformly to all users enabled for SSPR. Therefore, option D is correct because the requirement cannot be differentiated by department or group.

Exam trap

The trap here is that candidates assume group-based targeting for SSPR extends to authentication method requirements, when in reality group targeting only controls which users are enabled for SSPR, not the number of methods required, which is a tenant-wide setting.

How to eliminate wrong answers

Option A is wrong because PowerShell can be used to configure SSPR settings, but it cannot override the tenant-wide nature of authentication method requirements; any policy created would still apply to all users. Option B is wrong because Microsoft Entra ID Governance access packages manage resource access and entitlements, not SSPR authentication method requirements, which are a separate feature. Option C is wrong because while you can target SSPR to a group, the number of methods required is a tenant-wide setting and cannot be configured per group in the Entra admin center.

12
MCQhard

Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?

A.Deploy Azure AD Connect cloud sync
B.Enable password writeback
C.Configure Azure AD Connect to sync the 'userAccountControl' attribute
D.Configure Microsoft Entra Connect Sync to use filtered synchronization
AnswerA

Deploying Microsoft Entra Cloud Sync is correct because the cloud sync agent can be configured to synchronize identity changes—including the userAccountControl disabled flag—as frequently as every 1 minute, which satisfies the 5-minute latency requirement. Unlike Entra Connect Sync's 30-minute default cycle, Cloud Sync uses a lightweight agent that can run in parallel with Connect Sync (for non-overlapping scopes) or as a replacement, enabling near-real-time propagation of account disables for security and compliance.

Why this answer

Azure AD Connect cloud sync can be configured to synchronize the on-premises Active Directory 'userAccountControl' attribute, which includes the 'ACCOUNTDISABLE' flag. When an on-premises user account is disabled, this flag changes, and cloud sync can trigger a block on the corresponding cloud user's sign-in within a few minutes (typically under 5 minutes) due to its near-real-time sync cycle. This meets the requirement without relying on the slower default sync interval of Azure AD Connect.

Exam trap

The trap here is that candidates assume Azure AD Connect's 'userAccountControl' attribute sync (Option C) is sufficient, but they overlook the default 30-minute sync interval, which fails the 5-minute requirement, whereas cloud sync provides the needed speed.

How to eliminate wrong answers

Option B is wrong because password writeback enables users to reset their on-premises passwords from the cloud, but it does not control account disablement or sign-in blocking. Option C is wrong because while Azure AD Connect can sync the 'userAccountControl' attribute, the default sync interval is 30 minutes, which cannot guarantee the 5-minute requirement; cloud sync offers faster sync. Option D is wrong because filtered synchronization limits which objects are synced (e.g., by OU or domain), but it does not affect the sync speed or the ability to block sign-ins within 5 minutes.

13
MCQeasy

A company uses Microsoft Entra ID for identity management. The security team wants to ensure that users cannot register applications in the tenant to prevent potential data leakage. Which setting should be configured?

A.Set the 'Admin consent requests' setting to 'Allow'
B.Enable the 'Admin consent workflow'
C.Set 'Users can register applications' to 'No' in User settings
D.Set 'Users can consent to apps accessing company data' to 'No'
AnswerC

The 'Users can register applications' setting, found under Microsoft Entra ID > User settings, is the directory-wide toggle that controls whether non-admin users can create application registrations in the tenant. Setting it to 'No' revokes the default user permission to self-register apps, ensuring only users with applicable administrative roles (such as Application Administrator) can register applications. This directly satisfies the requirement to prevent user app registration.

Why this answer

Setting 'Users can register applications' to 'No' in the Microsoft Entra ID User settings explicitly prevents non-admin users from creating application registrations in the tenant. This directly addresses the security team's goal of blocking users from registering apps, which could otherwise expose tenant data through misconfigured or malicious applications.

Exam trap

The trap here is that candidates often confuse 'users registering applications' with 'users consenting to applications,' leading them to select Option D, which only controls consent, not the creation of the app registration itself.

How to eliminate wrong answers

Option A is wrong because 'Admin consent requests' setting controls whether users can request admin consent for applications, not whether users can register applications themselves. Option B is wrong because enabling the 'Admin consent workflow' allows users to request admin approval for app permissions, but does not block user-initiated app registration. Option D is wrong because setting 'Users can consent to apps accessing company data' to 'No' prevents users from granting permissions to apps, but does not prevent users from registering new applications in the tenant.

14
MCQeasy

You are planning a migration from on-premises Active Directory to Microsoft Entra ID using cloud sync. You need to synchronize user passwords so that users can authenticate using their existing passwords. Which feature should you enable?

A.Pass-through Authentication
B.Password Hash Synchronization
C.Federation with AD FS
D.Seamless Single Sign-On
AnswerB

Password Hash Synchronization (PHS) synchronizes a hash of the on-premises Active Directory password to Azure AD, enabling users to sign in to Microsoft 365 and Azure AD with the same password without any on-premises infrastructure at the moment of authentication. PHS also supports advanced security features like leaked credential detection and Identity Protection, making it the correct choice when the goal is to have password hashes available in the cloud.

Why this answer

Password Hash Synchronization (PHS) is the correct feature because it synchronizes the hash of a user's on-premises Active Directory password to Microsoft Entra ID, allowing users to authenticate with the same password without any additional on-premises infrastructure. Cloud sync specifically relies on PHS to replicate password hashes from AD to Entra ID, enabling seamless authentication for cloud-based services.

Exam trap

The trap here is that candidates often confuse Pass-Through Authentication with password synchronization, but PTA does not synchronize hashes—it only validates passwords in real time against on-premises AD, which is not the same as synchronizing passwords for cloud sync.

How to eliminate wrong answers

Option A is wrong because Pass-Through Authentication (PTA) validates passwords directly against on-premises AD without synchronizing password hashes, requiring agents and network connectivity, and does not meet the requirement of synchronizing passwords for cloud sync. Option C is wrong because Federation with AD FS relies on a federated trust and on-premises AD FS servers for authentication, not password synchronization, and adds complexity beyond cloud sync's scope. Option D is wrong because Seamless Single Sign-On (SSO) only provides automatic sign-in for domain-joined devices on corporate networks, but does not synchronize password hashes or enable password-based authentication from non-domain-joined devices.

15
Multi-Selectmedium

Which TWO of the following are valid conditions that can be used in a Microsoft Entra ID conditional access policy? (Choose two.)

Select 2 answers
A.Network location
B.Sign-in risk
C.Application sensitivity label
D.User risk
E.Device manufacturer
AnswersB, D

Sign-in risk is a valid condition in Azure AD Conditional Access. It evaluates the probability that the current authentication attempt is compromised, based on real-time risk detections from Identity Protection (such as impossible travel, anonymous IP, or leaked credentials). Administrators can configure policies to block access or require additional controls when the sign-in risk level is Low, Medium, or High.

Why this answer

Sign-in risk (B) and user risk (D) are both valid conditions in Microsoft Entra ID Conditional Access policies. These risk levels are calculated by Microsoft Entra ID Protection using real-time signals such as anonymous IP addresses, atypical travel, or leaked credentials, and can be used to trigger policies like requiring multi-factor authentication or blocking access.

Exam trap

The trap here is that candidates may confuse 'Network location' with the valid 'Locations' condition, or assume that application sensitivity labels (which are part of Microsoft Purview) can be used directly in Conditional Access policies, when in fact they are not a supported condition.

16
Multi-Selectmedium

You are configuring Microsoft Entra ID for your organization. You need to enable passwordless authentication for users. Which TWO authentication methods are passwordless and supported by Microsoft Entra ID?

Select 2 answers
A.SMS-based one-time passcode (OTP)
B.Hardware OATH tokens
C.Microsoft Authenticator app
D.OAuth 2.0 device authorization grant
E.FIDO2 security keys
AnswersC, E

Microsoft Authenticator supports true passwordless phone sign-in by using a cryptographic key pair stored in the device's secure enclave, where the user simply confirms a number shown on the sign-in screen or approves a notification to authenticate. This flow does not require entering a password or a one-time code, because the device proves possession and the user proves presence via the approval action, making it a valid passwordless Microsoft Entra ID authentication method.

Why this answer

The Microsoft Authenticator app supports passwordless authentication by allowing users to approve sign-in requests via a notification or a number match on their mobile device, eliminating the need for a password. FIDO2 security keys are also a passwordless method, using public-key cryptography to authenticate users without a password, and are fully supported by Microsoft Entra ID for both Azure AD joined and hybrid joined devices.

Exam trap

The trap here is that candidates often confuse multi-factor authentication methods (like SMS OTP or OATH tokens) with passwordless methods, but passwordless requires the primary authentication factor to be something you have or are, not something you know (a password), and both SMS OTP and OATH tokens still require a password as the first factor in most configurations.

17
MCQmedium

Your company has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the security administrator. You need to implement a solution that automatically detects and remediates identity risks. Requirements: - Risky sign-ins (e.g., from anonymous IP addresses) should be automatically blocked. - Users with confirmed compromised credentials should be forced to reset their password at next sign-in. - You need to receive alerts when high-risk events occur. - The solution must minimize false positives. Which Microsoft Entra ID features should you combine?

A.Set up Microsoft Entra Identity Governance access reviews and enable self-service password reset.
B.Configure Conditional Access policies to block sign-ins from anonymous IP addresses and require password reset for all users.
C.Enable Microsoft Entra Identity Protection, configure a sign-in risk policy to block high-risk sign-ins, and a user risk policy to require password reset for high-risk users. Set up alerts for risk events.
D.Deploy Microsoft Defender for Cloud Apps to detect risky sign-ins and configure session policies.
AnswerC

Microsoft Entra Identity Protection continuously evaluates sign-in and user risk using detections like leaked credentials, impossible travel, and unfamiliar properties. A sign-in risk policy can block high-risk sign-ins, and a user risk policy can require a secure password reset for high-risk users. Configuring alerts for risk events enables investigation. This provides the adaptive, real-time protection the company needs.

Why this answer

The correct combination is Microsoft Entra Identity Protection with a sign-in risk policy to block high-risk sign-ins and a user risk policy to require password reset for high-risk users, plus alerts for risk events. Identity Protection uses machine learning to detect risky sign-ins and compromised credentials, and the risk policies automatically remediate based on risk level. This minimizes false positives by using risk-based conditional access.

Exam trap

MS-102 often tests the difference between Identity Protection and other security features like Defender for Cloud Apps or Conditional Access alone, and candidates may incorrectly choose a solution that does not include risk-based policies.

How to eliminate wrong answers

Option A is wrong because Identity Governance access reviews and self-service password reset do not automatically detect and remediate identity risks; they are for access certification and password management, not risk detection. Option B is wrong because configuring Conditional Access to block sign-ins from anonymous IP addresses and require password reset for all users is too broad and does not use risk detection; it would cause many false positives and is not automated based on risk. Option D is wrong because Microsoft Defender for Cloud Apps is for cloud app security and session policies, not for identity risk detection and remediation; it does not provide the required user risk and sign-in risk policies.

18
MCQhard

Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to ensure that when a user's on-premises Active Directory account is disabled, their Microsoft Entra ID account is also disabled within 30 minutes. What should you do?

A.Enable Azure AD Connect cloud sync.
B.Configure password hash synchronization to run every 30 minutes.
C.Configure Azure AD Connect to sync the 'userAccountControl' attribute and set the sync frequency to 30 minutes.
D.Enable password writeback.
AnswerC

The userAccountControl attribute stores bit flags such as UF_ACCOUNTDISABLE, which directly determines whether the account is enabled. Synchronizing this attribute through Azure AD Connect propagates on-premises account status changes to Microsoft Entra ID. By explicitly setting the synchronization frequency to 30 minutes, you ensure that the next sync cycle will reflect the updated account state, making the current configuration the correct method to address the requirement.

Why this answer

Disabling an on-premises Active Directory account sets the 'userAccountControl' attribute (specifically the ACCOUNTDISABLE flag, bit 2). By configuring Azure AD Connect to sync this attribute and setting the sync frequency to 30 minutes, the disabled state is replicated to Microsoft Entra ID within that interval, ensuring the cloud account is also disabled.

Exam trap

The trap here is that candidates often confuse password hash synchronization (which handles password changes) with account status synchronization, mistakenly thinking that disabling an on-premises account automatically disables the cloud account without configuring attribute sync and schedule.

How to eliminate wrong answers

Option A is wrong because Azure AD Connect cloud sync is a separate synchronization service for syncing objects from multiple disconnected forests, not for controlling the sync frequency or attribute-level changes like userAccountControl. Option B is wrong because password hash synchronization only syncs password hashes for authentication, not user account status or the userAccountControl attribute; it does not disable accounts. Option D is wrong because password writeback enables password changes from the cloud to on-premises, not the synchronization of account disabled status.

19
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Manage device compliance policies
B.Automate user access reviews
C.Configure single sign-on for SaaS apps
D.Delegate administrative roles
E.Manage entitlement management
AnswersB, E

Automating user access reviews is a core feature of Microsoft Entra ID Governance, allowing organizations to schedule recurring attestation for access to groups, applications, and roles. Reviews can include automatic reminders and apply decisions like removing dormant access when a reviewer does not act. This transforms a manual audit process into an ongoing control, ensuring access remains appropriate and compliant over time.

Why this answer

Microsoft Entra ID Governance includes automated user access reviews, which allow organizations to periodically certify that users still need access to applications, groups, and roles. These reviews can be scheduled, recurring, and delegated to reviewers, with automated actions like removing access when a reviewer does not respond. This directly supports compliance and least-privilege principles.

Exam trap

The trap here is that candidates confuse general Entra ID features (like SSO and role delegation) with the specific governance capabilities of Entra ID Governance, which focuses on access lifecycle, reviews, and entitlement management.

20
MCQeasy

You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P1. The company wants to allow users to register for self-service password reset (SSPR) and require them to use two methods for authentication. You need to configure SSPR to require two methods. What should you do?

A.In the Microsoft Entra admin center, go to Users > Password reset > Properties, and enable 'Require two methods'.
B.Enable security defaults in Microsoft Entra ID.
C.Configure a Conditional Access policy that requires MFA for all users.
D.In the Microsoft Entra admin center, go to Password reset > Authentication methods, and set 'Number of methods required to reset' to 2.
AnswerD

The SSPR settings include an option for 'Number of methods required to reset'. Setting it to 2 requires users to register and use two authentication methods to reset their password. This directly meets the requirement. This setting is available in the Microsoft Entra admin center under Password reset > Authentication methods.

Why this answer

Self-service password reset settings in Microsoft Entra ID allow you to specify the number of authentication methods required to reset a password. By navigating to Password reset > Authentication methods and setting 'Number of methods required to reset' to 2, users must register and use two methods. This fulfills the requirement directly without affecting sign-in MFA.

Exam trap

The trap here is confusing Conditional Access MFA with SSPR authentication methods, which are configured separately.

21
MCQhard

You are a Microsoft 365 administrator. Your organization uses Microsoft Entra ID and Microsoft Intune for device management. You need to ensure that only compliant devices can access corporate email via Microsoft Outlook on mobile devices. What should you configure?

A.Create a Conditional Access policy with 'Require device to be marked as compliant'
B.Deploy app protection policies (MAM) for Outlook
C.Enable Microsoft Entra device registration
D.Create a device compliance policy in Intune
AnswerA

A Conditional Access policy with 'Require device to be marked as compliant' is the correct enforcement mechanism because Conditional Access acts as the real-time policy engine in Microsoft Entra ID (Azure AD) that evaluates the device's compliance state at the moment of sign-in. It checks the compliance status that Intune has reported for the device and blocks or allows access based on that report, applying to all selected cloud apps. Without this Conditional Access grant control, a device could be non-compliant yet still access resources, because the compliance check is not enforced elsewhere. This policy is what translates 'device must be compliant' from a status label into an access decision.

Why this answer

Conditional Access policies in Microsoft Entra ID can enforce 'Require device to be marked as compliant' as a grant control. This ensures that only devices meeting your Intune compliance policies (e.g., encryption, OS version, threat level) are allowed to access corporate email via Outlook on mobile devices. The policy evaluates device compliance status reported by Intune and blocks access if the device is non-compliant.

Exam trap

The trap here is that candidates often confuse device compliance policies (which define rules) with Conditional Access policies (which enforce access decisions), or they assume MAM policies alone can block non-compliant devices, but MAM does not evaluate device compliance status.

How to eliminate wrong answers

Option B is wrong because app protection policies (MAM) manage data protection at the app level (e.g., prevent copy-paste, require PIN) but do not enforce device-level compliance; they can be applied to unmanaged devices but do not check Intune compliance status. Option C is wrong because enabling Microsoft Entra device registration is a prerequisite for device-based Conditional Access but alone does not enforce compliance; it merely creates a device identity in Entra ID. Option D is wrong because a device compliance policy in Intune defines the compliance rules (e.g., require BitLocker, minimum OS) but does not enforce access control; it must be paired with a Conditional Access policy to block non-compliant devices.

22
MCQmedium

Your organization plans to use Microsoft Entra ID as the identity provider for a third-party SaaS application that supports SAML 2.0. You need to configure single sign-on (SSO) for the application. What should you create in Microsoft Entra ID?

A.An enterprise application with SAML-based sign-on
B.An Application Proxy connector group
C.A service principal for Microsoft Graph
D.An app registration with OpenID Connect
AnswerA

In Microsoft Entra ID, an enterprise application is a service principal created from a gallery or non-gallery app template, which supports SAML 2.0 federation for SSO. For an on-premises app like the IDE, you register an enterprise application, configure SAML-based sign-on, and assign users/groups. The SAML assertions are exchanged to authenticate users, and this is the designated method for federating an on-premises application with Microsoft Entra ID.

Why this answer

To configure SSO for a third-party SaaS application that supports SAML 2.0, you must create an enterprise application in Microsoft Entra ID and configure it with SAML-based sign-on. Enterprise applications are designed for integrating third-party applications, and SAML-based sign-on allows Entra ID to act as the identity provider, exchanging SAML assertions for authentication.

Exam trap

The trap here is that candidates often confuse app registrations (used for OIDC/OAuth apps) with enterprise applications (used for SAML-based SSO), leading them to choose Option D, even though SAML 2.0 requires the enterprise application gallery or custom enterprise app configuration.

How to eliminate wrong answers

Option B is wrong because an Application Proxy connector group is used for publishing on-premises applications to external users via reverse proxy, not for configuring SSO with a cloud-based SaaS application that supports SAML. Option C is wrong because a service principal for Microsoft Graph is used to grant permissions for programmatic access to Microsoft Graph APIs, not for configuring SAML-based SSO with a third-party SaaS app. Option D is wrong because an app registration with OpenID Connect is used for applications that use OIDC (an OAuth 2.0 extension) for authentication, not for SAML 2.0, which requires a different protocol and configuration in enterprise applications.

23
Multi-Selecteasy

Which TWO of the following are benefits of using Microsoft Entra ID Provisioning for cloud HR applications like Workday? (Choose two.)

Select 2 answers
A.Automatic license assignment
B.Support for attribute-based provisioning
C.Automatic password reset for new users
D.Automated user lifecycle management based on HR events
E.Automatic creation of user mailboxes in Exchange Online
AnswersB, D

Support for attribute-based provisioning is a core benefit because Entra ID provisioning lets you map HR source attributes to target Entra ID user attributes using attribute-mapping rules and expression functions. You can also define scoping filters that include or exclude users based on attribute values, and transform values before they are written to the cloud user object. This makes HR data such as title, department, and cost center authoritative within Microsoft Entra ID.

Why this answer

Microsoft Entra ID Provisioning for cloud HR applications like Workday supports attribute-based provisioning, which allows mapping of HR attributes (e.g., department, location) to Entra ID user attributes using an expression-based mapping engine. This enables dynamic filtering and transformation of user data during synchronization, ensuring that only users meeting specific criteria (e.g., employment status) are provisioned.

Exam trap

The trap here is that candidates often confuse the capabilities of Entra ID Provisioning with those of Microsoft Identity Manager (MIM) or Exchange Online hybrid management, assuming provisioning handles tasks like license assignment or mailbox creation, which are separate downstream processes.

24
MCQmedium

You are the Microsoft 365 administrator for Fabrikam, which has a Microsoft 365 E5 tenant and Microsoft Entra ID P2. The security team wants to require multifactor authentication for all users when they access any cloud app from outside the corporate network, but they do not want to affect users working in the office. You create a Conditional Access policy named CA01. You need to configure the policy to meet the requirements. What should you do?

A.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location and exclude the corporate network location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
B.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
C.Set the Assignments to All users, All cloud apps, and under Conditions configure Client apps to Exchange ActiveSync clients and other clients, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
D.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to Report-only.
AnswerA

Excluding the corporate network location from the Locations condition ensures the policy applies only to sign-ins from outside the trusted network. Setting Grant to Require multifactor authentication enforces MFA for those sign-ins, and enabling the policy makes it active. This precisely matches the requirement to prompt external users while leaving office users unaffected.

Why this answer

The requirement is to enforce MFA only for sign-ins originating outside the corporate network. A Conditional Access policy must include All users and All cloud apps as the assignment scope, then use the Locations condition to exclude the trusted corporate network. With the Grant control set to Require multifactor authentication and the policy enabled, external sign-ins are challenged while internal sign-ins remain unaffected.

Exam trap

The trap here is assuming that selecting Any location automatically limits the policy to external networks, when in fact Any location includes trusted locations unless you explicitly exclude them.

25
MCQmedium

An organization is implementing Microsoft Entra Verified ID for verifiable credentials. They want to issue credentials to employees that can be used to prove employment status to third parties. Which component must be created first?

A.A presentation request policy
B.A distributed ledger network
C.A credential manifest in the Microsoft Entra admin center
D.A decentralized identifier (DID) for the organization
AnswerC

A credential manifest is the core configuration artifact for issuing a verifiable credential in Microsoft Entra Verified ID. Defined in the Microsoft Entra admin center, it combines rules and display information: the rules definition specifies required claims, such as user attributes and optional validation logic, while the display definition controls the JSON schema and the visual layout of the credential. This manifest is what transforms a user's claim data into a signed verifiable credential, making it essential for any issuance scenario. Without it, the right issuance API calls would lack the necessary structure and would fail.

Why this answer

The credential manifest defines the rules for issuing a verifiable credential, including the claims schema, display information, and issuance policies. In Microsoft Entra Verified ID, you must create the credential manifest in the Entra admin center before any credentials can be issued, as it serves as the template that governs the credential's structure and validation. Without a manifest, there is no definition for what the credential contains or how it should be presented.

Exam trap

The trap here is that candidates often confuse the order of setup steps, assuming the DID must be manually created first, when in fact the DID is automatically generated during the Verified ID service initialization, and the credential manifest is the first component that requires explicit user configuration in the admin center.

How to eliminate wrong answers

Option A is wrong because a presentation request policy is used by verifiers to request proof of a credential from a holder, not to define the credential itself; it is created after the credential manifest. Option B is wrong because Microsoft Entra Verified ID uses a distributed ledger (ION) to anchor DIDs, but the organization does not create or manage a ledger network—it is an existing infrastructure that Microsoft manages. Option D is wrong because the decentralized identifier (DID) for the organization is automatically created when you set up the Verified ID service in the Entra admin center, and it is a prerequisite step that occurs before creating the credential manifest, but the question asks which component must be created first, and the DID is created as part of the initial setup, not as a separate manual creation step; the credential manifest is the first user-defined component after the DID is established.

26
MCQhard

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Microsoft Entra Connect Sync to synchronize user accounts. The security team requires that all cloud-only users must be blocked from syncing to on-premises AD. What should you do to meet this requirement?

A.Configure attribute mapping to filter out cloud-only users from writeback
B.Use the cloudFilter attribute to mark cloud-only users as false
C.Disable directory writeback in Microsoft Entra Connect Sync
D.Configure Selective Password Hash Sync to exclude cloud-only users
AnswerA

Configuring an outbound attribute mapping in Microsoft Entra Connect Sync allows you to set a scoping filter (e.g., `sourceAnchor` present or `cloudAnchored` true) on the writeback rule. Cloud-only users, created directly in Entra ID, have no corresponding on-premises Active Directory object, so the filter prevents the sync engine from attempting to write attributes like `msDS-cloudExtensionAttribute` to a nonexistent object. This selectively permits writeback for synced users while excluding cloud-only identities, thus addressing the selective requirement without disabling writeback globally.

Why this answer

Configuring attribute mapping to filter out cloud-only users from writeback directly prevents those users from being written back to on-premises Active Directory. In Microsoft Entra Connect Sync, attribute mapping rules can include scoping filters that exclude objects based on specific attributes, such as a custom attribute or the cloud-only user indicator. This ensures that only synchronized users are written back, meeting the security requirement without affecting other sync operations.

Exam trap

The trap here is that candidates often confuse the cloudFilter attribute (which controls sync direction from on-premises to cloud) with a mechanism to block cloud-only users from writeback, leading them to incorrectly select option B.

How to eliminate wrong answers

Option B is wrong because the cloudFilter attribute is used in Microsoft Entra Connect Sync to control which objects are synchronized from on-premises to the cloud, not to block cloud-only users from writeback; it cannot be applied to cloud-only objects that do not exist in on-premises AD. Option C is wrong because disabling directory writeback entirely would block all writeback operations, including for synchronized users who need to be written back (e.g., for password writeback or device writeback), which is too broad and does not specifically target cloud-only users. Option D is wrong because Selective Password Hash Sync controls which users have their password hashes synchronized from on-premises to the cloud, not writeback from cloud to on-premises; it is irrelevant to blocking cloud-only users from syncing to on-premises AD.

27
MCQmedium

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the Global Administrator. The security team reports that several users have been compromised due to weak passwords. You need to implement a solution that enforces strong password policies and blocks common passwords. The solution must also provide users with the ability to reset their own passwords securely if they forget them, without requiring help desk intervention. Additionally, you need to configure risk-based Conditional Access policies to block sign-ins from anonymous IP addresses and require MFA for high-risk sign-ins. You have the following options: A. Configure password protection in Microsoft Entra ID to enforce a custom banned password list and enable self-service password reset (SSPR) with MFA. Then create Conditional Access policies for sign-in risk and anonymous IP. B. Enable password hash sync and configure pass-through authentication. Create a Conditional Access policy to require MFA for all users. C. Implement Microsoft Entra ID Protection and enable MFA registration policy. Configure password expiration to 90 days. D. Use security defaults in Microsoft Entra ID and enable automatic password rollback. Which option should you choose?

A.Configure password protection with custom banned list, SSPR with MFA, and risk-based Conditional Access policies
B.Enable password hash sync, pass-through authentication, and require MFA for all
C.Implement Identity Protection, enable MFA registration policy, set password expiration to 90 days
D.Use security defaults and enable automatic password rollback
AnswerA

This approach combines Azure AD Password Protection custom banned list to block predictable passwords, SSPR with MFA to enable secure self-service recovery, and risk-based Conditional Access policies that require step-up authentication only when sign-in or user risk is elevated. It directly satisfies the requirement for password strength controls, offers a recovery path without helpdesk involvement, and adaptively enforces access based on real-time threat signals.

Why this answer

Option A directly addresses every stated requirement: Microsoft Entra Password Protection with a custom banned password list enforces strong passwords and blocks common ones, SSPR with MFA lets users reset passwords without help desk involvement, and risk-based Conditional Access policies (sign-in risk and anonymous IP) block risky sign-ins and require MFA for high-risk events. This combination uses the Entra ID P2 features already licensed in the E5 tenant.

Exam trap

MS-102 often tests whether candidates conflate authentication methods (password hash sync, pass-through) with password policy enforcement — the trap is selecting an option that addresses identity synchronization instead of password strength and risk-based access control.

How to eliminate wrong answers

Option B is wrong because password hash sync and pass-through authentication are authentication methods for hybrid identity, not password strength enforcement mechanisms — they do nothing to block weak or common passwords, and requiring MFA for all users is broader than the risk-based requirement. Option C is wrong because Identity Protection's MFA registration policy only ensures users register for MFA; it does not enforce password complexity or block common passwords, and setting password expiration to 90 days is a legacy practice that does not improve password strength. Option D is wrong because security defaults are a baseline set of policies for tenants without Conditional Access licensing and cannot be combined with custom risk-based policies; 'automatic password rollback' is not a real Entra ID feature.

28
MCQeasy

You are configuring Microsoft Entra ID to allow external users from a partner organization to access a specific SharePoint Online site. You need to ensure that the external users authenticate using their own corporate credentials and are automatically invited when they first access the resource. What should you configure?

A.Microsoft Entra External ID (B2C)
B.Microsoft Entra B2B direct connect
C.Microsoft Entra entitlement management access packages
D.Microsoft Entra B2B collaboration with manual invitation
AnswerC

Microsoft Entra entitlement management access packages are the correct solution because they enable admins to create cataloged resource collections—such as groups, applications, and SharePoint sites—and define policies that automatically invite external users, including B2B collaboration invitations when access is approved. These policies enforce access requirements, approval workflows, time-limited assignments, and recurring access reviews, providing full lifecycle governance for external users. This automation and centralized management distinguish it from manual invitation methods.

Why this answer

Microsoft Entra entitlement management access packages allow you to create a policy that automatically sends an invitation to external users when they request access to a resource, such as a SharePoint Online site. This policy can be configured to require that external users authenticate using their own corporate credentials (via their home tenant) and be automatically added to the resource upon first access, without manual invitation. Entitlement management integrates with B2B collaboration under the hood, but adds the automation and approval workflows needed for this scenario.

Exam trap

The trap here is that candidates confuse Microsoft Entra B2B collaboration (which requires manual invitation) with entitlement management access packages (which automate the invitation and access lifecycle), or they incorrectly assume B2B direct connect can be used for SharePoint Online site access when it is actually limited to Teams Connect shared channels.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra External ID (B2C) is designed for consumer-facing identity management (social or local accounts), not for enabling partner organizations to use their own corporate credentials for resource access. Option B is wrong because Microsoft Entra B2B direct connect is used for establishing mutual trust between two tenants for real-time collaboration (e.g., Teams Connect shared channels), but it does not support automatic invitation or access package-based provisioning for SharePoint Online sites. Option D is wrong because Microsoft Entra B2B collaboration with manual invitation requires an admin to manually send an invitation email or CSV upload, which does not meet the requirement for automatic invitation when users first access the resource.

29
MCQhard

You are a Microsoft 365 administrator for Contoso Pharmaceuticals, which uses Microsoft Entra ID P2. The company has a partnership with a research firm that needs access to a specific set of SharePoint Online sites and a custom line-of-business application. The partners must authenticate by using their own Microsoft Entra ID credentials. You need to provide access while ensuring that the partners' access is reviewed every quarter and that they can request access through a self-service portal. What should you do?

A.Configure Microsoft Entra B2B collaboration and create an entitlement management access package that includes the SharePoint sites and the application, with a quarterly access review and an external catalog for partner self-service requests.
B.Configure cross-tenant synchronization to synchronize partner users into the tenant and assign them to the resources.
C.Configure a Conditional Access policy that requires MFA for guest users and grants access to the SharePoint sites and application.
D.Configure Microsoft Entra B2B collaboration and create a guest user for each partner, then assign them directly to the SharePoint sites and application.
AnswerA

Entitlement management access packages allow you to bundle resources and configure access reviews on a schedule. By creating an access package with the required resources and a quarterly review, and exposing it through an external catalog, partners can request access via a self-service portal. B2B collaboration lets them use their own credentials, meeting all requirements.

Why this answer

The requirements are for partners to use their own credentials, to access specific resources, to have quarterly access reviews, and to request access via self-service. Entitlement management access packages with B2B collaboration meet all these needs: access packages bundle resources, support external catalogs for self-service, and allow scheduled access reviews. This is the correct solution.

Exam trap

The trap here is assuming that B2B collaboration alone provides governance features like access reviews and self-service portals, when those require entitlement management access packages.

30
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You want to set up a policy that automatically suspends a user if they download more than 100 files from SharePoint Online within 10 minutes. Which type of policy should you create?

A.Session policy
B.Activity policy
C.File policy
D.App discovery policy
AnswerB

Activity policies monitor user, admin, and sign-in activities for anomalous patterns, such as impossible travel, mass download, or failed sign-ins. When a threshold or heuristic is breached, the policy can automatically trigger a governance action, including suspending the affected user account. This makes the Activity policy the correct option for post-detection user suspension, as it reacts to logged activity rather than controlling the live session.

Why this answer

An Activity policy in Microsoft Defender for Cloud Apps monitors user activities across connected apps and can trigger automated actions, such as suspending a user, when a specific threshold of downloads from SharePoint Online is exceeded within a defined time window. This policy type is designed to detect anomalous behavior patterns like mass file downloads, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse Activity policies with Session policies, mistakenly thinking session-level controls can enforce download limits, but session policies only act on real-time actions within a single session and cannot trigger user suspension based on aggregated activity history.

How to eliminate wrong answers

Option A is wrong because a Session policy controls real-time user actions during a session (e.g., blocking uploads or requiring authentication) but does not evaluate historical activity counts or trigger user suspension based on past downloads. Option C is wrong because a File policy focuses on scanning files for content, metadata, or sharing permissions, not on monitoring the volume of download activities by a user. Option D is wrong because an App discovery policy analyzes cloud app usage and shadow IT, not user-specific download thresholds within a single app like SharePoint Online.

31
MCQhard

You manage a Microsoft 365 E5 tenant with Microsoft Entra ID P2. The security team wants to ensure that when a user is assigned the Global Administrator role, the assignment is time-bound, requires approval, and requires multifactor authentication for activation. You need to configure Privileged Identity Management (PIM). Which setting should you configure?

A.In PIM, for the Global Administrator role, configure the role settings to require justification and enable alerts for role activation.
B.In Microsoft Entra ID, create a Conditional Access policy that requires MFA for users assigned the Global Administrator role.
C.In PIM, for the Global Administrator role, set the assignment type to Eligible, configure activation settings to require approval and Azure MFA, and set the maximum activation duration.
D.In PIM, for the Global Administrator role, set the assignment type to Active and configure the assignment to expire after 30 days.
AnswerC

Making the Global Administrator role eligible allows users to activate it on demand. Configuring activation settings to require approval and Azure MFA ensures the activation is controlled and secure. Setting the maximum activation duration makes the assignment time-bound. This combination meets all stated requirements for time-bound, approval-based, and MFA-protected activation.

Why this answer

Privileged Identity Management (PIM) enables just-in-time role activation. To meet the requirements, the Global Administrator role must be assigned as eligible, and the role settings must require approval and Azure MFA for activation, with a maximum activation duration. This ensures time-bound, approved, and MFA-protected access, which is the core purpose of PIM.

Exam trap

The trap here is confusing active assignments with eligible assignments; only eligible assignments require activation, which can then enforce approval and MFA.

32
MCQmedium

Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires MFA for all external users. However, guest users from a partner organization are being blocked when they try to access a SharePoint Online site. You need to ensure that guest users can access the site without being prompted for MFA if they have already satisfied MFA in their home tenant. What should you configure?

A.Disable MFA requirement for guest users in Conditional Access
B.Configure authentication methods policy to accept MFA from external identities
C.Enable the trust MFA for external users setting in cross-tenant access settings
D.Use B2B direct connect instead of B2B collaboration
AnswerC

Enabling the 'Trust MFA for external users' setting in cross-tenant access settings instructs the resource tenant to accept the multifactor authentication claim that a guest user already satisfied in their home Microsoft Entra tenant. This allows the guest to access applications protected by an MFA Conditional Access policy without being prompted again, streamlining the sign-in experience while maintaining a verified MFA state. The setting applies to inbound B2B collaboration access and can be scoped to all external users or specific tenants, precisely matching the scenario of avoiding redundant MFA challenges.

Why this answer

The cross-tenant access settings in Microsoft Entra ID include a 'Trust MFA from external tenants' option. When enabled, this setting allows guest users who have already satisfied MFA in their home tenant to access resources in your tenant without being prompted for MFA again. This respects the partner's MFA claims and avoids redundant authentication, which directly resolves the blocking issue caused by the Conditional Access policy requiring MFA for all external users.

Exam trap

The trap here is that candidates often confuse the 'authentication methods policy' (which governs allowed MFA methods in your tenant) with the cross-tenant trust setting, leading them to choose Option B, when in fact the correct solution is to enable the trust setting in cross-tenant access settings.

How to eliminate wrong answers

Option A is wrong because disabling MFA for guest users in Conditional Access would remove the security requirement entirely, which violates the organization's policy and exposes resources to unauthenticated access. Option B is wrong because the authentication methods policy controls which methods are allowed for MFA in your tenant, not whether MFA claims from external identities are trusted; it does not accept or reject MFA from other tenants. Option D is wrong because B2B direct connect is designed for real-time, unmanaged collaboration (e.g., Teams shared channels) and does not support SharePoint Online site access via invitations; B2B collaboration is the correct model for granting guest users access to SharePoint sites.

33
Multi-Selecthard

Which THREE of the following are valid permissions in Microsoft Entra ID custom roles? (Choose three.)

Select 4 answers
A.microsoft.directory/applications/delete
B.microsoft.directory/applications/credentials/update
C.microsoft.directory/users/update
D.microsoft.directory/roles/assign
E.microsoft.directory/groups/members/update
AnswersA, B, C, E

It is a valid permission for deleting applications.

Why this answer

Option A, microsoft.directory/applications/delete, is a valid permission for deleting applications. Option B, microsoft.directory/applications/credentials/update, is valid for managing application credentials. Option C, microsoft.directory/users/update, is valid for updating user properties.

Option D, microsoft.directory/roles/assign, is not valid; role assignment uses the microsoft.directory/roleAssignments/assign action. Option E, microsoft.directory/groups/members/update, is valid for updating group membership. Therefore, the valid permissions are A, B, C, and E.

Exam trap

The trap is that candidates may think only common permissions like application delete and user update are valid, missing that credentials/update and group members/update are also valid. Additionally, role assignment uses a different path ('roleAssignments') than expected.

34
MCQmedium

Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant multifactor authentication (MFA) for all users accessing sensitive applications. Which authentication strength should you select in the policy?

A.Phishing-resistant MFA
B.Passwordless MFA
C.Multifactor authentication
D.No authentication strength
AnswerA

Phishing-resistant MFA is correct because Microsoft Entra ID P2 authentication strength policies can enforce device-bound credential types such as FIDO2 security keys or certificate-based authentication. These methods cryptographically tie the sign-in to the specific relying party and origin, which prevents relay attacks and adversary-in-the-middle phishing. The user proves possession of a private key stored in tamper-resistant hardware, making credentials impossible to replay on a fraudulent site.

Why this answer

The scenario explicitly requires 'phishing-resistant multifactor authentication (MFA).' Microsoft Entra ID authentication strengths allow you to enforce specific authentication methods. The 'Phishing-resistant MFA' strength includes methods like FIDO2 security keys and certificate-based authentication (CBA), which are resistant to phishing attacks. Selecting this strength ensures that only phishing-resistant methods are accepted for the Conditional Access policy.

Exam trap

The trap here is that candidates often confuse 'passwordless MFA' with 'phishing-resistant MFA,' not realizing that passwordless methods like Microsoft Authenticator phone sign-in are not considered phishing-resistant because they can still be intercepted by a sophisticated adversary-in-the-middle attack.

How to eliminate wrong answers

Option B is wrong because 'Passwordless MFA' includes methods like Microsoft Authenticator (phone sign-in) and Windows Hello for Business, which, while passwordless, are not all inherently phishing-resistant (e.g., phone sign-in can still be vulnerable to man-in-the-middle attacks). Option C is wrong because 'Multifactor authentication' is a generic strength that includes any MFA method (e.g., SMS, voice call, OTP), many of which are not phishing-resistant. Option D is wrong because selecting 'No authentication strength' means the policy will not enforce any specific authentication method, leaving the system to use the default MFA settings, which do not guarantee phishing resistance.

35
Multi-Selectmedium

Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?

Select 2 answers
A.Conditional Access
B.Self-service password reset (SSPR)
C.Privileged Identity Management (PIM)
D.Application Proxy
E.Microsoft Entra Join
AnswersA, C

Conditional Access is the core policy engine for zero trust, continuously evaluating signals like user risk, device compliance, location, and session context in real time. It enforces granular access controls—block, require MFA, or restrict session—before and during access, embodying the 'verify explicitly' principle of zero trust. Without it, other security controls lack a unified mechanism to apply context-aware, adaptive policies.

Why this answer

Conditional Access (A) is correct because it enforces least-privilege access by applying policies that require specific conditions (e.g., device compliance, location, risk level) before granting access to resources. It also enables continuous verification by evaluating signals in real time during each authentication request, ensuring that access is revoked if conditions change (e.g., user risk increases). This aligns directly with the zero-trust principle of 'never trust, always verify.'

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) as solely for role activation, but PIM enforces least-privilege by requiring just-in-time (JIT) elevation for admin roles, which is a core zero-trust requirement for privileged access, while Conditional Access handles continuous verification for all users.

36
MCQeasy

You are the administrator for a Microsoft 365 tenant. Users report that they cannot sign in to Microsoft Entra ID because their accounts are locked after multiple failed password attempts. You need to reduce the number of lockouts caused by users forgetting their passwords and to allow users to unlock their own accounts without calling the help desk. What should you do?

A.Configure a Conditional Access policy that requires multifactor authentication for all users.
B.Increase the account lockout threshold in Microsoft Entra password protection policies.
C.Enable Microsoft Entra Password Protection with a custom banned password list.
D.Enable self-service password reset (SSPR) for all users and configure the option to require users to register when they sign in.
AnswerD

SSPR allows users to reset their own passwords and unlock their accounts after lockout, reducing help desk calls. Requiring registration at sign-in ensures users enroll authentication methods before they need them. This directly addresses the requirement to reduce lockouts from forgotten passwords and enable self-service account unlocking.

Why this answer

Self-service password reset (SSPR) is the feature that lets users reset forgotten passwords and unlock their accounts without help desk involvement. Enabling SSPR and requiring registration at sign-in ensures users can self-remediate lockouts. Other options improve security but do not provide self-service account recovery, so they do not meet the requirement.

Exam trap

The trap here is thinking that increasing the lockout threshold or enabling MFA solves forgotten password lockouts, when only SSPR provides self-service reset and unlock.

37
MCQmedium

You are the identity administrator for a Microsoft 365 E5 tenant. The security team wants to enforce Microsoft Entra multifactor authentication (MFA) for all users when they access Microsoft 365 apps from outside the corporate network, but allow seamless access from the corporate office IP range 203.0.113.0/24. You create a Conditional Access policy named 'Require MFA offsite'. Which configuration should you use to meet the requirement?

A.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Require multifactor authentication.
B.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Block access, then create a separate policy to allow the corporate IP range.
C.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.
D.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Session to Use app enforced restrictions.
AnswerC

This is the correct approach: the policy targets all users and Office 365, applies from any location, but excludes the corporate IP range, so MFA is required only when users are outside the trusted network. The Grant control enforces MFA for the remaining sessions, satisfying the offsite-only requirement without affecting onsite access.

Why this answer

The requirement is to require MFA only when users are outside the corporate network. A Conditional Access policy that targets all users and Office 365, applies to any location, excludes the trusted corporate IP range, and grants multifactor authentication achieves this. Excluding the trusted location ensures onsite users are not prompted, while offsite sessions must satisfy the MFA grant control.

Exam trap

The trap here is assuming that 'Any location' means you cannot exclude the corporate range, when in fact trusted locations are configured as an exclusion within the Locations condition.

38
MCQmedium

You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The security team wants to require members of the 'Finance' group to use multifactor authentication (MFA) when they access any cloud app from outside the corporate network. You create a Conditional Access policy and assign it to the Finance group. You need to configure the policy to meet the requirement while minimizing impact on other users. What should you do?

A.Set the policy to report-only mode and monitor the sign-in logs.
B.Configure the policy to apply to all users and all cloud apps, and require MFA.
C.Create a named location for the corporate network and exclude it from the policy.
D.Enable security defaults in Microsoft Entra ID.
AnswerC

A named location defines trusted IP ranges. By excluding the corporate network, the policy applies only when Finance users are outside that network, satisfying the requirement to require MFA externally while not affecting internal access. This is the standard method to scope Conditional Access by network location.

Why this answer

The requirement is to require MFA for Finance group members only when they access cloud apps from outside the corporate network. This is achieved by creating a named location for the corporate network and excluding it from the Conditional Access policy. The policy then applies only to sign-ins from other locations, enforcing MFA externally without impacting internal users.

Exam trap

The trap here is assuming that report-only mode enforces MFA or that security defaults can be scoped to a group.

39
MCQhard

You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement just-in-time role activation for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification and approve via multi-factor authentication. They also want the activation to last for a maximum of 4 hours. You configure Privileged Identity Management (PIM). Which setting should you configure to meet the requirement for justification and MFA?

A.Assign the role as eligible and set the maximum activation duration to 4 hours.
B.In the role settings, enable 'Require justification on activation' and 'Require Microsoft Entra multifactor authentication on activation'.
C.Configure a Conditional Access policy that requires MFA for the Security Administrator role.
D.In the role settings, enable 'Require approval to activate' and specify approvers.
AnswerB

These settings are part of the role settings in PIM. Enabling 'Require justification on activation' forces users to provide a reason when activating. Enabling 'Require Microsoft Entra multifactor authentication on activation' enforces MFA during activation. Together, they meet the requirement for justification and MFA, and the maximum activation duration can be set separately.

Why this answer

In PIM, role settings include options to require justification and Microsoft Entra multifactor authentication on activation. Enabling both ensures that when a user activates the Security Administrator role, they must provide a reason and complete MFA. The maximum activation duration is set separately in the same role settings.

This configuration satisfies the just-in-time access requirements with the specified controls.

Exam trap

The trap here is confusing PIM activation requirements with Conditional Access MFA, which does not provide justification or just-in-time activation.

40
MCQeasy

You are implementing Microsoft Entra Verified ID to issue verifiable credentials to employees for proof of employment. Which component is required to issue and verify credentials?

A.Microsoft Entra ID P2 licenses for all users
B.A certificate from a public certificate authority (CA)
C.An Azure AD B2C tenant
D.A decentralized identifier (DID) and a trusted identity system
AnswerD

A decentralized identifier (DID) serves as the globally unique, cryptographically verifiable identifier for each participant in a verifiable credential ecosystem, paired with a trusted identity system that publishes and resolves DID documents. The DID document contains the public keys used to verify the credential issuer's signature, and the trust system establishes how DIDs are registered and discovered—through methods like did:ion or did:web. This combination replaces the need for a centralized CA, because trust is anchored in the cryptographic agreement of the DID infrastructure. Together, they form the core requirement for issuing and verifying verifiable credentials with Microsoft Entra Verified ID.

Why this answer

Microsoft Entra Verified ID uses a decentralized identity model where each issuer and verifier has a unique decentralized identifier (DID) and a trusted identity system (such as a blockchain-based ION network or a web-based DID method) to publish and resolve DID documents. The DID and the trusted identity system are the core components required to cryptographically sign verifiable credentials and verify them without relying on a central authority, making option D correct.

Exam trap

The trap here is that candidates often assume a traditional PKI certificate or a premium license is required, but Microsoft Entra Verified ID relies on decentralized identifiers (DIDs) and a trusted identity system, not on CA-issued certificates or specific license tiers.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P2 licenses provide advanced identity protection and governance features but are not a prerequisite for issuing or verifying verifiable credentials; Verified ID can work with any Azure AD tenant. Option B is wrong because a certificate from a public certificate authority (CA) is used for traditional PKI-based identity systems, but Verified ID uses DIDs and key pairs generated by the issuer, not a CA-issued certificate. Option C is wrong because Azure AD B2C is a customer identity and access management solution for external users, not a required component for Verified ID; Verified ID uses its own decentralized identity infrastructure.

41
Multi-Selecteasy

Your organization uses Microsoft Entra ID. You need to enable users to securely share documents with external partners. Which TWO features should you use?

Select 2 answers
A.Microsoft Entra B2B collaboration
B.Azure AD B2C
C.Microsoft Purview Information Protection
D.Microsoft Entra entitlement management
E.Microsoft Defender for Cloud Apps
AnswersA, D

Microsoft Entra B2B collaboration directly enables external sharing by letting you invite external partners into your tenant as guest users who authenticate with their own organizational or personal identity. It supports granular permissions, conditional access, and revocation without requiring you to manage those users' credentials. This is the core mechanism for giving outside collaborators secure access to your Entra ID-integrated applications.

Why this answer

Microsoft Entra B2B collaboration is correct because it allows you to securely share documents and collaborate with external partners by inviting them as guest users in your Entra ID tenant. This feature leverages existing identities (e.g., Microsoft, Google, or SAML/WS-Fed providers) without requiring external users to create new accounts, enabling controlled access to resources like SharePoint or Teams.

Exam trap

The trap here is confusing Azure AD B2C (customer-facing) with Microsoft Entra B2B collaboration (partner-facing), as both involve external users but serve fundamentally different scenarios—B2C is for consumer apps, while B2B is for enterprise collaboration.

42
Multi-Selecteasy

Which TWO are prerequisites for implementing Microsoft Entra ID Identity Protection? (Choose two.)

Select 2 answers
A.Microsoft Entra ID P2 license
B.Microsoft Entra ID P1 license
C.Identity Protection administrator role assigned
D.Audit logs enabled for sign-in events
E.Self-service password reset configured
AnswersA, C

Microsoft Entra ID P2 licensing is a hard prerequisite for implementing Identity Protection because risk detections, risk-based conditional access policies, and the Identity Protection report views are only included in the P2 tier. Attempting to configure these in a tenant with only P1 or free licensing will fail validation, as the underlying risk engine and policy controls are not provisioned.

Why this answer

Microsoft Entra ID Identity Protection requires a Microsoft Entra ID P2 license because it uses advanced risk detection and automated remediation capabilities (e.g., risk-based Conditional Access policies, user risk and sign-in risk policies) that are only available in the P2 tier. The P1 license provides basic Conditional Access but lacks the risk detection engine and adaptive policies that Identity Protection relies on.

Exam trap

The trap here is that candidates often confuse the licensing requirement for Identity Protection (P2) with the broader Conditional Access feature (P1), or assume that audit logs or SSPR are mandatory prerequisites when they are not directly required for Identity Protection's core functionality.

43
MCQeasy

You run the Azure CLI command shown in the exhibit. What does the output represent?

A.The application ID for Microsoft Entra ID
B.The application ID for Exchange Online
C.The application ID for SharePoint Online
D.The application ID for Microsoft Graph
AnswerD

The application ID 00000003-0000-0000-c000-000000000000 is the fixed, well-known application ID for Microsoft Graph. This ID is present in every Microsoft Entra ID tenant as the Microsoft Graph service principal and is used by Azure CLI commands to inspect its roles, permission scopes, and other configuration. It is not tied to any single workload like Exchange or SharePoint; it represents the unified Microsoft Graph API across all Microsoft 365 services.

Why this answer

The Azure CLI command `az ad sp show --id 00000003-0000-0000-c000-000000000000` retrieves the service principal for the Microsoft Graph API. The GUID `00000003-0000-0000-c000-000000000000` is the well-known application ID for Microsoft Graph in Microsoft Entra ID (formerly Azure AD). This ID is used to grant permissions and consent for Microsoft Graph API access.

Exam trap

The trap here is that candidates confuse the Microsoft Graph application ID with the SharePoint Online application ID because both start with `00000003`, but the middle segment differs (`-0000-0000-c000-` vs `-0000-0ff1-ce00-`), and Microsoft deliberately tests this subtle distinction.

How to eliminate wrong answers

Option A is wrong because the application ID for Microsoft Entra ID (the directory itself) is `00000001-0000-0000-c000-000000000000`, not the one shown. Option B is wrong because Exchange Online has its own application ID (`00000002-0000-0ff1-ce00-000000000000`), which is different from the GUID in the command. Option C is wrong because SharePoint Online uses application ID `00000003-0000-0ff1-ce00-000000000000`, not the Microsoft Graph ID `00000003-0000-0000-c000-000000000000`.

44
MCQhard

You are implementing Microsoft Entra Identity Protection. You need to configure automated responses to medium and high user risk. Which policy should you create?

A.Sign-in risk policy
B.Conditional Access policy with grant controls
C.MFA registration policy
D.User risk policy
AnswerD

The user risk policy responds to the aggregate probability that a user's identity has been compromised, based on multiple risk detections associated with that account. It can be configured to automatically block all access or trigger a secure password change with required MFA, based on the user risk level (low, medium, high). This is precisely the Microsoft Entra ID Protection mechanism designed for user risk levels, making it the correct answer.

Why this answer

User risk policy in Microsoft Entra Identity Protection is specifically designed to automatically respond to user risk levels (low, medium, high) by triggering remediation actions such as requiring a password change or blocking sign-in. Since the question asks for automated responses to medium and high user risk, the correct policy is the User risk policy, which evaluates risk based on user behavior and leaked credentials.

Exam trap

The trap here is confusing User risk policy (which responds to user-level risk like compromised accounts) with Sign-in risk policy (which responds to session-level risk like suspicious sign-in attempts), leading candidates to incorrectly choose the sign-in risk policy for user risk remediation.

How to eliminate wrong answers

Option A is wrong because Sign-in risk policy responds to real-time sign-in risks (e.g., anonymous IP, atypical travel) rather than user risk levels. Option B is wrong because Conditional Access policy with grant controls is a broader policy that can enforce MFA or block access but is not specifically designed to automate responses to user risk from Identity Protection; it can integrate with risk policies but is not the primary policy for user risk remediation. Option C is wrong because MFA registration policy is used to enforce MFA registration for all users, not to respond to user risk levels.

45
Multi-Selectmedium

Your company is implementing Microsoft Entra Conditional Access. You need to require multifactor authentication (MFA) for all users except those accessing from the corporate office. Which TWO components do you need?

Select 2 answers
A.Microsoft Intune compliance policies
B.Conditional Access policy configured with grant control requiring MFA and excluding Named Locations
C.Named Locations configuration
D.Microsoft Entra multifactor authentication registration policy
E.Microsoft Entra Identity Protection
AnswersB, C

To enforce MFA everywhere except the corporate office, you create a Conditional Access policy assigned to the target users and cloud apps, add your trusted corporate IP ranges as a Named Location, and set that location in the Exclude condition. Then, in Grant, you select 'Require multifactor authentication.' For sign-ins from any IP address that does not match the excluded Named Location, the grant control is applied and MFA is required; for sign-ins from the corporate location, the exclusion prevents MFA from being required. This is the actual policy object that implements the stated requirement.

Why this answer

To require MFA for all users except those accessing from the corporate office, you need a Conditional Access policy that grants access only if MFA is completed, and you must exclude the corporate office location. The 'Named Locations' configuration defines the corporate office IP ranges or trusted locations, and the Conditional Access policy uses that exclusion. Together, these two components enforce the requirement.

Exam trap

The trap here is that candidates often think a separate MFA registration policy (Option D) or Identity Protection (Option E) can handle location-based exclusions, but neither supports excluding Named Locations; only a Conditional Access policy with the 'Exclude' condition on Named Locations can achieve this.

46
MCQhard

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You have 10,000 users and 500 applications. You are planning to implement a comprehensive identity security strategy. Your requirements are: 1. All users must use phishing-resistant MFA for accessing business-critical applications. 2. Users accessing sensitive HR data must be required to use a compliant device. 3. Any authentication attempt from an anonymous IP address or from a country where Contoso has no business operations must be blocked. 4. All external collaboration must be governed by access reviews that require sponsor approval. 5. You need to monitor and respond to identity risks in real time. You need to design a solution using Microsoft Entra ID features. Which combination of features should you implement?

A.Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.
B.Configure Conditional Access policies with MFA and trusted locations. Use Identity Protection for risk monitoring. Set up access reviews with group owner approval.
C.Enable security defaults for all users. Use Microsoft Defender for Cloud Apps to block anonymous IPs. Configure Azure AD access reviews for external users.
D.Use certificate-based authentication for all users. Create Conditional Access policies for device compliance. Set up identity protection. Use self-service access reviews for external users.
AnswerA

Authentication strengths enforce phishing-resistant MFA, while Conditional Access applies compliant-device and location blocks. Identity Protection supplies real-time risk detection with automated remediation, and entitlement management with connected organisations plus sponsor-approved access reviews governs external collaboration, meeting all five stated requirements.

Why this answer

Option A correctly maps all requirements to Microsoft Entra ID features: authentication strengths for phishing-resistant MFA, Conditional Access for device compliance and location-based blocks, Identity Protection for risk monitoring and automated response, and entitlement management with access reviews for external collaboration governance. This combination leverages the full capabilities of Microsoft Entra ID P2 and E5 licenses.

Exam trap

MS-102 often tests the confusion between authentication methods (e.g., certificate-based) and authentication strengths, and between access reviews with group owner approval versus sponsor approval, leading candidates to choose incomplete solutions.

How to eliminate wrong answers

Option B is wrong because it uses MFA (not phishing-resistant) and trusted locations (which may not block all non-business countries), and access reviews with group owner approval do not require sponsor approval as specified. Option C is wrong because security defaults only provide basic MFA and do not support phishing-resistant methods or granular Conditional Access; Defender for Cloud Apps is not the primary tool for blocking anonymous IPs (Conditional Access is), and access reviews for external users lack sponsor approval. Option D is wrong because certificate-based authentication is not necessarily phishing-resistant (it can be if configured with strong factors, but authentication strengths is the correct feature), and self-service access reviews do not enforce sponsor approval.

47
MCQhard

Your organization uses Microsoft Entra ID and has a custom role that grants 'microsoft.directory/applications/credentials/update' permission. A security audit reveals that a user assigned this role has modified credentials for an application. You need to prevent such actions while allowing other application updates. What should you do?

A.Assign the user the built-in Application Administrator role instead.
B.Enable multi-factor authentication for the user.
C.Remove the user from the custom role and assign them another role with fewer permissions.
D.Create a custom role that excludes the 'microsoft.directory/applications/credentials/update' permission and assign it to the user.
AnswerD

Creating a custom role that omits the 'microsoft.directory/applications/credentials/update' permission ensures the user cannot change application secrets, certificates, or passwords, while still allowing other application management actions. Custom roles in Microsoft Entra ID allow you to compose a permission set from the available permissions, enabling you to exclude sensitive operations. Assigning this custom role to the user satisfies the requirement to prevent credential updates without over-restricting other updates.

Why this answer

The custom role currently includes the 'microsoft.directory/applications/credentials/update' permission, which allows modifying application credentials. To prevent credential updates while still permitting other application updates, you must create a new custom role that explicitly excludes this permission and assign it to the user. This approach preserves granular control without granting unnecessary privileges, unlike built-in roles that would either over-scope or under-scope permissions.

Exam trap

The trap here is that candidates may think removing the user from the custom role and assigning a different role (Option C) is the simplest fix, but that would likely revoke all application update permissions, failing the requirement to allow other updates.

How to eliminate wrong answers

Option A is wrong because assigning the built-in Application Administrator role grants broader permissions, including the ability to update credentials, which does not solve the problem. Option B is wrong because enabling multi-factor authentication enhances security but does not restrict the user's existing permissions to modify credentials. Option C is wrong because removing the user from the custom role and assigning another role with fewer permissions would likely remove all application update capabilities, which is too restrictive and does not allow other application updates.

48
MCQmedium

Your company uses Microsoft Intune for mobile device management. You need to ensure that only compliant devices can access corporate email in Microsoft 365. Which Microsoft Entra ID feature should you combine with Intune compliance policies?

A.Conditional Access
B.Microsoft Entra Application Proxy
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management
AnswerA

Conditional Access is the correct answer because it evaluates signals like device compliance before granting access. In Intune, compliance policies assess device health, and Conditional Access policies can require those devices to be marked compliant, blocking or allowing access based on that state. This direct integration makes it the tool that checks device compliance from Intune for MDM-managed devices.

Why this answer

Conditional Access is the correct answer because it is the Microsoft Entra ID feature that enforces access controls based on signals such as device compliance. When combined with Intune compliance policies, Conditional Access can block or allow access to corporate email in Microsoft 365 based on whether the device is marked as compliant by Intune. This integration ensures that only devices meeting your organization's security requirements can access corporate resources.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based access) with Conditional Access (which enforces policies like device compliance), leading them to select Option C instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Application Proxy provides secure remote access to on-premises web applications, not device compliance enforcement for cloud services. Option C is wrong because Microsoft Entra Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs), but it does not evaluate device compliance status. Option D is wrong because Microsoft Entra Privileged Identity Management manages, controls, and monitors access to privileged roles in Microsoft Entra ID, not device compliance or access policies for corporate email.

49
MCQeasy

Your company uses Microsoft Entra ID. You need to ensure that when users are assigned privileged roles, they must activate the role and provide a justification. The solution must minimize the number of standing assignments. What should you implement?

A.Conditional Access policy requiring MFA for all users assigned to privileged roles.
B.Microsoft Entra ID Protection risk policies for privileged users.
C.Microsoft Entra Privileged Identity Management (PIM) with eligible assignments and activation requirements.
D.Microsoft Entra ID Governance access reviews for privileged roles.
AnswerC

PIM allows you to assign users as eligible for privileged roles. When they need the role, they must activate it, optionally providing justification and passing MFA. This minimizes standing access and meets the requirement. It is the correct solution for just-in-time privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time privileged access. By configuring eligible assignments, users must activate roles when needed, and you can require justification and MFA. This minimizes standing access.

Other options do not provide activation workflows or justification requirements.

Exam trap

The trap here is assuming that Conditional Access or access reviews can enforce just-in-time role activation with justification, which they cannot.

50
MCQhard

Your organization uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. You need to protect a custom SaaS application that uses SAML-based SSO. The application does not support Conditional Access. You want to enforce session controls such as blocking downloads of sensitive files. What should you implement?

A.Deploy Microsoft Defender for Cloud Apps Conditional Access App Control and route the application through Defender for Cloud Apps.
B.Implement a reverse proxy from a third-party vendor.
C.Create a custom application registration and set app roles.
D.Configure the application to use Microsoft Entra ID as the identity provider and enable Conditional Access policies.
AnswerA

Microsoft Defender for Cloud Apps Conditional Access App Control (ACAC) is correct because it functions as a session-level reverse proxy that intercepts the user's session after authentication, enabling real-time controls like blocking downloads, preventing paste, and redacting sensitive data. By routing the application through Defender for Cloud Apps, you can target it with a Conditional Access policy using the 'Use Conditional Access App Control' session control, which works even for third-party SaaS apps that lack native Conditional Access support. This provides the exact session-level enforcement and visibility needed.

Why this answer

Microsoft Defender for Cloud Apps Conditional Access App Control acts as a reverse proxy that can enforce session policies—such as blocking downloads of sensitive files—on any SAML-based SaaS application, even if the application itself does not support Conditional Access. By routing the application's traffic through Defender for Cloud Apps, you can apply granular session controls at the proxy layer without modifying the application.

Exam trap

The trap here is that candidates often assume that enabling Entra ID as the identity provider and applying Conditional Access policies is sufficient, but they overlook that the application must support Conditional Access (i.e., be capable of enforcing the resulting controls) for those policies to work; when the app does not, a proxy-based solution like Defender for Cloud Apps App Control is required.

How to eliminate wrong answers

Option B is wrong because while a third-party reverse proxy could theoretically provide similar controls, the question specifically asks for a solution within the Microsoft ecosystem (Entra ID P2 and Defender for Cloud Apps), and Microsoft's own solution is the recommended and integrated approach. Option C is wrong because creating a custom application registration and setting app roles only manages authentication and authorization within Entra ID, but does not provide session-level controls like blocking file downloads. Option D is wrong because the application does not support Conditional Access, so configuring it to use Entra ID as the identity provider and enabling Conditional Access policies would have no effect—Conditional Access requires the application to be capable of interpreting and enforcing the resulting claims or tokens.

51
MCQhard

You are troubleshooting why a user cannot access a SharePoint Online site. The user is assigned a Conditional Access policy that requires compliant device, and the device is enrolled in Microsoft Intune but shows as non-compliant. What is the most likely cause?

A.The device is non-compliant due to missing security updates
B.The device is not enrolled in Microsoft Intune
C.The Conditional Access policy is not applied to SharePoint Online
D.The user does not have an Intune license
AnswerA

The device is non-compliant because Microsoft Intune compliance policies evaluate security update installation as a required health condition. Missing security updates cause the compliance state to become 'non-compliant', which triggers the Conditional Access policy's 'Require device to be marked as compliant' grant control and blocks access to SharePoint Online. The user's license and the policy's application scope are irrelevant because the failure is specifically the device's compliance state.

Why this answer

The user's device is enrolled in Intune but marked as non-compliant, which directly blocks access because the Conditional Access policy requires a compliant device. The most common reason for non-compliance is missing security updates, as Intune evaluates compliance based on configured policies such as required patch levels, encryption status, or threat detection. Since the device is enrolled, the issue is not enrollment or licensing, but a specific compliance rule violation.

Exam trap

The trap here is that candidates may assume the device is not enrolled or the policy is misconfigured, but the question explicitly confirms enrollment and policy application, forcing you to focus on the compliance state itself.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states the device is enrolled in Microsoft Intune, so non-enrollment is not the cause. Option C is wrong because the Conditional Access policy is applied to SharePoint Online (as stated in the question), and the user is being blocked, indicating the policy is active. Option D is wrong because the user must have an Intune license to enroll the device and have it evaluated for compliance; without a license, the device would not appear in Intune at all.

52
MCQeasy

You need to grant a vendor access to a specific SharePoint Online site for a limited time. The vendor does not have an account in your Microsoft Entra ID. What should you use?

A.Create a user account via Microsoft Entra Connect
B.Configure self-service sign-up user flow
C.Assign the vendor a guest user account with no expiration
D.Use Microsoft Entra B2B collaboration and set an expiration for the guest user
AnswerD

Microsoft Entra B2B collaboration is the intended mechanism for inviting external vendors, because it creates a guest user identity that can be scoped to specific resources such as a SharePoint site. Combined with the guest user expiration policy in Entra ID, you can specify a fixed number of days before the account becomes inactive, enforcing time-bound access without any manual offboarding. This approach aligns with zero-trust principles and ensures the vendor's access automatically expires after the engagement.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external users (vendors) as guest users to access your organization's resources, including SharePoint Online sites, without requiring them to have an existing account in your tenant. You can configure an expiration policy for the guest user account to automatically remove access after a specified period, meeting the requirement for limited-time access.

Exam trap

The trap here is that candidates often confuse B2B collaboration with creating a new user account (Option A) or assume that self-service sign-up (Option B) is appropriate for a single vendor, when in fact B2B collaboration is the correct method for granting external users time-limited access without managing their identities.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory identities to Microsoft Entra ID, not to create accounts for external vendors who do not have an existing identity in your organization. Option B is wrong because self-service sign-up user flow is designed for customers or partners to create their own accounts in your tenant for app registration or B2C scenarios, not for granting a specific vendor access to a SharePoint site with controlled expiration. Option C is wrong because assigning a guest user account with no expiration does not meet the requirement for limited-time access; it would grant permanent access unless manually removed, which is not automated or policy-driven.

53
MCQhard

Your company uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that a user's sign-in was blocked due to a medium user risk. However, the user claims the sign-in was legitimate. What should you do to allow future sign-ins without lowering security?

A.Create a conditional access policy to bypass MFA for this user
B.Suppress the alert in Microsoft Defender XDR
C.Use the Microsoft Entra ID Protection reports to confirm the user as safe
D.Dismiss the risk in the Risky users report
AnswerC

Using the Microsoft Entra ID Protection reports to confirm the user as safe is the correct manual remediation action when investigation shows the risk detection is a false positive or the account is validated as legitimate. Selecting 'Confirm user safe' on the Risky users report dismisses the risk, resets the user's risk level, and removes the user from the risky users list, allowing sign-ins to proceed normally without requiring a password reset. This action should be performed only after verifying the user's identity and activity, as it is a permanent dismissal that prevents risk-based conditional access policies from challenging the user in the future.

Why this answer

When a user claims a blocked sign-in was legitimate, the proper action is to confirm the user as safe in the Microsoft Entra ID Protection reports. This action updates the risk state to 'confirmed safe', which resets the user's risk level and allows future sign-ins without lowering security. It also provides feedback to the risk detection algorithm to improve accuracy.

Exam trap

The trap here is confusing 'dismissing the risk' (which only closes the alert) with 'confirming the user as safe' (which actively resets the risk state and provides feedback), leading candidates to incorrectly choose Option D.

How to eliminate wrong answers

Option A is wrong because creating a conditional access policy to bypass MFA for this user would lower security by removing a critical authentication requirement, and it does not address the underlying risk detection. Option B is wrong because suppressing the alert in Microsoft Defender XDR only hides the notification; it does not resolve the risk state or prevent future blocks. Option D is wrong because dismissing the risk in the Risky users report simply closes the alert without confirming the sign-in as legitimate, which could allow the same risk to trigger again and does not provide feedback to the risk engine.

54
MCQhard

Your organization uses Microsoft Entra ID with P2 licenses. You need to identify and remediate users who are at risk due to leaked credentials or anomalous sign-in activity. You want to automate the response to high-risk users by requiring a password change. Which feature should you use?

A.Microsoft Entra Identity Protection
B.Microsoft Defender for Cloud Apps
C.Microsoft Entra Identity Governance
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerA

Identity Protection detects leaked credentials and anomalous sign-in behaviour via its risk detections, then applies risk-based Conditional Access policies. A policy requiring password change for high-risk users automates remediation, satisfying the P2-licensed requirement to identify and respond to risky users.

Why this answer

Microsoft Entra Identity Protection provides risk-based conditional access policies that can automatically require a password change for high-risk users. Option B is wrong because Microsoft Defender for Cloud Apps focuses on cloud application security, not identity risk. Option C is wrong because Microsoft Entra Identity Governance handles access reviews and entitlement management.

Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages privileged roles, not user risk.

55
MCQmedium

Your organization uses Microsoft Entra Connect Sync. You need to ensure that specific on-premises Active Directory groups are synchronized to Microsoft Entra ID. What should you configure?

A.Set the sync scope to 'Synchronize selected groups'
B.Configure attribute-based filtering in Microsoft Entra Connect
C.Create a security group in Microsoft Entra ID and add members
D.Use the Synchronization Service Manager to select groups
AnswerA

Selecting 'Synchronize selected groups' in Microsoft Entra Connect wizard (or via PowerShell) restricts synchronization to only the on-premises groups you explicitly choose, along with their members. This is the native group-based filtering (also called group scoping) feature, letting you sync, for example, only the 'Sales' group and its users while excluding all other objects. It directly controls what the sync engine copies from the on-premises connector to Microsoft Entra ID, making it the correct answer.

Why this answer

Microsoft Entra Connect Sync allows you to scope synchronization to specific groups by selecting 'Synchronize selected groups' in the Azure AD Connect configuration. This setting, available during installation or via the 'Customize synchronization options' task, restricts synchronization to only the on-premises Active Directory groups you explicitly choose, ensuring that only those groups are synced to Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse attribute-based filtering (Option B) with group-specific scoping, not realizing that attribute-based filtering applies to all object types and cannot be used to select individual groups for synchronization.

How to eliminate wrong answers

Option B is wrong because attribute-based filtering in Microsoft Entra Connect filters objects based on their attributes (e.g., department or country), not specifically for selecting which groups to synchronize; it is a broader filtering mechanism that can exclude objects but does not provide a group-specific selection. Option C is wrong because creating a security group in Microsoft Entra ID and adding members does not control which on-premises groups are synchronized; it creates a cloud-only group that is not linked to the on-premises synchronization process. Option D is wrong because the Synchronization Service Manager is used to manage synchronization operations (e.g., run profiles, connectors, and metaverse objects) but does not provide a configuration option to select specific groups for synchronization; group selection is done during the Azure AD Connect configuration wizard.

56
MCQmedium

Your company uses Microsoft Entra ID. You need to restrict access to a critical application to only users who are in a specific security group and are signing in from a trusted location. You configure a conditional access policy with the following conditions: users (the security group), cloud apps (the critical application), conditions (locations: trusted IP ranges). However, users in the security group are still able to access the app from untrusted locations. What is the most likely reason?

A.The policy is configured as a block policy but is overridden by another policy
B.The cloud app is not correctly assigned to the policy
C.The policy uses session controls instead of grant controls
D.The policy is in report-only mode
AnswerD

Report-only mode evaluates a Conditional Access policy and writes the results to the Identity Protection logs without enforcing any of its configured controls. For a block policy, report-only means the intended block is never applied, and access is allowed exactly as if the policy did not exist. This is the classic default misconfiguration that makes a block policy appear ineffective during testing.

Why this answer

When a Conditional Access policy is in report-only mode, it evaluates the conditions and logs the result but does not enforce any access controls (grant or block). This explains why users in the security group can still access the app from untrusted locations—the policy is not actively blocking or requiring MFA/location compliance. Report-only mode is commonly used for testing before enabling enforcement.

Exam trap

The trap here is that candidates often assume a Conditional Access policy automatically enforces its conditions once configured, overlooking the critical distinction between report-only mode (evaluation only) and on/enforce mode (evaluation + enforcement).

How to eliminate wrong answers

Option A is wrong because if the policy were a block policy, it would actively block access when conditions match; the issue here is that no enforcement occurs at all, not that another policy overrides it. Option B is wrong because the cloud app assignment is correctly configured per the scenario; if it were incorrect, the policy wouldn't apply to the app at all, but users are still accessing it, indicating the policy is not enforcing. Option C is wrong because session controls (e.g., sign-in frequency) do not prevent access from untrusted locations; only grant controls (e.g., require trusted location) can block or allow access based on location.

The core problem is that the policy is not enforcing any controls, which points to report-only mode.

57
MCQhard

You are configuring a Microsoft Entra Conditional Access policy to require compliant devices for access to Microsoft 365 apps. You need to ensure that the policy applies to all users except those in the 'BreakGlass' group. The BreakGlass group contains emergency access accounts. What should you do?

A.Create a Conditional Access policy that includes the BreakGlass group and set the grant control to 'Block access'.
B.Create a Conditional Access policy that includes all users, excludes the BreakGlass group, and set the grant control to 'Require multi-factor authentication'.
C.Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.
D.Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the session control to 'Use app enforced restrictions'.
AnswerC

Conditional Access policies allow you to include all users and then exclude specific groups, such as the BreakGlass group. This ensures that emergency access accounts are not blocked by the policy. Setting the grant control to require a compliant device enforces the device compliance requirement for all other users. This is the correct and recommended approach to avoid locking out emergency accounts.

Why this answer

To enforce device compliance while excluding emergency access accounts, create a Conditional Access policy that targets all users but excludes the BreakGlass group. Then set the grant control to require the device to be marked as compliant. This ensures that only compliant devices can access Microsoft 365 apps, while emergency accounts remain unaffected.

The other options either block emergency accounts, apply session restrictions instead of compliance, or require MFA instead of compliance.

Exam trap

The trap here is mixing up grant controls and session controls; requiring a compliant device is a grant control, not a session control like app enforced restrictions.

58
MCQeasy

You are implementing Microsoft Entra Verified ID. Which identity verification method uses a decentralized identity standard?

A.Decentralized identifiers (DIDs)
B.SAML 2.0
C.OAuth 2.0
D.Federation with Azure AD
AnswerA

Decentralized identifiers (DIDs) are the core of Microsoft Entra Verified ID: they are W3C-standard, globally unique identifiers generated from a public/private key pair and resolvable without a central registry. In Entra Verified ID, issuers and verifiers anchor DIDs to ION (Sidetree on Bitcoin) or use did:web, and the key holder uses the private key to sign Verifiable Credentials. This gives the user a self-owned, portable identity that cannot be revoked or controlled by a single IdP, which is exactly what Verified ID is designed to provide.

Why this answer

Microsoft Entra Verified ID is built on open standards for decentralized identity, specifically using Decentralized Identifiers (DIDs) as defined by the W3C. DIDs enable verifiable, self-sovereign identity without relying on a central authority, which is the core requirement for a decentralized identity verification method. This allows users to control their own identifiers and present verifiable credentials that can be cryptographically verified.

Exam trap

The trap here is that candidates confuse decentralized identity with federation or token-based protocols (SAML, OAuth), which are centralized by design, and fail to recognize that DIDs are the specific W3C standard enabling self-sovereign identity in Verified ID.

How to eliminate wrong answers

Option B is wrong because SAML 2.0 is a centralized federation protocol that relies on a single identity provider (IdP) to assert identity, not a decentralized standard. Option C is wrong because OAuth 2.0 is an authorization framework for token-based access delegation, not an identity verification method or decentralized identity standard. Option D is wrong because federation with Azure AD is a centralized identity management approach that depends on a trusted authority (Azure AD) to manage identities, which contradicts the decentralized, user-controlled model of Verified ID.

59
MCQmedium

Your organization uses Microsoft Entra ID P2 licensing. You need to ensure that when a user's risk level is detected as 'high' by Identity Protection, the user is automatically required to perform a password change during their next sign-in. Which conditional access policy configuration should you use?

A.Assign 'Sign-in risk policy' with session control 'Sign-in frequency'
B.Assign 'User risk policy' with grant 'Require password change'
C.Assign 'User risk policy' with grant 'Require multifactor authentication'
D.Assign 'User risk policy' with grant 'Block access'
AnswerB

When a user risk policy triggers a 'Require password change' grant, the user must change their password before accessing resources, which invalidates the compromised credential. This directly remediates the detected user risk because the attacker no longer knows the valid password, and is the only option listed that performs an actual password reset.

Why this answer

The 'User risk policy' in Microsoft Entra ID Conditional Access is specifically designed to respond to user-level risk detections from Identity Protection. When a user's risk level is 'high', the policy can enforce a 'Require password change' grant, which forces the user to change their password at next sign-in to remediate the compromised account. This aligns with the requirement to automatically trigger a password change based on user risk.

Exam trap

The trap here is confusing 'Sign-in risk policy' (which controls session behavior) with 'User risk policy' (which controls user-level remediation), leading candidates to incorrectly select Option A for a password change requirement.

How to eliminate wrong answers

Option A is wrong because 'Sign-in risk policy' targets sign-in sessions (e.g., impossible travel, anonymous IP) and uses session controls like 'Sign-in frequency' to reauthenticate, not to force a password change based on user risk. Option C is wrong because 'Require multifactor authentication' as a grant for a user risk policy would prompt for MFA but does not force a password change, which is required to remediate a high-risk user. Option D is wrong because 'Block access' would prevent the user from signing in entirely, not allow them to sign in and then change their password.

60
MCQeasy

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Google or Facebook. Which identity solution should you configure?

A.External identities
B.Microsoft Entra B2B collaboration
C.Managed identities
D.Microsoft Entra Identity Protection
AnswerA

External identities is the Microsoft Entra ID capability that encompasses all identities outside your own directory, including B2B collaboration and B2C. It directly supports social identity providers such as Google and Facebook, allowing users to authenticate with those credentials and then access organizational or consumer-facing applications. Because the scenario is about social identity providers for user sign-in, this is the correct answer.

Why this answer

External identities in Microsoft Entra ID allow you to configure identity providers such as Google and Facebook, enabling users to sign in with their existing social media accounts. This is achieved by setting up federation with OAuth 2.0 and OpenID Connect protocols, which is the correct solution for the scenario described.

Exam trap

The trap here is that candidates often confuse 'External identities' (which includes social identity providers) with 'B2B collaboration' (which is for guest users from other organizations), leading them to select B2B collaboration incorrectly.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2B collaboration is specifically for inviting external business partners (guests) from other Azure AD tenants or email domains, not for federating with social identity providers like Google or Facebook. Option C is wrong because managed identities are used to provide Azure resources with an automatically managed identity in Azure AD for authenticating to other Azure services, not for external user sign-in. Option D is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats, not a federation solution for social identity providers.

61
Multi-Selecthard

Your organization uses Microsoft Entra ID and has a hybrid identity configuration with Active Directory Federation Services (AD FS). You are migrating to cloud authentication using Pass-through Authentication (PTA). Which TWO components are required for a PTA deployment?

Select 2 answers
A.Service Bus endpoints in Azure
B.Password Hash Synchronization agent
C.Azure AD Connect Health agent
D.Seamless Single Sign-On
E.Pass-through Authentication Agent
AnswersA, E

The Pass-through Authentication (PTA) Agent does not directly receive authentication requests from Azure AD over an inbound connection. Instead, it establishes an outbound connection to Azure Service Bus endpoints, and Azure AD delivers password validation requests to the agent through this Service Bus relay. Without these endpoints being reachable, the PTA agent cannot receive or respond to authentication requests, so Service Bus endpoints are an essential part of the PTA architecture.

Why this answer

Pass-through Authentication (PTA) requires the PTA Agent to be installed on-premises to validate user passwords against Active Directory. It also uses Azure Service Bus endpoints to establish a secure, persistent connection between the on-premises agent and Microsoft Entra ID, enabling authentication requests to flow without storing passwords in the cloud.

Exam trap

The trap here is that candidates often confuse the required components for PTA with those for PHS or Seamless SSO, mistakenly including the Password Hash Synchronization agent or Seamless SSO as mandatory for PTA.

62
Multi-Selecthard

You are designing a Microsoft Entra ID governance strategy. Which THREE features should you use to implement the principle of least privilege for administrative roles?

Select 3 answers
A.Microsoft Entra Lifecycle Workflows
B.Privileged Access Groups
C.Microsoft Entra Entitlement Management
D.Microsoft Entra Privileged Identity Management (PIM)
E.Microsoft Entra Access Reviews
AnswersB, D, E

Privileged Access Groups (PAG) are role-assignable Microsoft Entra ID groups that can be mapped to Azure AD roles, allowing group membership to control role eligibility. When PIM is enabled for these groups, admins receive just-in-time, time-bound activation, and dynamic membership rules can be used to add or remove users automatically based on attributes or lifecycle events. This combination makes PAG a modern, correct approach for admin role governance.

Why this answer

Privileged Access Groups (B) enable you to grant just-in-time or time-bound access to Azure AD roles and other resources by assigning users to a group that is eligible for role activation, directly supporting the principle of least privilege by limiting standing administrative access.

Exam trap

The trap here is that candidates often confuse Entitlement Management (which handles access packages for end users) with Privileged Access Groups (which specifically control administrative role activation), leading them to select Option C instead of B.

63
MCQmedium

Refer to the exhibit. You have a Conditional Access policy as shown. The exhibit shows the policy is in Report-only mode and that Microsoft Azure Management is included as the target cloud app. A Global Administrator reports that they are not prompted for MFA when accessing the Azure portal. Which is the most likely reason?

A.The Global Administrator role is not included in the policy.
B.The user is accessing from a trusted IP address.
C.The policy does not include the Azure portal as a target cloud app.
D.The policy is in Report-only mode.
AnswerD

Report-only mode evaluates the policy and logs its outcome without enforcing controls, so sign-ins proceed without an MFA prompt. The Global Administrator's experience confirms the policy is not yet switched to On, which is the enforcement state required to challenge users.

Why this answer

The policy is set to 'Report-only' mode, which means it evaluates sign-ins and logs results but does not enforce any controls like MFA. Even though the policy targets Microsoft Azure Management (which includes the Azure portal), the enforcement mode must be 'On' to require MFA. Since it is in Report-only mode, the Global Administrator is not prompted for MFA.

Exam trap

The trap is that candidates might assume that as long as a Conditional Access policy includes the correct cloud app (Microsoft Azure Management), it will enforce MFA. However, if the policy is in Report-only mode, it does not enforce any controls, regardless of the app targeting.

How to eliminate wrong answers

Option A is wrong because the policy targets 'All users', which includes Global Administrators; the role itself does not need to be listed separately. Option B is wrong because the exhibit shows no trusted IP address exclusion is configured; the policy applies to all locations. Option D is wrong because the exhibit shows the policy is set to 'On' (enabled), not 'Report-only' mode.

64
MCQmedium

Your organization, Contoso, has a Microsoft Entra ID tenant with 50,000 users. You are implementing a zero-trust security model. The following requirements must be met: 1) All access to SaaS applications must be restricted based on user, device, and location. 2) Users accessing from unmanaged devices must only be allowed browser-based access and must accept terms of use. 3) The IT team must be able to grant temporary access to the Global Administrator role for up to 8 hours. 4) All external users must have their access reviewed every 6 months. Which combination of Microsoft Entra features should you use?

A.Conditional access policies, entitlement management, Privileged Identity Management (PIM), and access reviews
B.Conditional access policies, Privileged Identity Management (PIM), access reviews, and terms of use
C.Conditional access policies, Microsoft Entra B2B, Privileged Identity Management (PIM), and access reviews
D.Conditional access policies, Identity Protection user risk policy, Privileged Identity Management (PIM), and access reviews
AnswerB

This combination fully meets the requirement: conditional access policies enforce device, location, and browser restrictions; terms of use require explicit consent from users on unmanaged devices before access is granted; PIM provides time-bound, just-in-time activation of administrative roles; and access reviews periodically recertify external and internal user access. Each component addresses a distinct control, and together they ensure both secure conditional access and ongoing governance.

Why this answer

It combines Conditional Access policies to enforce user, device, and location restrictions; Terms of Use to require acceptance for browser-based access from unmanaged devices; Privileged Identity Management (PIM) to grant time-limited Global Administrator access for up to 8 hours; and Access Reviews to ensure external users are reviewed every 6 months. This set directly addresses all four requirements without introducing unnecessary or conflicting features.

Exam trap

The trap here is that candidates often confuse Entitlement Management or B2B with the Terms of Use feature, but Terms of Use is a distinct Conditional Access grant control specifically designed to require user acceptance before accessing applications, which is essential for the unmanaged device browser-access requirement.

How to eliminate wrong answers

Option A is wrong because it includes Entitlement Management, which is used for managing resource access packages and guest user lifecycle, but it does not provide the Terms of Use functionality required for unmanaged device browser access. Option C is wrong because it includes Microsoft Entra B2B, which is for inviting external users and managing their identities, but it does not enforce Terms of Use acceptance for unmanaged devices; the requirement for browser-based access with Terms of Use is specifically met by the Terms of Use feature, not B2B. Option D is wrong because it includes Identity Protection user risk policy, which focuses on detecting and responding to risky user behavior (e.g., leaked credentials), but it does not enforce Terms of Use acceptance for unmanaged devices, which is a distinct requirement.

65
MCQeasy

You are configuring Microsoft Entra ID for a new organization. The CIO wants to ensure that all external users who are invited to collaborate via Microsoft Entra B2B must go through an approval process before gaining access. Which setting should you configure?

A.Create a Conditional Access policy requiring approval for external users
B.Set 'External collaboration settings' to restrict invitations to specific admins
C.Enable guest self-service sign-up via user flows
D.Enable Identity Protection for guest users
AnswerB

Under Microsoft Entra ID, go to External Identities > External collaboration settings and configure 'Guest invite restrictions' to 'Only users assigned to specific admin roles can invite guest users' (or the Guest Inviter role). This restricts invitation capability to authorized administrators, so any external user must be vetted by an admin before the invitation is sent, effectively acting as a mandatory approval gate. This is the correct control because it directly governs who may initiate external invitations and prevents regular users from bypassing oversight.

Why this answer

The 'External collaboration settings' in Microsoft Entra ID allow you to restrict who can invite external users. By setting the invitation restriction to 'Only users assigned to specific admin roles can invite', you ensure that all B2B collaboration invitations must be initiated by authorized admins, effectively requiring an approval process before external users gain access.

Exam trap

The trap here is confusing post-authentication access controls (Conditional Access) with pre-invitation approval workflows (External collaboration settings), leading candidates to incorrectly select a Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies control access after authentication (e.g., requiring MFA or device compliance), not the invitation or approval process for B2B guest users. Option C is wrong because enabling guest self-service sign-up via user flows allows external users to sign up without any admin approval, which directly contradicts the requirement for an approval process. Option D is wrong because Identity Protection for guest users monitors risk signals (e.g., leaked credentials) but does not control the invitation or approval workflow for B2B collaboration.

66
MCQmedium

Your company has a Microsoft Entra tenant with 5,000 users. You need to delegate the ability to reset user passwords to the helpdesk team, but only for users in the Sales department. What is the most efficient way to achieve this?

A.Create an administrative unit for Sales, add Sales users, then assign a custom role scoped to that administrative unit
B.Create a security group for Sales, then assign a custom role to the group
C.Create a custom role with password reset permissions and assign it to helpdesk
D.Add helpdesk users to the Global Administrator role
AnswerA

Administrative units scope role assignments to a defined subset of users, so a custom role granting password reset can be assigned to helpdesk over the Sales administrative unit only, avoiding tenant-wide permissions or per-user delegation.

Why this answer

Administrative units (AUs) in Microsoft Entra ID are containers specifically designed to scope administrative permissions to a subset of users, groups, or devices. By creating an AU for Sales, adding the Sales users to it, and assigning a custom role (such as Password Administrator or a custom role with microsoft.directory/users/password/update) scoped to that AU, the helpdesk team gains the ability to reset passwords only for Sales users. This is the most efficient and least-privilege approach because it uses built-in scoping mechanisms without needing to manage separate role assignments per user or create complex conditional access policies.

Exam trap

MS-102 often tests the misconception that security groups can be used to scope role assignments in Microsoft Entra ID, but role scoping requires administrative units or tenant-level assignment; security groups are for licensing and access management, not for scoping administrative roles.

How to eliminate wrong answers

Option B is wrong because security groups cannot be used as a scope for role assignments in Microsoft Entra ID; role assignments are scoped to the tenant, administrative units, or (for some roles) specific objects, not to security groups. Option C is wrong because a custom role assigned at the tenant level would grant password reset permissions for all users, not just Sales, violating the requirement to limit to the Sales department. Option D is wrong because Global Administrator is the highest-privilege role and grants full control over the entire tenant, which is excessive and violates the principle of least privilege.

67
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage administrative roles. You need to ensure that when a user activates the Global Administrator role, they must provide a justification and the activation is time-bound. Additionally, you want to require approval from the security team for this activation. What should you configure?

A.Configure an Identity Protection user risk policy for Global Administrators
B.Create an Access Review for Global Administrator role
C.Configure a Conditional Access policy requiring MFA for Global Administrator activation
D.Modify the PIM role settings for Global Administrator to require justification, set maximum activation duration, and require approval
AnswerD

Configuring the Global Administrator role's PIM settings directly satisfies every stated constraint: justification on activation, a maximum activation duration enforcing time-bound access, and approver selection for security team sign-off. These controls live in the role's activation settings within Microsoft Entra ID Privileged Identity Management, so no separate policy or access review is needed.

Why this answer

Privileged Identity Management (PIM) role settings allow you to enforce activation requirements such as justification, maximum activation duration, and approval. These settings are configured directly in the PIM role settings for the Global Administrator role, ensuring that every activation request is justified, time-bound, and requires approval from designated approvers (e.g., the security team).

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control authentication) with PIM role settings (which control role activation), leading them to select Option C even though Conditional Access cannot enforce approval workflows or activation duration limits.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policies are designed to detect and respond to user account compromise risks (e.g., leaked credentials), not to control PIM role activation workflows. Option B is wrong because Access Reviews are used for periodic recertification of role assignments (e.g., confirming who still needs the role), not for enforcing activation-time requirements like justification, duration, or approval. Option C is wrong because Conditional Access policies can require MFA during sign-in, but they cannot enforce PIM-specific activation requirements such as justification, time-bound activation, or approval workflow; those are managed exclusively within PIM role settings.

68
MCQeasy

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Microsoft, Google, or Facebook. What should you configure?

A.Configure Conditional Access policies for social identity providers
B.Configure External Identities and add identity providers for social networks
C.Configure Microsoft Entra Connect to sync social account attributes
D.Configure self-service password reset (SSPR)
AnswerB

External Identities lets you federate with social providers such as Microsoft, Google, and Facebook, so users sign in with existing accounts rather than new Entra ID credentials. This directly satisfies the requirement for social media sign-in.

Why this answer

Microsoft Entra ID supports External Identities, which allow you to add social identity providers (Microsoft, Google, Facebook) as external authentication sources. This enables users to sign in with their existing social accounts by configuring federation with those providers using OAuth 2.0 or OpenID Connect protocols, without needing to create separate Entra ID accounts.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with identity provider configuration, thinking policies can add or manage external authentication sources, when in fact Conditional Access only enforces rules on already-configured providers.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies evaluate sign-in risks and enforce access controls after authentication, but they cannot add or configure social identity providers; they only work with already-configured identity providers. Option C is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory objects to Entra ID, not to sync social account attributes—social identity providers are external and not synced via directory synchronization. Option D is wrong because self-service password reset (SSPR) allows users to reset their own passwords for their Entra ID accounts, but it does not enable sign-in with social media accounts; SSPR is unrelated to external identity provider configuration.

69
MCQhard

A multinational company uses Microsoft Entra ID with Conditional Access policies. They have a policy that requires multi-factor authentication (MFA) for all users when accessing the company's custom SaaS application. However, users from the European branch are reporting that they are prompted for MFA every time, even though they have already authenticated via a compliant device. What is the most likely cause?

A.The user's device is not marked as compliant
B.The user has per-user MFA enabled
C.The Conditional Access policy has a session control that requires sign-in frequency
D.The policy includes a location condition that is not met
AnswerC

Sign-in frequency is a Conditional Access session control that configures how often a user must re-authenticate, regardless of whether their device is compliant. Once the configured time window expires, the session's refresh token is no longer valid for re-authentication, forcing the user to provide MFA again. This exactly matches the reported behavior—repeated MFA prompts on a compliant device—because the policy is not checking device health but enforcing token lifetime limits.

Why this answer

The Conditional Access policy includes a session control that requires sign-in frequency, which forces users to re-authenticate with MFA at a specified interval regardless of device compliance or previous authentication. Even if the device is compliant and the user has already authenticated, the sign-in frequency control overrides session persistence and prompts for MFA again based on the configured time period (e.g., every hour). This explains why European branch users are repeatedly prompted for MFA despite having authenticated via a compliant device.

Exam trap

The trap here is that candidates confuse device compliance with session persistence, assuming that a compliant device automatically prevents repeated MFA prompts, but Conditional Access session controls like sign-in frequency explicitly override that behavior.

How to eliminate wrong answers

Option A is wrong because if the device were not marked as compliant, the policy would block access or require additional controls, but the users are still able to access the application after MFA, indicating the device compliance condition is satisfied. Option B is wrong because per-user MFA is a legacy setting that applies globally to all applications and would not cause repeated prompts only for this specific SaaS application; it would also be overridden by Conditional Access policies. Option D is wrong because a location condition that is not met would typically block access or require additional authentication, not cause repeated MFA prompts after successful authentication from a compliant device.

70
MCQmedium

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that the number of 'Leaked Credentials' detections is high. What action should you take to automatically remediate this risk?

A.Use Microsoft Entra ID Protection to automatically reset passwords for all users with leaked credentials
B.Configure a conditional access policy to block access for users with high user risk
C.Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users
D.Enable Microsoft Entra ID Multifactor Authentication for all users
AnswerC

The correct remediation is to configure a user risk policy in Microsoft Entra ID Protection that assigns 'Require password change' as the access control for high-risk users. When a user is flagged for leaked credentials, this policy forces the user to complete a password change the next time they sign in, which revokes the compromised password and automatically lowers the user's risk back to normal. This is the only built-in, automatically enforced way to remediate leaked credentials in Entra ID.

Why this answer

A user risk policy in Microsoft Entra ID Protection can be configured to automatically trigger a password change when a user is detected as high risk, such as when leaked credentials are identified. This policy directly remediates the risk by forcing the user to update their compromised credentials, effectively invalidating the leaked password. The other options either do not address the root cause or require manual intervention.

Exam trap

The trap here is that candidates often confuse 'automatic password reset' (which is not supported) with 'requiring a password change' (which is supported via a user risk policy), leading them to select Option A instead of C.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection does not support automatic password reset; it can only trigger a password change via a user risk policy, not directly reset passwords. Option B is wrong because blocking access with a conditional access policy does not remediate the leaked credentials; it only prevents access until the risk is manually resolved, leaving the compromised password still active. Option D is wrong because enabling MFA for all users adds an extra layer of security but does not address the fact that the user's password is already leaked; the compromised credential remains valid and could still be used.

71
MCQeasy

You are configuring Microsoft Entra ID provisioning for a SaaS application that supports SCIM 2.0. The app requires the 'manager' attribute to be mapped. However, the manager attribute is not populated for all users. What should you do to avoid provisioning failures?

A.Configure the attribute mapping to 'Ignore it if null' for the manager attribute
B.Modify the SCIM schema in the application to make manager optional
C.Use the expression language to set a default value for the manager attribute
D.Delete the manager attribute mapping from the provisioning configuration
AnswerA

In the Entra ID attribute mapping editor, the 'Ignore it if null' option instructs the provisioning engine to omit the manager attribute from the SCIM request when the source user has no manager set. This prevents the target application from receiving a null value that could fail schema validation or overwrite an existing value with empty data. As a result, users without managers are provisioned successfully, and manager relationships are only updated when a real manager actually exists.

Why this answer

When the 'manager' attribute is not populated for all users, configuring the attribute mapping to 'Ignore it if null' prevents provisioning failures by allowing the provisioning service to skip the attribute when its value is null, rather than attempting to send an empty or invalid value that the SCIM 2.0 endpoint might reject. This setting ensures that only users with a manager value trigger the mapping, avoiding errors for users without a manager.

Exam trap

The trap here is that candidates often confuse 'Ignore it if null' with setting a default value or removing the mapping, but the correct approach is to gracefully skip the null attribute rather than force a value or delete the mapping entirely.

How to eliminate wrong answers

Option B is wrong because modifying the SCIM schema in the application to make manager optional is typically not under your control—the SaaS application defines its SCIM schema, and you cannot alter it from Microsoft Entra ID. Option C is wrong because using expression language to set a default value for the manager attribute would assign a static value (e.g., 'Unknown') to users without a manager, which could cause incorrect data or provisioning failures if the application expects a valid manager reference. Option D is wrong because deleting the manager attribute mapping entirely would remove the attribute from provisioning, which might violate the application's required schema or business logic, and it does not address the need to handle null values gracefully.

72
MCQeasy

Your organization is implementing a hybrid identity solution. You want to synchronize on-premises Active Directory users to Microsoft Entra ID. Which tool should you use?

A.Microsoft Identity Manager
B.Microsoft Entra Cloud Sync
C.Microsoft Entra Connect Sync
D.Microsoft Entra Connect
AnswerD

Microsoft Entra Connect is the correct tool for a hybrid identity solution because it provides a single, unified sync engine that connects on-premises Active Directory with Microsoft Entra ID. It supports essential features such as password hash sync, pass-through authentication, single sign-on, and optional federation to deliver a seamless hybrid experience. For most organizations, this is the recommended and fully supported path to implement hybrid identity.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) is the correct tool for synchronizing on-premises Active Directory users to Microsoft Entra ID in a hybrid identity solution. It supports both password hash synchronization, pass-through authentication, and federation with Active Directory Federation Services (AD FS), making it the primary and most feature-rich sync tool for complex hybrid environments.

Exam trap

The trap here is that candidates confuse 'Microsoft Entra Connect Sync' (the sync engine component) with the full 'Microsoft Entra Connect' tool, or they incorrectly assume 'Cloud Sync' is sufficient for all hybrid scenarios despite its missing writeback and federation capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution for managing identities across heterogeneous systems, not a dedicated sync tool for Microsoft Entra ID; it requires additional configuration and is not the recommended tool for standard hybrid sync. Option B is wrong because Microsoft Entra Cloud Sync is a lightweight agent designed for syncing from a single on-premises forest to Entra ID, but it lacks support for advanced features like device writeback, group writeback, and hybrid Azure AD join, making it unsuitable for a full hybrid identity implementation. Option C is wrong because Microsoft Entra Connect Sync is not a distinct product; it is the sync engine component within Microsoft Entra Connect, and the question asks for the tool itself, not a subcomponent.

73
Multi-Selectmedium

Which TWO Microsoft Entra ID features can be used to provide just-in-time (JIT) access to privileged roles?

Select 2 answers
A.Identity Protection
B.Privileged Identity Management (PIM)
C.Conditional Access
D.Access Reviews
E.Privileged Access Groups
AnswersB, E

Privileged Identity Management (PIM) is the primary Microsoft Entra ID service for just-in-time (JIT) access, enabling users to activate eligible role assignments for a limited time with justification and optional approval. During activation, the role is temporarily added to the user's list of active assignments, and after the maximum duration (for example, 8 hours) it automatically expires. PIM also provides audit history and alerts for activations, making it the correct answer for time-bound role elevation.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) access by allowing users to activate eligible role assignments for a limited time, with approval workflows and auditing. Privileged Access Groups extend JIT capabilities by enabling time-bound membership in groups that grant access to Azure AD roles or Azure resources, ensuring temporary elevation only when needed.

Exam trap

The trap here is that candidates confuse Access Reviews (a recertification tool) with JIT activation, or think Conditional Access can provide time-bound role elevation when it only controls access to apps, not role assignments.

74
MCQmedium

Your organization plans to allow external users to access a SharePoint Online site using their own Microsoft Entra ID credentials. You need to ensure that external users can authenticate without creating a guest account in your tenant. Which solution should you use?

A.Configure B2B collaboration
B.Create external users as members
C.Configure B2B direct connect
D.Use Microsoft Entra Verified ID
AnswerC

Configure B2B direct connect – incorrect because this feature is limited to Teams Connect shared channels and does not support SharePoint Online site access.

Why this answer

Microsoft Entra B2B direct connect allows users from another Microsoft Entra tenant to access SharePoint Online sites and OneDrive using their own home tenant credentials without creating guest accounts in your tenant. It is configured through cross-tenant access settings and supports SharePoint Online and OneDrive in addition to Teams shared channels. B2B collaboration (A) creates guest user objects in your tenant, so it does not meet the requirement.

Creating external users as members (B) also provisions user objects in the tenant. Microsoft Entra Verified ID (D) is a decentralized identity verification service and does not by itself grant external users access to SharePoint Online without a guest account.

Exam trap

The trap is assuming B2B direct connect only works for Teams Connect shared channels. In current Microsoft Entra and SharePoint Online, B2B direct connect also supports SharePoint and OneDrive access without guest accounts. Another trap is selecting Microsoft Entra Verified ID, which is for identity verification, not for cross-tenant SharePoint authentication.

How to eliminate wrong answers

Option A is wrong because B2B collaboration requires creating guest user objects in your tenant to represent external users, which contradicts the requirement to avoid guest accounts. Option B is wrong because creating external users as members still involves provisioning user objects in your tenant, and it does not leverage the external user's own Microsoft Entra ID credentials for direct authentication. Option D is wrong because Microsoft Entra Verified ID is a decentralized identity verification solution using verifiable credentials, not designed for direct authentication to SharePoint Online without guest accounts.

75
MCQeasy

Refer to the exhibit. You are configuring permissions for a daemon application that runs without a user. Which permission should you request?

A.User.Read.All application permission with admin consent.
B.Mail.Read delegated permission with admin consent.
C.Delegated permission type for User.Read.All.
D.User.Read.All delegated permission with user consent.
AnswerA

In an app-only daemon flow, the client authenticates with its own credentials and has no signed-in user, so the application permission is the only usable type. The exhibit shows User.Read.All with type 'Application' and adminConsentRequired true, indicating the tenant admin must consent because this scope can read every user's profile. This exactly matches the requirement for the background service.

Why this answer

For a daemon application that runs without a user, you must request an application permission (not delegated) because there is no signed-in user to delegate permissions. User.Read.All application permission allows the app to read all users' full profiles without a user context, and admin consent is required because this permission grants access to data across the entire organization.

Exam trap

The trap here is that candidates often confuse delegated and application permissions, assuming admin consent alone makes a delegated permission suitable for a daemon app, but delegated permissions always require a user context even with admin consent.

How to eliminate wrong answers

Option B is wrong because Mail.Read delegated permission requires a signed-in user context, which a daemon application does not have; delegated permissions are for user-interactive apps. Option C is wrong because Delegated permission type for User.Read.All still requires a user to be present, and the question specifies the app runs without a user. Option D is wrong because User.Read.All delegated permission with user consent cannot be used by a daemon app (no user to consent) and delegated permissions are inappropriate for non-interactive scenarios.

Page 1 of 2 · 129 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Implement and manage Microsoft Entra identity and access questions.