Courseiva

CCNA Implement and manage Microsoft Entra identity and access Questions

54 of 129 questions · Page 2/2 · Implement and manage Microsoft Entra identity and access · Answers revealed

76
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra Connect. You are planning to migrate to cloud-only authentication using Microsoft Entra Cloud Sync. However, some legacy applications still require NTLM authentication. What should you do to ensure those applications can authenticate after the migration?

A.Use Microsoft Entra Application Proxy to publish the legacy applications
B.Enable pass-through authentication (PTA)
C.Configure Microsoft Entra Cloud Sync with password hash sync
D.Deploy Microsoft Entra Password Protection
AnswerA

Microsoft Entra Application Proxy publishes legacy on-premises applications through a cloud entry point, and after the user authenticates to Microsoft Entra ID, the connector uses Kerberos Constrained Delegation (KCD) to communicate with the back-end application using NTLM or Kerberos. This provides true single sign-on for legacy apps that require integrated Windows authentication without modifying the application code. It is the only option here that actually relays the app-level authentication protocol.

Why this answer

Microsoft Entra Application Proxy allows you to publish on-premises legacy applications that rely on NTLM authentication without requiring any changes to the application itself. It acts as a reverse proxy, terminating the external connection and then forwarding the request to the internal application using Kerberos or NTLM, thus enabling cloud-only authentication while preserving NTLM support for legacy apps.

Exam trap

The trap here is that candidates often confuse authentication methods (like PTA or PHS) with application publishing solutions, mistakenly thinking that changing the authentication flow itself will fix legacy app compatibility, when in fact a reverse proxy like Application Proxy is required to relay NTLM traffic.

How to eliminate wrong answers

Option B is wrong because pass-through authentication (PTA) is an authentication method for validating user passwords against on-premises Active Directory, but it does not provide a mechanism to publish or proxy legacy NTLM-based applications; it only handles user sign-in. Option C is wrong because Microsoft Entra Cloud Sync with password hash sync synchronizes password hashes to the cloud for cloud authentication, but it does not enable legacy applications to continue using NTLM after migration; those apps still need a way to receive NTLM requests from external users. Option D is wrong because Microsoft Entra Password Protection is a feature to block weak passwords and enforce custom banned password lists; it has no role in enabling NTLM authentication for legacy applications.

77
MCQeasy

You are implementing Microsoft Entra ID Governance. You need to automate the creation of guest user accounts when employees submit a request through the company's HR system. What should you use?

A.Microsoft Entra Verified ID
B.Access Reviews
C.Microsoft Entra ID Protection
D.Lifecycle Workflows
AnswerD

Lifecycle Workflows in Microsoft Entra ID Governance are specifically designed to automate identity lifecycle tasks, including the creation of guest user accounts. They can be configured with custom execution conditions or triggered programmatically via API, enabling integration with external systems like an HR system. This allows for the automated provisioning of guest accounts precisely when an employee request is submitted through the HR system, satisfying the need for automated, event-driven account creation.

Why this answer

Lifecycle Workflows (D) is the correct choice because it is the Microsoft Entra ID Governance feature designed to automate identity lifecycle processes, including the creation of guest user accounts triggered by events such as HR system submissions. It uses built-in or custom workflows with tasks like 'Create user' and 'Send email' to handle the entire provisioning flow without manual intervention.

Exam trap

The trap here is that candidates often confuse Lifecycle Workflows with Access Reviews or ID Protection because all three fall under 'Identity Governance', but only Lifecycle Workflows provides the actual provisioning automation for HR-driven account creation.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Verified ID is a decentralized identity verification solution using verifiable credentials (based on W3C standards), not an automation tool for creating guest accounts from HR triggers. Option B is wrong because Access Reviews are used for periodic attestation and recertification of existing access rights, not for provisioning new accounts. Option C is wrong because Microsoft Entra ID Protection focuses on detecting and mitigating identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not include workflow automation for user creation.

78
MCQmedium

Your company uses Microsoft Entra ID and has a custom line-of-business application that supports SAML-based SSO. You need to configure the application to use Microsoft Entra ID as the identity provider. Which enterprise application configuration should you use?

A.Linked Sign-on
B.SAML-based Sign-on
C.Password-based Sign-on
D.OpenID Connect-based Sign-on
AnswerB

SAML-based Sign-on is correct because it enables true federated single sign-on between Microsoft Entra ID and a custom application that supports the SAML 2.0 standard. Entra ID acts as the identity provider, authenticates the user, and sends a digitally signed SAML assertion to the app's ACS (Assertion Consumer Service) URL, allowing the app to trust the assertion without prompting for credentials again. This is the recommended SSO method for non-gallery enterprise applications, especially older line-of-business apps that lack support for modern OAuth/OIDC protocols.

Why this answer

The application supports SAML-based SSO, so the correct enterprise application configuration is SAML-based Sign-on. This allows Microsoft Entra ID to act as the identity provider by exchanging SAML assertions with the application, enabling federated authentication.

Exam trap

The trap here is that candidates may confuse SAML-based Sign-on with OpenID Connect because both are federated protocols, but the question explicitly states the application supports SAML, not OIDC.

How to eliminate wrong answers

Option A is wrong because Linked Sign-on is used to link an existing user account in an external identity provider to Microsoft Entra ID, not to configure SAML-based SSO. Option C is wrong because Password-based Sign-on uses a password vaulting approach where Microsoft Entra ID stores and replays credentials, which does not leverage SAML assertions. Option D is wrong because OpenID Connect-based Sign-on is built on OAuth 2.0 and uses ID tokens (JWT) instead of SAML assertions, making it incompatible with an application that specifically supports SAML-based SSO.

79
MCQmedium

You are a Microsoft 365 administrator. You run the Get-MgPolicyCrossTenantAccessPolicyDefault cmdlet and see the exhibit output. What does this configuration imply?

A.Your tenant will accept compliant device claims from external tenants
B.Your tenant will accept MFA claims from a specific partner tenant
C.Your tenant will accept MFA claims from all external Microsoft Entra tenants
D.Your tenant blocks all inbound B2B collaboration
AnswerC

This is correct. The default cross-tenant access policy you retrieved shows IsMfaAccepted equal to true, so your tenant will trust the MFA claim for external users from any Microsoft Entra tenant when they access your resources. With this setting, Azure AD Conditional Access treats the external user as having completed MFA in their home tenant, reducing friction while still enabling security policies.

Why this answer

The Get-MgPolicyCrossTenantAccessPolicyDefault cmdlet retrieves the default cross-tenant access policy settings. The exhibit output shows that the InboundTrust property is configured to accept MFA claims from all external Microsoft Entra tenants, meaning your tenant will trust MFA claims made by users from any external Entra tenant without requiring them to re-authenticate.

Exam trap

The trap here is confusing the default cross-tenant access policy (which applies to all external tenants) with partner-specific policies, leading candidates to incorrectly select a specific partner option when the default policy is being examined.

How to eliminate wrong answers

Option A is wrong because accepting compliant device claims requires the 'IsCompliantDevice' flag to be set in the InboundTrust property, which is not indicated in the exhibit. Option B is wrong because the default policy applies to all external tenants, not a specific partner tenant; specific partner tenant settings are configured via the Get-MgPolicyCrossTenantAccessPolicyPartner cmdlet. Option D is wrong because the exhibit does not show any block settings; blocking inbound B2B collaboration would require the B2B direct connect or B2B collaboration inbound settings to be set to 'blocked', which is not the case here.

80
MCQhard

Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?

A.The B2BCollaborationOutbound setting is blocking access
B.The default cross-tenant access policy is set to block all
C.The B2BCollaborationInbound setting for Fabrikam does not allow any identities or applications
D.The B2BDirectConnectInbound setting is empty
AnswerC

The B2BCollaborationInbound section for Fabrikam is the exact place where Contoso must explicitly allow Fabrikam users, groups, and applications to participate in B2B collaboration. When this inbound section contains no entries at all, Microsoft Entra ID treats it as an implicit deny: no Fabrikam identities are authorized to be invited as B2B guests, and no Contoso applications are available for them to access. Because the exhibit shows an empty inbound B2B collaboration policy for Fabrikam, it actively blocks the invitation and sign-in flow for those external users, which directly causes the reported access failure.

Why this answer

The B2BCollaborationInbound setting for Fabrikam controls which external users and applications are allowed to access Contoso resources via B2B collaboration. If this setting does not allow any identities or applications, all inbound B2B collaboration attempts from Fabrikam will be blocked, even if the default cross-tenant access policy is permissive.

Exam trap

The trap here is that candidates confuse inbound vs. outbound settings or assume the default policy applies to explicitly configured tenants, when in fact a specific tenant policy overrides the default for that tenant.

How to eliminate wrong answers

Option A is wrong because the B2BCollaborationOutbound setting controls traffic leaving Contoso to Fabrikam, not inbound access from Fabrikam to Contoso. Option B is wrong because the default cross-tenant access policy applies to tenants not explicitly configured; since Fabrikam has a specific policy, the default policy does not apply. Option D is wrong because B2BDirectConnectInbound is used for Teams external access and shared channels, not for B2B collaboration invitations or resource access.

81
Multi-Selectmedium

Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant authentication for all users when accessing the Azure Management application. Which TWO authentication methods satisfy the requirement?

Select 2 answers
A.SMS one-time passcode
B.Windows Hello for Business
C.Microsoft Authenticator with number matching
D.FIDO2 security key
E.Voice call verification code
AnswersB, D

Windows Hello for Business implements the FIDO2 protocol to provide device-bound cryptographic credentials, with the private key stored in the TPM of the enrolled device. It requires something you have (device with TPM) and something you know (PIN) or are (biometrics), satisfying true multi-factor authentication. Because the key never leaves the device and the challenge is scoped to the specific resource, it resists phishing and credential replay attacks, making it a strong conditional-access authentication method.

Why this answer

Windows Hello for Business is a phishing-resistant authentication method because it uses a key pair bound to the device, requiring a biometric or PIN gesture that cannot be intercepted or replayed. It satisfies the Conditional Access requirement for phishing-resistant authentication when accessing the Azure Management application.

Exam trap

The trap here is that candidates often confuse 'strong authentication' (like number matching or OTP) with 'phishing-resistant' authentication, but only methods using asymmetric key cryptography bound to the device (Windows Hello for Business and FIDO2) meet the strict phishing-resistant definition under Microsoft's Conditional Access policies.

82
MCQmedium

Refer to the exhibit. You are configuring consent for the Microsoft Graph application. Which of the following statements is true based on the JSON?

A.Users can consent to the User.Read.All permission.
B.The Mail.Read permission requires admin consent.
C.No consent is required for either permission.
D.The User.Read.All permission requires admin consent.
AnswerD

This is correct because the JSON entry for User.Read.All shows adminConsentRequired: true and userConsentPossible: false. User.Read.All grants access to every user's full profile across the organization, a high-privilege scope that Microsoft mandates be approved by an administrator to prevent lateral data exposure. A regular user cannot see an admin consent prompt or grant this permission, so tenant-wide admin consent is mandatory.

Why this answer

The JSON shows the User.Read.All permission has the 'AdminConsentRequired' property set to true, meaning it requires admin consent. The Mail.Read permission has 'AdminConsentRequired' set to false, so users can consent to it without admin involvement. Option D correctly identifies that User.Read.All requires admin consent.

Exam trap

The trap here is that candidates often assume all permissions with 'Read' in the name are user-consentable, but Microsoft marks permissions that access data across the entire organization (like User.Read.All) as requiring admin consent, while user-scoped reads (like Mail.Read) may not.

How to eliminate wrong answers

Option A is wrong because User.Read.All has 'AdminConsentRequired' set to true, so users cannot consent to it; admin consent is mandatory. Option B is wrong because Mail.Read has 'AdminConsentRequired' set to false, meaning it does not require admin consent; users can consent on their own. Option C is wrong because User.Read.All requires admin consent, so consent is required for at least one permission.

83
MCQhard

Refer to the exhibit. The conditional access policy JSON shown above is applied to all users. A user authenticates from a trusted location and wants to access a cloud app. Which combination of controls will be enforced?

A.MFA, terms of use acceptance, sign-in frequency of 1 hour, and persistent browser never
B.Terms of use acceptance and persistent browser never only
C.MFA and terms of use acceptance only
D.MFA and sign-in frequency of 1 hour only
AnswerA

Despite the user authenticating from a trusted location, the conditional access policy's configuration dictates the enforced controls. The policy must explicitly include Multi-Factor Authentication (MFA) and terms of use acceptance within its grant controls, meaning these are required regardless of the trusted location status. Furthermore, the policy's session controls specify a sign-in frequency of 1 hour and persistent browser set to 'never', ensuring re-authentication and session termination after the specified period.

Why this answer

The conditional access policy JSON explicitly defines three grant controls: 'mfa' (require multi-factor authentication), 'termsOfUse' (require terms of use acceptance), and 'signInFrequency' (value 3600 seconds = 1 hour) combined with 'persistentBrowser' set to 'never'. Since the policy is applied to all users and the user authenticates from a trusted location, all specified controls are enforced simultaneously, as conditional access policies apply all grant controls in the 'grantControls' block unless overridden by session controls.

Exam trap

The trap here is that candidates often assume session controls (like sign-in frequency and persistent browser) are optional or ignored when grant controls are present, but in reality, all controls in both 'grantControls' and 'sessionControls' are enforced together unless explicitly conditional.

How to eliminate wrong answers

Option B is wrong because it omits the MFA requirement and the sign-in frequency control, both of which are explicitly listed in the JSON's 'grantControls' array. Option C is wrong because it ignores the 'signInFrequency' (value 3600 seconds) and 'persistentBrowser' (set to 'never') session controls, which are part of the policy's 'sessionControls' object and are enforced alongside grant controls. Option D is wrong because it omits the 'termsOfUse' grant control, which is included in the 'builtInControls' array as 'termsOfUse', and also ignores the 'persistentBrowser' session control.

84
MCQmedium

Your organization uses Microsoft Entra ID and requires users to authenticate using FIDO2 security keys. You need to ensure that users can register and manage their security keys through the My Security Info portal. Which authentication method policy setting should you enable?

A.Temporary Access Pass
B.Certificate-based authentication
C.Security keys (FIDO2)
D.Microsoft Authenticator
AnswerC

Security keys (FIDO2) is the correct method because Microsoft Entra ID's 'Security Keys (FIDO2)' policy specifically enables users to register a FIDO2 security key in the My Security Info portal. FIDO2 keys are hardware-based, phishing-resistant authenticators that generate a WebAuthn credential bound to the specific key and device. This policy is what appears in the Microsoft Entra admin center under Authentication methods, and it must be enabled for deploying FIDO2 passwordless sign-in for a defined user group.

Why this answer

The Security keys (FIDO2) authentication method policy must be enabled to allow users to register and manage FIDO2 security keys through the My Security Info portal. This policy controls the registration, key restrictions, and user targeting for FIDO2 authentication in Microsoft Entra ID, directly enabling the self-service management experience.

Exam trap

The trap here is that candidates confuse the authentication method policy that enables the feature (Security keys FIDO2) with the method used to authenticate after registration (like Microsoft Authenticator or Certificate-based authentication), leading them to pick an option that supports a different passwordless flow.

How to eliminate wrong answers

Option A is wrong because Temporary Access Pass is a time-limited passcode used for passwordless onboarding or recovery, not for registering or managing FIDO2 security keys. Option B is wrong because Certificate-based authentication (CBA) uses X.509 certificates for authentication, not FIDO2 security keys, and its policy does not control FIDO2 key registration. Option D is wrong because Microsoft Authenticator is a separate authentication method for phone sign-in or OTP, and its policy does not govern FIDO2 security key registration or management.

85
MCQmedium

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. Users report that they are frequently prompted for multi-factor authentication (MFA) even after signing in successfully. You want to minimize these prompts while maintaining security. What should you configure?

A.Configure Authentication Session Management
B.Modify the Conditional Access policy to require MFA for all apps
C.Change the per-user MFA state to Disabled
D.Adjust Identity Protection user risk policy
AnswerA

Configuring Authentication Session Management within a Conditional Access policy allows you to set sign-in frequency (for example, every 12 hours) and persistent browser sessions. This controls the token lifetime so that users are not repeatedly prompted for MFA within the defined window, directly reducing authentication prompts while retaining security.

Why this answer

Configuring Authentication Session Management in a Conditional Access policy allows you to control how often users are prompted for MFA by setting the sign-in frequency (e.g., every 24 hours) or persistent browser session (e.g., 'Remember MFA for 14 days'). This directly addresses the user complaint of frequent MFA prompts while maintaining security by enforcing reauthentication at defined intervals.

Exam trap

The trap here is that candidates confuse session controls (which manage MFA prompt frequency) with risk-based policies or per-user MFA states, assuming that disabling MFA or modifying risk policies will reduce prompts, when in fact session management is the precise control for this scenario.

How to eliminate wrong answers

Option B is wrong because requiring MFA for all apps would increase the frequency of MFA prompts, not minimize them, and it does not address session persistence. Option C is wrong because disabling per-user MFA would eliminate MFA entirely, compromising security, and it does not control session lifetime. Option D is wrong because Identity Protection user risk policy triggers MFA based on risk level (e.g., medium/high user risk), which is unrelated to session duration and would not reduce prompts for low-risk users.

86
MCQmedium

You are designing a Microsoft Entra ID tenant for a new subsidiary. You need to ensure that users can authenticate using their existing on-premises Active Directory credentials without synchronizing password hashes to the cloud. Which identity model should you choose?

A.Federation with AD FS
B.Cloud-only identity
C.Pass-through authentication (PTA)
D.Password hash synchronization (PHS)
AnswerC

Pass-through authentication (PTA) is correct because it validates user passwords directly against on-premises Active Directory at sign-in time without ever storing password hashes in the cloud. PTA uses a lightweight agent installed on an on-premises server that receives authentication requests from Entra ID and validates them against the local domain controller. This gives organizations the benefit of cloud-based authentication while preserving on-premises password policies, account states, and lockout settings, and avoids the cloud hash storage that would otherwise be introduced.

Why this answer

Pass-through authentication (PTA) allows users to authenticate against on-premises Active Directory directly, without synchronizing password hashes to the cloud. When a user signs in to Microsoft Entra ID, the authentication request is forwarded to an on-premises PTA agent, which validates the credentials against the local domain controller. This meets the requirement of using existing on-premises credentials without storing password hashes in the cloud.

Exam trap

The trap here is that candidates often confuse federation (AD FS) with pass-through authentication, assuming that only federation can avoid password hash sync, but PTA also avoids hash sync while being simpler to deploy and manage.

How to eliminate wrong answers

Option A is wrong because federation with AD FS requires an on-premises federation server and still does not synchronize password hashes, but it introduces additional complexity and is not the simplest solution for direct password validation without hash sync. Option B is wrong because cloud-only identity creates accounts entirely in Microsoft Entra ID with passwords stored in the cloud, which does not use existing on-premises Active Directory credentials. Option D is wrong because password hash synchronization (PHS) explicitly synchronizes password hashes from on-premises AD to Microsoft Entra ID, which violates the requirement to avoid synchronizing password hashes.

87
MCQmedium

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can reset their own passwords without administrator intervention, but only if they have registered for self-service password reset (SSPR). What should you configure?

A.Enable SSPR for a selected security group containing registered users
B.Configure a conditional access policy requiring admin approval for password changes
C.Configure Microsoft Entra ID Protection user risk policy
D.Enable SSPR for All users
AnswerA

This is correct because SSPR can be scoped to a selected Microsoft Entra (Azure AD) security group, and by populating that group only with users who have already completed SSPR registration (e.g., set up phone, email, or authenticator methods), you ensure that password reset is available only to those pre-registered users. This gives you precise control and meets the 'registered users only' requirement. As a best practice, you would maintain that group dynamic or assigned to reflect the registered-user population, and combine it with the 'Registration required' setting to keep the allowlist accurate.

Why this answer

Enabling SSPR for a selected security group ensures that only users who have been explicitly added to that group (and thus have registered for SSPR) can reset their own passwords without administrator intervention. This meets the requirement of restricting self-service password reset to registered users only, while still allowing password changes without admin approval.

Exam trap

The trap here is that candidates often confuse enabling SSPR for 'All users' as the simplest way to meet the requirement, overlooking the explicit condition that only registered users should be allowed to reset passwords, which requires scoping to a security group containing those registered users.

How to eliminate wrong answers

Option B is wrong because configuring a conditional access policy requiring admin approval for password changes would prevent users from resetting their own passwords without administrator intervention, directly contradicting the requirement. Option C is wrong because Microsoft Entra ID Protection user risk policy is designed to automatically respond to risky user behavior (e.g., by blocking sign-in or requiring MFA), not to enable or restrict self-service password reset. Option D is wrong because enabling SSPR for All users would allow any user, including those who have not registered for SSPR, to reset their passwords, which does not meet the requirement that only registered users can reset their passwords.

88
MCQhard

Your organization uses Microsoft Entra ID with Application Proxy to publish on-premises web apps. Users report that they are prompted for credentials multiple times when accessing an app. You need to reduce the number of authentication prompts. What should you configure?

A.Enable Azure MFA for the application
B.Disable pre-authentication for the application
C.Increase the session lifetime in conditional access
D.Enable Kerberos Constrained Delegation (KCD) for single sign-on
AnswerD

Enabling Kerberos Constrained Delegation (KCD) is the correct approach for single sign-on to a legacy on-premises application published through Application Proxy. After the user authenticates to Entra ID, the Application Proxy connector uses the user's token to obtain a Kerberos service ticket from on-premises Active Directory on behalf of the user, then presents that ticket to the backend application. This avoids a second credential prompt because the backend app sees an already authenticated user. KCD requires the application to support Windows Integrated Authentication and careful SPN configuration, but it delivers true SSO without extra MFA prompts or session-lengthening workarounds.

Why this answer

The multiple authentication prompts indicate that the Application Proxy is not passing the user's credentials seamlessly to the on-premises app. Enabling Kerberos Constrained Delegation (KCD) allows the Application Proxy connector to impersonate the user and obtain a Kerberos ticket for the backend application, enabling single sign-on (SSO) and eliminating repeated credential prompts.

Exam trap

The trap here is that candidates often confuse session lifetime settings (Option C) with SSO configuration, thinking that extending session duration will reduce prompts, when in fact the issue is the lack of credential delegation between the proxy and the backend app.

How to eliminate wrong answers

Option A is wrong because enabling Azure MFA would add an additional authentication factor, increasing the number of prompts rather than reducing them. Option B is wrong because disabling pre-authentication would bypass Microsoft Entra ID authentication entirely, exposing the app to the internet without Entra ID protection, and would not resolve the multiple prompts caused by missing SSO. Option C is wrong because increasing the session lifetime in Conditional Access only extends how long a session remains valid before re-authentication is required; it does not address the root cause of repeated prompts within a single session due to lack of SSO.

89
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy JSON. The policy is intended to block legacy authentication. However, users are still able to connect using Exchange ActiveSync. What is the most likely reason?

A.The policy is missing the 'browser' and 'mobileAppsAndDesktopClient' client app types
B.The grant control operator 'OR' should be 'AND'
C.The policy is configured in 'report-only' mode instead of 'enforce'
D.The policy is missing a condition for 'device platforms' to target iOS and Android
AnswerC

If the policy is in report-only mode, it will not enforce the block, allowing legacy connections to succeed. This is the most likely reason.

Why this answer

The policy is configured in 'report-only' mode. In report-only mode, Conditional Access policies are evaluated but not enforced. Users can still connect using legacy authentication because the policy does not block access.

To block legacy authentication, the policy must be set to 'enforce' mode. Additionally, the client apps condition should include 'Exchange ActiveSync clients' and 'Other clients' to specifically target legacy authentication protocols.

Exam trap

A common trap is that candidates mistake report-only mode for enforcement. Report-only mode is used for testing and does not block access. Always verify the policy mode when troubleshooting Conditional Access policy effects.

How to eliminate wrong answers

Option B is wrong because the grant control operator 'OR' vs 'AND' affects how multiple controls are evaluated (e.g., require MFA or require compliant device), but it does not impact whether the policy applies to legacy authentication; the issue is the missing client app types, not the logical operator. Option C is wrong because 'report-only' mode logs the policy result without blocking, but the question states users are still able to connect, which could occur in report-only mode; however, the most likely reason is the missing client app types, as report-only mode would still show the policy applying in logs, whereas the described behavior suggests the policy is not being evaluated at all. Option D is wrong because device platform conditions (e.g., iOS, Android) are optional and not required to block legacy authentication; legacy authentication blocking depends on client app types, not device platforms.

90
MCQeasy

Your organization uses Microsoft 365 Business Premium with Microsoft Entra ID P1. You have 200 users. You need to enforce multi-factor authentication (MFA) for all users accessing the company's CRM application, which is a third-party SaaS app integrated via SAML. The CRM app does not support modern authentication protocols. You want to use a Microsoft solution that does not require additional licenses. What should you use?

A.Enable security defaults in Microsoft Entra ID.
B.Deploy Microsoft Entra application proxy for the CRM app.
C.Configure per-user MFA for users of the CRM app.
D.Create a Conditional Access policy targeting the CRM application and require MFA.
AnswerD

Create a Conditional Access policy that targets the CRM application and requires MFA provides exactly the app-level scoping you need. Conditional Access policies can be assigned to a specific cloud/SaaS application, and when a user accesses that app, the policy evaluates signals and enforces MFA only for that application. Microsoft 365 Business Premium includes Microsoft Entra ID P1, which gives you the license rights to use Conditional Access, making this the correct, modern approach.

Why this answer

Conditional Access policies in Microsoft Entra ID P1 allow you to target specific cloud applications (including third-party SAML-integrated SaaS apps) and enforce MFA. Since the CRM app does not support modern authentication protocols, Conditional Access can still enforce MFA by requiring a compliant domain-joined device or by using app-enforced restrictions; however, the key is that Conditional Access works at the authentication plane and can require MFA even for legacy apps when combined with a capable authentication method like a one-time passcode or Microsoft Authenticator. This solution uses existing Microsoft Entra ID P1 licensing without additional costs.

Exam trap

The trap here is that candidates assume per-user MFA (Option C) is the only way to enforce MFA for legacy apps, but Conditional Access policies in Microsoft Entra ID P1 can target specific SAML-integrated apps and enforce MFA without requiring modern authentication protocols on the app side.

How to eliminate wrong answers

Option A is wrong because security defaults enforce MFA for all users but cannot be scoped to a specific application like the CRM app; they apply globally to all cloud apps and break if you need granular control. Option B is wrong because Microsoft Entra application proxy is designed for publishing on-premises web apps externally, not for enforcing MFA on a third-party SaaS app that is already integrated via SAML. Option C is wrong because per-user MFA is a legacy approach that requires manual configuration and does not support targeting a specific application; it also lacks the granularity and reporting of Conditional Access and is not recommended for modern deployments.

91
MCQhard

Your organization has a hybrid identity deployment using Microsoft Entra Connect Sync. You need to ensure that password writeback is enabled so that users can reset their own passwords from the cloud. Which prerequisite must be met?

A.Self-Service Password Reset (SSPR) must be enabled in Microsoft Entra ID
B.Password hash synchronization must be enabled
C.Azure MFA must be enabled for all users
D.Microsoft Entra ID P2 licenses must be assigned
AnswerA

Enabling Self-Service Password Reset (SSPR) in Microsoft Entra ID is the controlling service that invokes password writeback. When a user resets a forgotten password through the SSPR portal, the cloud tenant calls back to the on-premises directory via the Microsoft Entra Connect sync engine, and only if SSPR is toggled on with the writeback option does the tenant pass the new password value back to the local Active Directory domain. Thus, without SSPR enabled and configured, there is no cloud-side operation to trigger the writeback service, regardless of how the on-premises sync is set up.

Why this answer

Password writeback requires that Self-Service Password Reset (SSPR) is enabled in Microsoft Entra ID because writeback is a feature of SSPR that allows password changes initiated in the cloud to be written back to the on-premises Active Directory. Without SSPR enabled, the cloud tenant has no mechanism to trigger the writeback operation, even if the Entra Connect Sync configuration is correct.

Exam trap

The trap here is that candidates often assume password hash synchronization must be enabled for any password-related feature, but password writeback is a separate SSPR function that does not depend on hash sync and can be used with other authentication methods.

How to eliminate wrong answers

Option B is wrong because password hash synchronization is not a prerequisite for password writeback; writeback works independently of hash sync and can be used with federation or pass-through authentication. Option C is wrong because Azure MFA is not a prerequisite for password writeback; MFA can be used as an additional security layer for SSPR but is not required for the writeback feature itself. Option D is wrong because Microsoft Entra ID P2 licenses are not required for password writeback; SSPR with writeback is available with Microsoft Entra ID P1 licenses, though P2 adds additional identity protection features.

92
Multi-Selecthard

You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement access reviews for privileged roles. They want to ensure that access reviews are conducted quarterly and that reviewers must provide a justification for their decision. You need to configure the access review. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the access review to automatically apply results.
B.Set the recurrence of the access review to quarterly.
C.Enable 'Require justification on approval' in the access review settings.
D.Enable 'Require MFA to approve' in the access review settings.
E.Set the reviewers to be the users themselves.
AnswersB, C

The access review schedule includes recurrence settings. Setting it to quarterly ensures reviews occur every three months, meeting the requirement. Recurrence can be set to weekly, monthly, quarterly, semi-annually, or annually. This directly addresses the quarterly requirement.

Why this answer

To meet the requirements, you need to set the access review recurrence to quarterly and enable the option that requires reviewers to provide a justification when approving. These two settings ensure the review happens every three months and that reviewers must justify their decisions. Other settings like auto-apply or self-review do not address justification.

Exam trap

The trap here is assuming that auto-apply or MFA settings within access reviews enforce justification, when actually justification is a separate toggle.

93
MCQmedium

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?

A.Password Hash Synchronization (PHS)
B.Pass-through Authentication with Seamless SSO
C.Active Directory Federation Services (AD FS)
D.Install Azure AD Connect with default settings
AnswerB

Pass-through Authentication with Seamless SSO is not the best option because it uses lightweight agents on-premises to validate passwords directly against Active Directory in real time, rather than synchronizing any password hash to Entra ID. While PTA avoids storing password hashes in the cloud, it introduces a dependency on on-premises agent availability, requires agent high availability planning, and Seamless SSO only provides silent sign-in on domain-joined devices. For a simple migration to cloud authentication, PTA is operationally more complex than PHS and does not allow cloud-based sign-in if the on-premises directory becomes unreachable.

Why this answer

Pass-through Authentication (PTA) validates passwords directly against on-premises Active Directory, ensuring that on-premises password policies (complexity, expiration, lockout) are enforced for cloud sign-ins. PHS merely synchronizes password hashes to Entra ID and cannot enforce on-premises lockout or account state at authentication time.

Exam trap

The trap is that candidates may think PHS is sufficient because it uses the same password, but the requirement to maintain on-premises policy enforcement during logon points to PTA, not PHS. Seamless SSO is optional and not the deciding factor.

How to eliminate wrong answers

Option B is wrong because Pass-through Authentication with Seamless SSO validates passwords directly against on-premises Active Directory without storing password hashes in the cloud, but it does not maintain password policy enforcement on-premises in a way that differs from PHS—it still relies on on-premises policy, but the question specifically asks for a feature that ensures users can use existing passwords while maintaining on-premises policy enforcement, and PHS is the simplest and most direct solution. Option C is wrong because Active Directory Federation Services (AD FS) is a federation service that redirects authentication to on-premises servers, which adds complexity and requires high-availability infrastructure; it is not the simplest or most appropriate choice when the goal is to use existing passwords without additional federation overhead. Option D is wrong because installing Azure AD Connect with default settings does not automatically enable password synchronization; the default settings only synchronize directory objects, and you must explicitly select the Password Hash Synchronization option to achieve the described goal.

94
MCQmedium

You need to configure Microsoft Entra ID to allow users to authenticate using their existing social media accounts. Which identity provider type should you add?

A.OpenID Connect identity provider
B.Google identity provider
C.Microsoft account identity provider
D.SAML/WS-Fed identity provider
AnswerB

Google identity provider is a first-class social identity provider in Microsoft Entra External Identities. You add it by navigating to External Identities > All identity providers > Google, supplying a client ID and client secret from the Google API Console, and then enabling it for B2B guest invitations or self-service sign-up user flows. This is the correct option because it directly configures Microsoft Entra ID to accept Google accounts for authentication.

Why this answer

To allow users to authenticate using their existing social media accounts, you need to add a Google identity provider in Microsoft Entra ID. Google is explicitly supported as a social identity provider (IdP) for B2B guest user scenarios, enabling users to sign in with their Gmail accounts. This is configured under External Identities > All identity providers, where you select Google and configure the OAuth 2.0 client ID and secret from the Google API Console.

Exam trap

The trap here is that candidates confuse the generic 'OpenID Connect identity provider' option with the pre-configured social providers, not realizing that Microsoft provides dedicated Google and Facebook identity providers for social authentication, while OpenID Connect is for custom OIDC-compliant IdPs.

How to eliminate wrong answers

Option A is wrong because OpenID Connect is a protocol, not a specific social identity provider; adding a generic OpenID Connect provider requires custom configuration and is not the pre-built option for social accounts like Google. Option C is wrong because Microsoft account is already a built-in identity provider in Entra ID for Microsoft personal accounts (e.g., Outlook.com), not for third-party social media accounts like Google or Facebook. Option D is wrong because SAML/WS-Fed identity providers are used for enterprise federation with on-premises or cloud directories (e.g., ADFS, Okta), not for consumer social media authentication.

95
MCQeasy

You are configuring Microsoft Entra ID Protection. You want to automatically respond to a specific risk level by requiring the user to change their password. Which risk policy should you configure?

A.MFA registration policy
B.Sign-in risk policy
C.Session risk policy
D.User risk policy
AnswerD

User risk policy targets the user account itself, so its remediation action is a password change, satisfying the stem's requirement. Sign-in risk policy instead blocks or demands MFA at authentication, which cannot force a credential reset. Configuring user risk to High and allowing password change enforces the required response.

Why this answer

The user risk policy in Microsoft Entra ID Protection is designed to respond to user risk detections such as leaked credentials, and it can be configured to require a password change (password reset) when a specified user risk level is reached. This directly matches the requirement to automatically respond to a risk level by requiring a password change.

Exam trap

MS-102 often tests the confusion between user risk and sign-in risk policies — candidates must remember that password change is tied to user risk, while MFA is tied to sign-in risk.

How to eliminate wrong answers

Option A is wrong because the MFA registration policy is used to require users to register for MFA, not to respond to risk with a password change. Option B is wrong because the sign-in risk policy responds to sign-in risk by requiring MFA or blocking access, not by forcing a password change. Option C is wrong because there is no 'session risk policy' in Entra ID Protection — session controls are configured within Conditional Access, not as a standalone risk policy.

96
Multi-Selecthard

Your company uses Microsoft Entra ID with P2 licenses. You need to configure Privileged Identity Management (PIM) for Azure AD roles. Which THREE actions are possible with PIM?

Select 3 answers
A.Automatically assign a role to all users in a security group
B.Schedule start and end times for role assignments
C.Require Azure MFA during role activation
D.Require approval from a specified group before activating a role
E.Limit role activation to a specific device
AnswersB, C, D

PIM supports time-bound assignments by letting you configure specific start and end dates and times for both eligible and active role assignments. This allows an administrator to grant access for a defined project window or temporary scenario without leaving the role permanently active. The scheduling capability is a core part of managing just-in-time privileged access. After the end time, the assignment expires and no longer grants access.

Why this answer

PIM allows you to configure time-bound role assignments with specific start and end dates, enabling just-in-time access and reducing standing privileges. This is a core feature of PIM for Azure AD roles, supporting both eligible and active assignments with scheduled durations.

Exam trap

The trap here is that candidates may confuse PIM's role activation restrictions with Conditional Access policies, assuming device-based limitations are possible, when in fact PIM only supports MFA, approval, and time-bound settings for activation.

97
Multi-Selecthard

Which TWO of the following are valid methods to enforce device compliance in a Conditional Access policy? (Select two.)

Select 2 answers
A.Require Microsoft Authenticator
B.Require session persistence
C.Require approved client app
D.Require Microsoft Entra hybrid joined device
E.Require device to be marked as compliant
AnswersD, E

Requiring Microsoft Entra hybrid joined device is a valid device compliance enforcement method because it checks that the device is joined to on-premises Active Directory and is synchronized or registered with Microsoft Entra ID (formerly Azure AD). This status confirms organizational ownership and management via Group Policy or SCCM/Intune hybrid scenarios, making it acceptable for Conditional Access device conditions. It is often used as an alternative when Intune MDM compliance is not deployed.

Why this answer

Requiring a Microsoft Entra hybrid joined device ensures the device is joined to both on-premises Active Directory and Microsoft Entra ID, which allows Conditional Access to enforce compliance based on the device's identity and configuration. Option E is correct because requiring the device to be marked as compliant relies on Microsoft Intune (or another MDM) to evaluate device health and policy adherence, and then Conditional Access blocks access if the device is not compliant.

Exam trap

The trap here is that candidates confuse authentication controls (like MFA or app restrictions) with device compliance controls, leading them to select 'Require approved client app' or 'Require Microsoft Authenticator' instead of the correct device-based grants.

98
MCQeasy

Your company has a hybrid identity configuration with Microsoft Entra Connect Sync. You need to enable password hash synchronization (PHS) for hybrid users. What is the prerequisite?

A.Pass-through authentication agent installed
B.Password writeback enabled
C.Hybrid Identity Administrator role in Microsoft Entra ID
D.Federation with AD FS
AnswerC

Configuring password hash synchronization requires changing tenant-level directory synchronization settings, which is protected by administrative roles. The Hybrid Identity Administrator role in Microsoft Entra ID grants permission to manage provisioning and synchronization, including enabling PHS. A Global Administrator can also perform this task, but Hybrid Identity Administrator is the least-privileged role that can, making it a necessary prerequisite.

Why this answer

The Hybrid Identity Administrator role in Microsoft Entra ID is required to enable password hash synchronization (PHS) because this role grants the necessary permissions to configure directory synchronization settings, including the PHS feature, within the Entra ID tenant. Without this role, the synchronization account used by Microsoft Entra Connect Sync cannot modify the tenant-level PHS toggle, even if the local service account has sufficient permissions on-premises.

Exam trap

The trap here is that candidates often confuse the on-premises administrative permissions (like Enterprise Admin) with the cloud role required to toggle the PHS feature, mistakenly thinking local AD permissions are sufficient, when in fact the Hybrid Identity Administrator role in Entra ID is the specific prerequisite for enabling PHS at the tenant level.

How to eliminate wrong answers

Option A is wrong because the Pass-through Authentication (PTA) agent is an alternative authentication method, not a prerequisite for PHS; PHS and PTA are mutually exclusive for the same user authentication flow, and PHS can be enabled without any PTA agent installed. Option B is wrong because password writeback enables password changes in the cloud to be written back to on-premises Active Directory, which is a separate feature used for self-service password reset (SSPR) and is not required for synchronizing password hashes from on-premises to the cloud. Option D is wrong because federation with AD FS is a different authentication model that bypasses PHS entirely; PHS can be enabled as a backup or standalone authentication method without any federation infrastructure.

99
MCQmedium

Your company uses Microsoft Entra ID and has an app named App1 that requires permissions to read all user profiles. You need to grant admin consent for App1 to read profiles without requiring each user to consent. What should you do?

A.Create a Conditional Access policy that requires consent for App1.
B.Register a new application in App registrations and assign the required permissions.
C.From Microsoft Entra ID, go to Enterprise applications, select App1, and grant admin consent.
D.Configure the user consent settings to allow users to consent for themselves.
AnswerC

To grant admin consent for App1, navigate to Microsoft Entra ID > Enterprise applications, select App1, then choose Permissions and click the Grant admin consent button. This action applies the app's required permissions to the tenant on behalf of all users, eliminating the need for individual user consent. This is the direct, supported method in the administration center for an existing enterprise application.

Why this answer

Granting admin consent for an enterprise application in Microsoft Entra ID allows a tenant administrator to pre-approve permissions for all users, eliminating the need for individual user consent. This is done by navigating to Enterprise applications, selecting App1, and using the 'Grant admin consent' option, which sends an OAuth 2.0 authorization request with the required permissions (e.g., User.Read.All) on behalf of the entire organization.

Exam trap

The trap here is that candidates often confuse 'granting admin consent' with 'configuring user consent settings' or 'creating a new app registration', not realizing that admin consent is a specific action on the existing enterprise application's permissions blade.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies control access conditions (e.g., location, device state) and cannot be used to grant or require consent for an application; consent is managed via application permissions and consent settings. Option B is wrong because registering a new application would create a separate app identity, not modify App1's existing permissions; the required permissions must be assigned to App1 itself, and admin consent must be granted for that specific app. Option D is wrong because configuring user consent settings to allow self-consent would require each user to individually consent, which contradicts the goal of granting admin consent to avoid user-by-user approval.

100
MCQeasy

You are implementing Microsoft Entra Verified ID. Which technology does it use to create decentralized digital identities?

A.Decentralized Identifiers (DIDs)
B.OpenID Connect
C.OAuth 2.0
D.Security Assertion Markup Language (SAML)
AnswerA

Decentralized Identifiers (DIDs) are the foundation of Microsoft Entra Verified ID. They are a W3C standard for globally unique identifiers that are cryptographically verifiable and do not require a central registration authority. DIDs enable the issuer, holder, and verifier to interact via verifiable credentials, with the DID document containing public keys and service endpoints used to establish trust. The core is that DIDs provide a decentralized, self-sovereign identity layer, not merely an authentication protocol.

Why this answer

Microsoft Entra Verified ID uses Decentralized Identifiers (DIDs) as the core technology to create decentralized digital identities. DIDs are globally unique identifiers that are cryptographically verifiable and do not rely on a centralized registry, enabling self-sovereign identity scenarios where users control their own identity data.

Exam trap

The trap here is that candidates confuse authentication/authorization protocols (OpenID Connect, OAuth 2.0, SAML) with the underlying decentralized identity infrastructure (DIDs), mistakenly thinking these protocols are used to create the identity itself rather than to secure access to it.

How to eliminate wrong answers

Option B is wrong because OpenID Connect is an authentication protocol built on top of OAuth 2.0, used for verifying user identity via ID tokens, not for creating decentralized identifiers. Option C is wrong because OAuth 2.0 is an authorization framework that issues access tokens, not a technology for generating decentralized digital identities. Option D is wrong because SAML is an XML-based federated identity standard for single sign-on (SSO) that relies on a centralized identity provider, not a decentralized identity model.

101
MCQhard

Your company, Fabrikam Inc., uses Microsoft Entra ID with hybrid identity. You have an on-premises Active Directory and use Microsoft Entra Connect Sync to synchronize users. You need to configure Microsoft Entra ID Protection to detect leaked credentials and risky sign-ins. Additionally, you must ensure that when a user is detected as high risk, their access is automatically blocked and they are required to change their password. You also need to enable password writeback so that password changes are written back to on-premises AD. You have the following options: A. Enable Identity Protection, configure user risk policy to require password change, and enable password writeback in Microsoft Entra Connect. B. Enable Identity Protection, configure sign-in risk policy to block access, and enable password hash sync. C. Configure Conditional Access policy to require MFA for all users, and enable seamless SSO. D. Deploy Microsoft Defender for Identity and configure automatic remediation. Which option should you choose?

A.Enable Identity Protection, configure user risk policy to require password change, enable password writeback
B.Enable Identity Protection, configure sign-in risk policy to block access, enable password hash sync
C.Deploy Microsoft Defender for Identity, configure automatic remediation
D.Configure Conditional Access policy to require MFA, enable seamless SSO
AnswerA

This option is correct because it combines user risk detection in Microsoft Entra ID Protection with a user risk policy that automatically requires a secure password change when an account is flagged as compromised. Password writeback is essential in a hybrid environment to propagate the new password to on-premises Active Directory. This workflow directly remediates the risk and meets all stated requirements.

Why this answer

It directly addresses all requirements: enabling Identity Protection allows detection of leaked credentials and risky sign-ins; configuring the user risk policy to require a password change automatically blocks high-risk users until they change their password; and enabling password writeback in Microsoft Entra Connect ensures that password changes performed in the cloud are written back to on-premises Active Directory, maintaining hybrid identity synchronization.

Exam trap

The trap here is that candidates often confuse sign-in risk policies (which block access) with user risk policies (which can require a password change), and they may overlook that password writeback must be explicitly enabled in Microsoft Entra Connect, not just password hash sync.

How to eliminate wrong answers

Option B is wrong because configuring a sign-in risk policy to block access does not require the user to change their password—it only blocks the sign-in attempt, and enabling password hash sync alone does not enable password writeback, which is necessary for on-premises password changes. Option C is wrong because deploying Microsoft Defender for Identity focuses on detecting on-premises attacks and does not natively provide user risk policies for leaked credentials or automatic password change enforcement in Entra ID Protection. Option D is wrong because configuring a Conditional Access policy to require MFA does not detect leaked credentials or risky sign-ins, and enabling seamless SSO does not provide password writeback or automatic blocking with password change for high-risk users.

102
MCQhard

Your organization uses Microsoft Entra ID P2 and has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement a solution that automatically remediates risky user sign-ins by requiring a password change when Microsoft Entra ID Protection detects a leaked credential. You also want to minimize help desk calls. Which configuration should you use?

A.Configure a user risk policy in Microsoft Entra ID Protection to require a secure password change for high user risk, and enable self-service password reset (SSPR) so users can remediate themselves.
B.Create a Conditional Access policy that requires multifactor authentication for all users and enable risk detections in Microsoft Entra ID Protection.
C.Enable Microsoft Entra Connect Health and configure alert notifications for synchronization errors, then instruct users to change their passwords when alerts are received.
D.Configure a sign-in risk policy to block access for medium and high sign-in risk, and enable Microsoft Entra Password Protection with a custom banned password list.
AnswerA

A user risk policy set to require a secure password change for high-risk users responds to leaked credentials by forcing a password reset. Enabling SSPR allows users to complete the remediation without help desk involvement, satisfying both the security and the minimize-help-desk-calls requirements. This is the intended use of Identity Protection user risk policies.

Why this answer

Microsoft Entra ID Protection detects leaked credentials and raises user risk. A user risk policy configured to require a secure password change for high user risk enforces remediation, and enabling SSPR lets users reset their own passwords. This combination automatically addresses the risk and reduces help desk dependency, which is exactly what the scenario requires.

Exam trap

The trap here is confusing sign-in risk policies with user risk policies; leaked credentials raise user risk, not sign-in risk, so a sign-in risk policy will not force a password change.

103
MCQeasy

Contoso uses Microsoft Entra ID P2. Users report that password reset self-service does not work. You verify that the users have the required license. What should you check next?

A.Ensure the users are in a group scoped for SSPR
B.Check that the users have registered for SSPR
C.Confirm the users have Microsoft Entra ID P1 licenses
D.Verify SSPR is enabled in Microsoft Entra ID
AnswerD

The correct first step is to open the Microsoft Entra admin center, go to Password reset > Properties, and verify that the 'Self-service password reset enabled' toggle is set to 'All' or 'Selected' instead of 'None'. By default, this setting is 'None', which disables the feature entirely even for users with P2 licenses and enrolled authentication methods. This matches the known requirement that SSPR must be explicitly enabled by an administrator. You should also confirm that the authentication methods under 'Authentication methods' are configured, but enabling the feature is the primary action needed.

Why this answer

The users already have the required Microsoft Entra ID P2 license, which includes SSPR functionality. However, SSPR must be explicitly enabled at the tenant level in Microsoft Entra ID under 'Password reset' settings before users can use the self-service password reset feature. Without this tenant-wide enablement, even licensed users cannot reset their passwords.

Exam trap

The trap here is that candidates often assume that having the correct license (P2) automatically enables SSPR, but Microsoft requires an explicit tenant-level toggle to activate the feature, and the question's phrasing 'does not work' points to the most fundamental missing configuration.

How to eliminate wrong answers

Option A is wrong because SSPR can be enabled for 'All users' or 'Selected' groups; scoping to a specific group is not required for SSPR to work—it is a configuration choice, not a prerequisite. Option B is wrong because user registration for SSPR is a step that occurs after SSPR is enabled; if SSPR is not enabled, users cannot register. Option C is wrong because the question states users already have the required license (Microsoft Entra ID P2), which includes all P1 features; checking for P1 licenses is redundant and irrelevant.

104
MCQmedium

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra Domain Services (Azure AD DS). You need to ensure that legacy applications that require NTLM authentication can still authenticate against the managed domain. What should you configure?

A.Configure Kerberos delegation
B.Disable NTLM v1 authentication on the managed domain
C.Enable NTLM v1 authentication on the managed domain
D.Enable password hash synchronization for the managed domain
AnswerC

Enabling NTLM v1 authentication on the Microsoft Entra Domain Services managed domain directly addresses the requirement for legacy applications. Microsoft Entra Domain Services typically prioritises more secure protocols like NTLM v2 and Kerberos. However, older applications often lack support for these newer versions and specifically mandate NTLM v1. Configuring the managed domain to support NTLM v1 allows these legacy applications to successfully authenticate, ensuring their continued operation within the environment.

Why this answer

Legacy applications that require NTLM authentication must have NTLM v1 enabled on the managed domain because Azure AD DS, by default, disables NTLM v1 for security reasons. Enabling NTLM v1 allows these older applications to authenticate against the managed domain using the NTLM protocol, which is necessary when Kerberos is not supported.

Exam trap

The trap here is that candidates often confuse enabling NTLM v1 with disabling it for security, or think that password hash synchronization alone enables NTLM authentication, but the key is that NTLM v1 must be explicitly enabled on the managed domain for legacy apps that require it.

How to eliminate wrong answers

Option A is wrong because Kerberos delegation is used for constrained or unconstrained delegation of Kerberos authentication, not for enabling NTLM authentication for legacy apps. Option B is wrong because disabling NTLM v1 would prevent legacy applications that require NTLM from authenticating, which is the opposite of what is needed. Option D is wrong because password hash synchronization is already required for Azure AD DS to function and does not control which authentication protocols are enabled on the managed domain.

105
MCQhard

Your company uses Microsoft Entra ID with hybrid joined devices. You need to enforce multi-factor authentication (MFA) for all cloud app access but want to exclude specific locations (trusted IPs). What is the most efficient way to implement this?

A.Use Microsoft Intune to enforce MFA for all corporate devices
B.Enable per-user MFA and exclude trusted IPs in the MFA service settings
C.Configure a user risk policy in Microsoft Entra ID Protection to require MFA when risk is medium or higher
D.Create a Conditional Access policy targeting all cloud apps, requiring MFA, with a condition to exclude trusted IPs
AnswerD

Conditional Access evaluates sign-ins against user, app and location conditions, so a single policy requiring MFA for all cloud apps with trusted IPs excluded satisfies both requirements without per-app configuration or legacy per-user MFA settings.

Why this answer

A Conditional Access policy scoped to 'All cloud apps' with a grant control of 'Require multi-factor authentication' and a location condition excluding trusted IPs is the most efficient and granular way to meet the requirement. Conditional Access is the modern, recommended policy engine in Entra ID and supports named locations (trusted IPs) as a first-class condition, so trusted locations bypass MFA while all other access is challenged. This satisfies both the enforcement and exclusion requirements in a single policy.

Exam trap

MS-102 often tests the confusion between per-user MFA (legacy, limited) and Conditional Access (modern, granular) — candidates who pick per-user MFA miss that CA is the recommended and more capable solution.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies control device configuration and can feed into Conditional Access, but Intune alone does not enforce MFA for cloud app access. Option B is wrong because per-user MFA is the legacy approach — while it does support trusted IP exclusion, it is being deprecated in favor of Conditional Access and lacks the granularity and reporting of CA policies. Option C is wrong because a user risk policy in Entra ID Protection only triggers MFA when risk is medium or high; it does not enforce MFA for all cloud app access regardless of risk, so it fails the 'all cloud app access' requirement.

106
MCQhard

Your organization uses Microsoft 365 E5 with Microsoft Entra ID P2. You have a hybrid identity environment with Microsoft Entra Connect Sync. You need to ensure that when a user is disabled in on-premises Active Directory, their Microsoft 365 access is blocked within 5 minutes, and any active refresh tokens are invalidated. You have already configured password hash synchronization. What should you do?

A.Enable Microsoft Entra Password Protection and configure a custom banned password list.
B.Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable Continuous Access Evaluation (CAE) in Microsoft Entra ID.
C.Enable 'Enable password hash synchronization' and set the 'User must change password at next logon' flag in on-premises Active Directory.
D.Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable 'Enable soft match' on the connector.
AnswerB

Synchronizing accountEnabled ensures the disabled state propagates to Microsoft Entra ID. Enabling CAE allows token revocation events, such as account disablement, to be enforced near real-time, invalidating refresh tokens within minutes. This combination meets the 5-minute blocking requirement.

Why this answer

Synchronizing the accountEnabled attribute from on-premises Active Directory ensures that disabled accounts are reflected in Microsoft Entra ID. Enabling Continuous Access Evaluation (CAE) allows Microsoft 365 services to respond to critical events like account disablement in near real-time, invalidating refresh tokens within minutes. Together, they meet the 5-minute blocking requirement.

Exam trap

The trap here is thinking that password hash synchronization alone propagates account disablement or that setting a password change flag blocks access; in reality, account status synchronization and CAE are required for timely token revocation.

107
MCQeasy

Your organization uses Microsoft Entra ID and requires that all guest users must have a mobile phone number registered for authentication. You need to enforce this requirement. What should you configure?

A.Create a Terms of Use policy that guests must accept.
B.Configure a Conditional Access policy requiring multifactor authentication for guest users.
C.Configure the Authentication methods policy to require mobile phone registration for guests.
D.Create an access review for guest users in Identity Governance.
AnswerC

The Authentication methods policy is the admin-level control that defines which verification methods are available and required for users, including guests. By enabling and configuring the Phone (mobile) method for guest users, you can mandate that guests register a mobile phone number before accessing resources. This directly satisfies the stated requirement.

Why this answer

The Authentication methods policy in Microsoft Entra ID allows you to define which authentication methods are available to users, including guest users. By configuring this policy to require mobile phone registration, you enforce that all guest users must register a mobile phone number for authentication, directly addressing the requirement.

Exam trap

The trap here is that candidates confuse requiring multifactor authentication (MFA) with requiring a specific authentication method (mobile phone), but MFA can be satisfied by other methods like email OTP or authenticator app, whereas the Authentication methods policy directly mandates registration of a mobile phone number.

How to eliminate wrong answers

Option A is wrong because a Terms of Use policy requires users to accept terms but does not enforce registration of a mobile phone number for authentication. Option B is wrong because a Conditional Access policy requiring multifactor authentication (MFA) for guest users enforces MFA at sign-in but does not specifically require the registration of a mobile phone number; MFA can be satisfied by other methods like email OTP or authenticator app. Option D is wrong because an access review in Identity Governance is used to review and attest to guest user access rights periodically, not to enforce authentication method registration.

108
MCQmedium

Your organization uses Microsoft Entra ID and has an application that requires the 'User.Read.All' permission. You need to grant this permission to the application but ensure that only an administrator can consent, not users. What should you do?

A.Grant admin consent for the application from the Enterprise applications blade.
B.Enable user consent for this application in the enterprise application settings.
C.Configure the user consent settings to allow user consent for low-risk permissions.
D.Set the 'Consent and permissions' settings to block user consent.
AnswerA

Granting admin consent from the Enterprise applications blade (by selecting the application, then clicking 'Grant admin consent' under Security/Permissions) authorizes the app's requested permissions for every user in the tenant. This is the only effective solution because the application likely requests high-risk permissions, such as Graph API application permissions, that must be consented to by a tenant administrator, not an end user. Once admin consent is granted, the application's status changes to 'Granted' and users can access it without being prompted for consent.

Why this answer

Granting admin consent from the Enterprise applications blade explicitly authorizes the application to access the 'User.Read.All' permission without requiring individual user consent. This is the only way to satisfy the requirement that only an administrator can consent, as admin consent bypasses user consent policies entirely and applies tenant-wide.

Exam trap

The trap here is that candidates often confuse blocking user consent (Option D) with granting admin consent, thinking that blocking users automatically grants the permission, but blocking only prevents consent without actually authorizing the application.

How to eliminate wrong answers

Option B is wrong because enabling user consent for this application would allow any user to consent to the 'User.Read.All' permission, which directly contradicts the requirement that only an administrator can consent. Option C is wrong because configuring user consent for low-risk permissions does not apply to 'User.Read.All', which is a high-risk permission (it allows reading all user profiles); users would still be blocked from consenting, but the requirement is to grant the permission, not just block users. Option D is wrong because blocking user consent entirely prevents users from consenting but does not grant the required permission to the application; admin consent must still be explicitly performed.

109
Multi-Selectmedium

Which TWO permissions are required for a custom role to manage Conditional Access policies in Microsoft Entra ID?

Select 2 answers
A.microsoft.directory/conditionalAccessPolicies/allProperties/read
B.microsoft.directory/conditionalAccessPolicies/read
C.microsoft.directory/conditionalAccessPolicies/delete
D.microsoft.directory/conditionalAccessPolicies/update
E.microsoft.directory/conditionalAccessPolicies/create
AnswersB, D

The read permission is the foundational access required to view Conditional Access policies and their current configuration. Without it, an administrator cannot even see the policies that need management, making it an indispensable part of the minimal permission set. Together with update, it covers the two core operations needed for policy management: seeing the policy and changing it.

Why this answer

To manage Conditional Access policies in Microsoft Entra ID, a custom role requires both the read and update permissions. The 'read' permission (option B) is necessary to view existing policies, while the 'update' permission (option D) is required to modify or configure policy settings. Without both, the role cannot effectively manage policies, as management implies the ability to change them.

Exam trap

The trap here is that candidates often assume 'create' or 'delete' permissions are needed for management, but Microsoft defines 'manage' as the combination of read and update, not full CRUD access.

110
MCQmedium

Your organization uses Microsoft Entra ID. You need to ensure that users can only access company resources from trusted networks. Which Conditional Access condition should you configure?

A.Sign-in risk
B.Device platforms
C.Client apps
D.Locations
AnswerD

The locations condition is specifically designed to evaluate the network origin of a sign-in request, using named locations that can be defined either as trusted IP address ranges or as countries/regions. This includes the trusted IPs feature in Microsoft Entra ID, which lets you mark corporate office ranges as trusted to bypass MFA or to block access from any other location. Because the organization needs to ensure access based on network location, this is the correct condition to configure in Conditional Access.

Why this answer

The Locations condition in a Conditional Access policy allows you to define trusted network locations using named locations (IP ranges or country/region). By configuring a policy that grants access only from these trusted locations, you ensure users can only access company resources from networks you have explicitly approved, such as corporate offices or VPN egress IPs.

Exam trap

The trap here is that candidates often confuse 'network location' with 'device compliance' or 'sign-in risk,' leading them to select Device platforms or Sign-in risk instead of the correct Locations condition.

How to eliminate wrong answers

Option A is wrong because Sign-in risk is a condition that detects the likelihood that a sign-in attempt is not legitimate based on real-time risk signals (e.g., anonymous IP, atypical travel), not the network location of the user. Option B is wrong because Device platforms condition restricts access based on the operating system of the device (e.g., Windows, iOS, Android), not the network from which the request originates. Option C is wrong because Client apps condition controls access based on the application type (e.g., browser, mobile app, legacy authentication), not the network location.

111
Multi-Selecthard

Which THREE are valid Microsoft Entra ID license plans that include Identity Protection?

Select 3 answers
A.Microsoft Entra ID P1
B.Microsoft 365 E3
C.Microsoft 365 E5 Security
D.Microsoft 365 E5
E.Microsoft Entra ID P2
AnswersC, D, E

Microsoft 365 E5 Security is an add-on subscription that brings Microsoft Entra ID P2 to an existing Microsoft 365 tenant, enabling Identity Protection with risk policies, user risk, and sign-in risk assessments. Since it explicitly grants P2 entitlements, it is a valid license plan for this question.

Why this answer

Microsoft Entra ID Identity Protection is a premium feature that requires either a Microsoft Entra ID P2 license or inclusion in a suite like Microsoft 365 E5 or Microsoft 365 E5 Security. Option C (Microsoft 365 E5 Security) is correct because it includes Microsoft Entra ID P2, which provides full Identity Protection capabilities including risk-based conditional access and user risk policies.

Exam trap

The trap here is that candidates often assume Microsoft 365 E3 includes all security features of E5, but E3 only provides Entra ID P1, which lacks Identity Protection's risk detection and remediation capabilities.

112
MCQmedium

Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires compliant devices for access to corporate resources. You need to ensure that iOS devices are compliant before accessing Exchange Online. Which Microsoft Intune policy should you configure?

A.Device configuration policy
B.Device compliance policy
C.App protection policy
D.Enrollment restrictions
AnswerB

A device compliance policy defines the platform-specific rules, such as iOS version and encryption requirements, that Intune evaluates to mark a device compliant. Conditional Access then grants Exchange Online access only to compliant devices, satisfying the stated requirement.

Why this answer

A Device Compliance policy in Microsoft Intune defines the rules a device must meet (OS version, encryption, jailbreak/root detection, password requirements) to be marked compliant. Conditional Access then uses that compliance state as a grant control, so iOS devices must satisfy the compliance policy before accessing Exchange Online. This is the correct policy type to enforce device health for Conditional Access.

Exam trap

MS-102 often tests the distinction between compliance policies (device health for Conditional Access) and configuration policies (settings delivery) — candidates pick configuration because it sounds like it 'configures' compliance, but only a compliance policy feeds the CA grant control.

How to eliminate wrong answers

Option A is wrong because a Device Configuration policy pushes settings to devices (Wi-Fi, VPN, restrictions) but does not evaluate or report compliance status to Conditional Access. Option C is wrong because an App Protection policy (MAM) protects app data on unmanaged or BYOD devices and does not make the device itself compliant. Option D is wrong because Enrollment Restrictions control which devices/users can enroll and which platforms are allowed, not whether an enrolled device meets compliance requirements.

113
MCQhard

You are reviewing directory settings for Microsoft 365 Groups. Based on the exhibit, which statement is true?

A.Only users in a specific security group can create Microsoft 365 Groups
B.A naming policy is enforced for new groups
C.Groups must have a classification label
D.All users in the tenant can create Microsoft 365 Groups
AnswerD

The EnableGroupCreation directory setting is set to true, which is the master switch that permits group creation in the tenant. Because GroupCreationAllowedGroupId is also empty, there is no security-group scoping override. As a result, every user in the organization can create Microsoft 365 Groups.

Why this answer

The exhibit shows that under 'Group creation settings,' the option 'Set which users can create Microsoft 365 Groups' is configured to 'Everyone.' This means all users in the tenant are permitted to create groups, regardless of membership in any security group. Therefore, option D is correct because the setting explicitly allows all users to create Microsoft 365 Groups.

Exam trap

The trap here is that candidates often assume a naming policy or classification label is always enforced for Microsoft 365 Groups, but the exhibit clearly shows no such configuration, and the question tests the ability to read the actual directory settings rather than relying on default assumptions.

How to eliminate wrong answers

Option A is wrong because the exhibit shows 'Everyone' is selected, not a specific security group; if a security group were required, the setting would show 'Selected security group' with a group specified. Option B is wrong because the exhibit does not display any naming policy configuration; a naming policy would be visible under 'Naming policy' settings, which are not shown or enabled here. Option C is wrong because the exhibit does not indicate that a classification label is required; classification labels are optional and must be explicitly configured in the 'Classification' settings, which are absent from the exhibit.

114
Multi-Selectmedium

Your organization uses Microsoft Entra ID. You need to enable users to reset their own passwords without administrator intervention. Which TWO components must be configured?

Select 2 answers
A.Microsoft Entra self-service password reset (SSPR)
B.Microsoft Entra Identity Protection
C.Conditional Access policies
D.Microsoft Entra Privileged Identity Management
E.Authentication methods registration
AnswersA, E

Microsoft Entra self-service password reset (SSPR) is the license-enabled feature that must be explicitly toggled on and configured for users to reset or change their own passwords without administrator intervention. The 'Enable self-service password reset' setting must be set to 'Selected' or 'All' (or via group assignment), and the reset process is governed by policies and authentication requirements. Its purpose is exactly the requested capability: allow users to self-reset when locked out or expired.

Why this answer

Microsoft Entra self-service password reset (SSPR) is the core feature that allows users to reset their own passwords without administrator intervention. It must be enabled and configured at the tenant level, and it relies on users having registered authentication methods to verify their identity during the reset process.

Exam trap

The trap here is that candidates often confuse optional security features like Identity Protection or Conditional Access as prerequisites for SSPR, when in fact only SSPR enablement and authentication method registration are strictly required.

115
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to implement an access review for all users who have access to a critical application. The review must be recurring every quarter and require reviewers to provide a justification for their decisions. Which access review settings should you configure?

A.Frequency: Quarterly, Justification required: No
B.Frequency: Quarterly, Justification required: Yes
C.Frequency: Annually, Justification required: Yes
D.Frequency: Monthly, Justification required: Yes
AnswerB

This combination is correct because it satisfies both core requirements: the access review recurrence is set to Quarterly, matching the mandated cadence, and 'Justification required' is enabled. In Microsoft Entra ID Governance, enabling justification forces reviewers to enter a rationale for each approval or denial, which is captured in the review logs and used for compliance evidence. This exactly aligns with the organization's attestation policy.

Why this answer

The requirement specifies a quarterly recurring access review with mandatory justification. In Microsoft Entra ID Governance, the 'Frequency' setting controls the recurrence interval (e.g., Quarterly), and the 'Justification required' toggle enforces that reviewers must provide a reason for their decision. Setting 'Justification required' to 'Yes' ensures compliance with audit and governance policies.

Exam trap

The trap here is that candidates may focus solely on the frequency requirement and overlook the justification requirement, selecting Option A because it matches 'Quarterly' but ignores the mandatory justification setting.

How to eliminate wrong answers

Option A is wrong because it sets 'Justification required' to 'No', which violates the explicit requirement that reviewers must provide justification. Option C is wrong because it sets 'Frequency' to 'Annually', which does not meet the quarterly recurrence requirement. Option D is wrong because it sets 'Frequency' to 'Monthly', which is more frequent than required and could introduce unnecessary overhead, but more importantly, it does not match the specified quarterly interval.

116
MCQeasy

You need to prevent users from registering security information for Microsoft Entra self-service password reset (SSPR) if they are not in a specific group. What should you configure?

A.Microsoft Entra Identity Protection user risk policy
B.Combined registration for SSPR and Microsoft Entra multifactor authentication
C.SSPR scope setting to require group membership
D.Conditional Access policy to block registration for non-group members
AnswerC

SSPR scope lets you target registration and reset to a single Microsoft Entra group, so users outside that group cannot register security information. This directly satisfies the requirement to restrict registration by group membership rather than disabling SSPR tenant-wide.

Why this answer

The SSPR scope setting in Microsoft Entra ID allows you to restrict self-service password reset registration and usage to a specific group of users. By configuring the scope to 'Selected' and choosing the group, only members of that group can register security information for SSPR. This directly prevents users outside the group from registering.

Exam trap

MS-102 often tests the confusion between SSPR scope settings and Conditional Access policies, leading candidates to choose Conditional Access for restricting SSPR registration.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policies are used to detect and respond to risky sign-ins, not to control SSPR registration scope. Option B is wrong because combined registration for SSPR and MFA only simplifies the registration experience; it does not restrict who can register. Option D is wrong because Conditional Access policies control access to cloud apps based on conditions, but they do not govern SSPR registration scope; SSPR scope is configured separately in the Password reset blade.

117
MCQmedium

You are reviewing a Conditional Access policy in JSON format. The policy is applied to all users accessing Office 365 from trusted locations. What is the intended behavior of this policy?

A.Users are blocked if they are not using a compliant device
B.Users must provide MFA and use a compliant device
C.Users only need to provide MFA regardless of device
D.Users must provide MFA or use a compliant device
AnswerD

This is correct because the grant controls are structured with an OR operator, meaning at least one of the listed controls must be satisfied. Users can authenticate with MFA to gain access, or they can sign in from a device that is marked compliant, and either fulfilled control results in grant. The policy scope (users, apps, conditions, etc.) determines when this grant logic is applied, but the operator and control list express exactly an MFA-or-compliant-device requirement.

Why this answer

The policy grants access when users are in a trusted location and either provide MFA or use a compliant device. The 'OR' condition between MFA and device compliance means that satisfying either requirement is sufficient, not both. This is the standard behavior when multiple controls are assigned with 'Require one of the selected controls' in Conditional Access.

Exam trap

The trap here is that candidates often assume multiple grant controls always require all conditions (AND logic), but Conditional Access defaults to OR logic unless the policy explicitly specifies 'Require all the selected controls'.

How to eliminate wrong answers

Option A is wrong because the policy does not block users; it grants access with conditions, and trusted location users are not blocked if they fail device compliance as long as they provide MFA. Option B is wrong because the policy does not require both MFA and a compliant device; it uses an OR condition, so only one is needed. Option C is wrong because the policy does not grant access with MFA alone regardless of device; it also allows access with a compliant device without MFA, so device compliance is a separate path.

118
MCQmedium

You are examining the default cross-tenant access policy for your Microsoft Entra ID tenant. Based on the exhibit, which statement is true?

A.Your users can use their Microsoft Authenticator app to sign in to partner tenants.
B.B2B direct connect is enabled for all external organizations.
C.External users must always reauthenticate even if their home tenant requires MFA.
D.Compliant device claims from external tenants are trusted.
AnswerC

With IsMfaAccepted set to $false in the inbound trust settings, the default cross-tenant access policy does not accept MFA claims from external IdPs. This means that even if a user from a partner tenant satisfied MFA in their home tenant, they must complete MFA again when accessing resources in your tenant. Your tenant's conditional access policies are enforced independently of the external tenant's MFA state, ensuring your organization's MFA requirements are always satisfied.

Why this answer

The default cross-tenant access policy in Microsoft Entra ID includes a setting that, when enabled, requires external users to satisfy MFA requirements from their home tenant. However, the exhibit shows that the 'Trust MFA from external tenants' option is not selected, meaning Entra ID will not accept MFA claims from the external user's home tenant. As a result, external users must always reauthenticate with MFA, even if their home tenant already enforced MFA.

Exam trap

The trap here is that candidates assume 'Trust MFA from external tenants' is enabled by default, but Microsoft deliberately leaves it disabled to enforce the resource tenant's own MFA policies, requiring external users to reauthenticate.

How to eliminate wrong answers

Option A is wrong because the Microsoft Authenticator app is a personal authentication method tied to the user's home tenant; cross-tenant access policies do not govern which authenticator app a user can use in partner tenants. Option B is wrong because B2B direct connect is not enabled by default for all external organizations; it must be explicitly configured in the cross-tenant access settings. Option D is wrong because compliant device claims from external tenants are not trusted by default; the 'Trust device compliance from external tenants' setting must be explicitly enabled in the cross-tenant access policy.

119
Multi-Selecthard

Your organization uses Microsoft Entra ID and has strict security requirements. You need to implement a Zero Trust security model. Which THREE of the following are foundational principles of Zero Trust that should be implemented?

Select 3 answers
A.Assume trust based on location
B.Segment access
C.Use least privilege access
D.Assume breach
E.Verify explicitly
AnswersC, D, E

Least privilege access enforces just-in-time and just-enough-access (JEA), limiting standing permissions so users receive only the rights needed for a task. This directly satisfies the Zero Trust principle of assuming breach, since compromised accounts cannot move laterally across Microsoft Entra ID resources without elevated rights.

Why this answer

Option E (Verify explicitly) is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust. Option C (Use least privilege access) is correct because Zero Trust mandates just-in-time and just-enough-access (JIT/JEA), risk-based adaptive policies, and data protection to limit each user's access to only what is needed for the task. Option D (Assume breach) is correct because Zero Trust operates on the assumption that the network is already compromised, so organizations must minimize blast radius, segment access, verify end-to-end encryption, and use analytics to detect and respond to threats.

Option A (Assume trust based on location) does not belong because Zero Trust explicitly rejects implicit trust from network location such as a corporate LAN or VPN, which is a core tenet of the traditional perimeter model. Option B (Segment access) is a related implementation tactic rather than one of the three foundational principles, which Microsoft defines as Verify explicitly, Use least privilege access, and Assume breach.

Exam trap

Microsoft often tests the distinction between security best practices (like segmentation) and the specific foundational principles of Zero Trust, causing candidates to select 'Segment access' because it sounds correct, but it is not one of the three core pillars defined by Microsoft.

120
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their Google Workspace credentials without creating external identities. What should you configure?

A.Enable Microsoft Entra Verified ID for Google Workspace users
B.Configure Google as a social identity provider in Microsoft Entra External ID
C.Configure Microsoft Entra B2B collaboration with Google Workspace
D.Configure SAML/WS-Fed identity provider federation with Google Workspace
AnswerD

Configuring SAML/WS-Fed identity provider federation is the correct approach because Microsoft Entra ID supports direct federation with Google Workspace by exchanging metadata and establishing a trust relationship. This allows Google Workspace users to authenticate with their existing corporate credentials and gain SSO access to Entra ID-integrated apps and resources. It provides a true federation experience where Google is treated as an external IdP within the Entra tenant.

Why this answer

Configuring SAML/WS-Fed identity provider federation with Google Workspace allows users to sign in using their Google Workspace credentials directly, without creating external identities. This federation establishes a trust relationship between Microsoft Entra ID and Google Workspace as an identity provider, enabling seamless authentication for users who already have Google accounts.

Exam trap

The trap here is that candidates often confuse social identity provider configuration (Option B) with enterprise federation, but social IdPs are designed for consumer scenarios and create external identities, whereas SAML/WS-Fed federation preserves the user's existing identity without creating new objects in the directory.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Verified ID is a decentralized identity solution using verifiable credentials, not designed for federating with Google Workspace for sign-in. Option B is wrong because configuring Google as a social identity provider in Microsoft Entra External ID is intended for consumer-facing applications and creates external identities, not for enterprise users with existing Google Workspace accounts. Option C is wrong because Microsoft Entra B2B collaboration creates external guest user objects in the directory, which contradicts the requirement to avoid creating external identities.

121
MCQmedium

An administrator runs the Azure CLI command shown in the exhibit. What is the result of this command?

A.A new application registration is created with requested permissions to Graph
B.An existing application registration is updated
C.The application is configured with single-tenant sign-in audience
D.An admin consent is granted for the Microsoft Graph permissions
AnswerA

The Azure CLI command uses the `az ad app create` verb, which always creates a brand-new application registration object in the directory rather than touching an existing one. The `--required-resource-accesses` parameter supplies the Microsoft Graph permissions the new app needs, so the operation registers the app and declares its required scopes in one step. This is purely a creation action, and the requested permissions are merely declared, not approved.

Why this answer

The Azure CLI command `az ad app create --display-name 'MyApp' --required-resource-accesses '[{"resourceAppId":"00000003-0000-0000-c000-000000000000","resourceAccess":[{"id":"e1fe6dd8-ba31-4d61-89e7-88639da4923c","type":"Scope"}]}]'` creates a new application registration in Microsoft Entra ID. The `--required-resource-accesses` parameter specifies the Microsoft Graph (resourceAppId `00000003-0000-0000-c000-000000000000`) and the permission with ID `e1fe6dd8-ba31-4d61-89e7-88639da4923c` (which corresponds to the `User.Read` delegated permission). This registers the app with requested permissions to Microsoft Graph, but does not grant admin consent or configure sign-in audience.

Exam trap

The trap here is that candidates confuse requesting permissions (which happens during app registration) with granting admin consent (a separate administrative action), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because the `az ad app create` command always creates a new application registration; it does not update an existing one (use `az ad app update` for updates). Option C is wrong because the command does not include any parameter to set the sign-in audience (e.g., `--sign-in-audience`); by default, the audience is set to `AzureADMyOrg` (single-tenant), but the command itself does not configure it—the default applies. Option D is wrong because the command only requests permissions; admin consent requires a separate step, such as using `az ad app permission admin-consent` or the Microsoft Entra admin center.

122
MCQeasy

You need to configure self-service password reset (SSPR) for users in Microsoft Entra ID. Which license is required?

A.Microsoft 365 F3
B.Microsoft 365 E3
C.Microsoft Entra ID P1
D.Microsoft Entra ID Free
AnswerC

Correct. Microsoft Entra ID P1 is the specific license that provides SSPR functionality.

Why this answer

Self-service password reset (SSPR) requires a Microsoft Entra ID P1 or P2 license. Both Microsoft 365 F3 and Microsoft 365 E3 include Microsoft Entra ID P1 licenses, which support SSPR. However, the question directly asks which license is required for SSPR, and the correct answer is the standalone Microsoft Entra ID P1 license.

While F3 and E3 include this license, they are suite licenses and not the specific license component being asked for.

Exam trap

The trap is that candidates may incorrectly assume Microsoft 365 E3 and F3 only include Entra ID Free, but in fact they include Entra ID P1, which supports SSPR. This can lead candidates to dismiss these options, but the correct answer is still the specific Entra ID P1 license.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 F3 includes only Azure AD Free, which does not support SSPR. Option B is wrong because Microsoft 365 E3 also includes only Azure AD Free, lacking the premium SSPR capability. Option D is wrong because Microsoft Entra ID Free explicitly excludes SSPR; SSPR requires at least a P1 license.

123
Multi-Selecteasy

Your company uses Microsoft Entra ID for identity management. You are planning to implement Conditional Access policies. Which TWO components are required to create a Conditional Access policy?

Select 2 answers
A.MFA registration status
B.Identity Protection risk policies
C.Azure AD roles
D.Assignments (users, groups, cloud apps, conditions)
E.Access controls (grant or block, session controls)
AnswersD, E

Assignments constitute the first mandatory component of a Conditional Access policy and define the target scope. They include Users, Groups, Cloud apps or actions, and Conditions such as device state, location, client app, and sign-in risk. This section determines who and what the policy applies to, and without it the policy would have no subject to evaluate.

Why this answer

A Conditional Access policy in Microsoft Entra ID requires two core components: Assignments and Access controls. Assignments define the scope of the policy by specifying users, groups, cloud apps, and conditions (e.g., location, device state). Access controls determine the enforcement action, such as granting access (optionally requiring MFA or compliant device) or blocking access, along with session controls like app-enforced restrictions.

Without both components, the policy cannot be created.

Exam trap

The trap here is that candidates confuse optional conditions or integrated features (like MFA registration status or Identity Protection risk) with the mandatory structural components of Assignments and Access controls, leading them to select distractors that are valid policy elements but not required for creation.

124
MCQmedium

Your organization uses Microsoft Entra Conditional Access. You need to block access from countries where your company does not operate. The list of blocked countries changes frequently. What is the most efficient way to manage this?

A.Enable Microsoft Entra multifactor authentication for all users from blocked countries
B.Create a Conditional Access policy that blocks all locations except the allowed countries
C.Use IP ranges in Conditional Access to block specific country IPs
D.Create Named Locations for blocked countries and use them in Conditional Access
AnswerD

Named Locations let you define country-based restrictions once and reference them across Conditional Access policies, so frequent updates to the blocked-country list require editing only the location definition rather than every policy. This directly satisfies the stem's changing-list constraint, avoiding repeated policy reconfiguration as countries are added or removed.

Why this answer

Named Locations in Microsoft Entra Conditional Access allow you to define countries by IP ranges and then use those locations in a policy to block access. This is the most efficient approach because you can update the list of blocked countries in the Named Locations configuration without modifying the Conditional Access policy itself, which is ideal when the list changes frequently.

Exam trap

The trap here is that candidates often think using IP ranges directly in the policy (Option C) is more precise, but they overlook the administrative overhead of maintaining those ranges manually, whereas Named Locations with country selection provide a simpler and more scalable solution for frequently changing country lists.

How to eliminate wrong answers

Option A is wrong because enabling MFA for users from blocked countries does not block access; it only adds an authentication challenge, which is not a block action and does not meet the requirement to prevent access. Option B is wrong because creating a policy that blocks all locations except allowed countries is inefficient when the list of blocked countries changes frequently, as you would need to constantly update the allowed list, and it is easier to manage a list of blocked countries directly. Option C is wrong because using IP ranges in Conditional Access to block specific country IPs is impractical and inefficient; you would need to manually gather and maintain a list of all IP ranges for each blocked country, which is error-prone and does not leverage the built-in country-based location detection that Named Locations provide.

125
MCQhard

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You are implementing Privileged Identity Management (PIM) to manage access to Azure AD roles. You need to ensure that when a user activates a privileged role, the activation request must be approved by their manager and must include a ticket number. What should you configure?

A.Create an access review for the role
B.Modify the role settings in PIM to require approval and justification with ticket number
C.Configure an access package in Entitlement Management
D.Use Conditional Access policy with session controls
AnswerB

In Privileged Identity Management (PIM), you can modify the role's settings to require approval for activation and mandate that the user supply a justification, which can include the support ticket number before the role becomes active. This enforcement is embedded directly in the activation workflow, so the request is routed to designated approvers and the ticket reference is captured. Because the scenario asks for exactly this type of activation-time control, changing the PIM role settings is the correct solution.

Why this answer

PIM role settings allow you to configure activation requirements, including requiring approval and mandating a justification field. By enabling 'Require approval to activate' and configuring the approver as the user's manager, and by setting 'Require ticket information on activation', you enforce that every activation request includes a ticket number and is routed to the manager for approval.

Exam trap

The trap here is that candidates confuse Entitlement Management access packages (which also support approval workflows) with PIM role settings, but only PIM role settings allow you to require a ticket number and specify the manager as the approver for Azure AD role activation.

How to eliminate wrong answers

Option A is wrong because access reviews are used for periodic recertification of role assignments, not for controlling the activation process itself. Option C is wrong because Entitlement Management access packages manage resource access through catalogs and policies, but they do not enforce manager approval and ticket number requirements for Azure AD role activation—that is a PIM role settings feature. Option D is wrong because Conditional Access policies control authentication and session behavior, not the approval workflow or justification requirements for PIM role activation.

126
MCQhard

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You have configured Microsoft Entra Identity Governance. You need to create an access review for all guest users in the tenant to ensure their access is still required. The review should be recurring every 90 days and should auto-remove guests if they are not approved. What should you configure?

A.Configure a Conditional Access policy to block guests after 90 days
B.Create an access review for all guest users with a recurrence of 90 days and auto-apply results
C.Configure PIM settings for guest users
D.Create an access package in entitlement management for guest users
AnswerB

Create an access review scoped to 'All guest users' and set the recurrence to 90 days; under 'Results' enable 'Auto apply results to resources' and 'If reviewers don't respond, remove access.' When each review instance completes, the service automatically removes the guest's assignments and, if you also enable the additional setting, can block sign-in and remove the B2B guest object from the directory. This is the identity governance feature designed for certified, recurring recertification of external identities.

Why this answer

Creating an access review for all guest users with a recurrence of 90 days and auto-apply results directly meets the requirement: it reviews guest access every 90 days and automatically removes guests who are not approved. Access reviews in Microsoft Entra ID Governance allow you to scope reviews to guest users, set recurrence, and enable auto-apply to enforce removal without manual intervention.

Exam trap

The trap here is that candidates confuse Conditional Access policies (which block access but do not remove accounts) with access reviews (which can automatically remove guest accounts), or they mistakenly think PIM or access packages can perform tenant-wide recurring guest reviews with auto-removal.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy controls access conditions (e.g., blocking sign-ins after 90 days) but does not perform recurring reviews or automatically remove guest accounts; it only blocks authentication, leaving the guest object and its assignments intact. Option C is wrong because PIM (Privileged Identity Management) settings manage just-in-time privileged role activation and approval, not recurring access reviews for all guest users or auto-removal of unapproved guests. Option D is wrong because creating an access package in entitlement management manages resource access through requests and approvals, but it does not provide a recurring review cycle with auto-removal for all guest users; access packages are for specific resource catalogs, not tenant-wide guest review.

127
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to automate the removal of access when an employee leaves the company. The identity lifecycle should trigger access reviews and automatic deprovisioning. What should you configure?

A.Microsoft Entra Entitlement Management
B.Microsoft Entra Lifecycle Workflows
C.Microsoft Entra Access Reviews
D.Microsoft Entra Privileged Identity Management
AnswerB

Microsoft Entra Lifecycle Workflows directly orchestrates joiner, mover, leaver, and post-arbitration workflows using built-in tasks arranged in a configurable schedule. For deprovisioning, it can trigger on an employee's leave date (for example, employeeLeaveDateTime) to disable the account, block sign-in, revoke sessions, remove licenses, and delete the user or send a manager email. Because it is event-driven by HR attributes and runs without manual intervention, it is the only option that automates the entire lifecycle from onboarding through offboarding.

Why this answer

Microsoft Entra Lifecycle Workflows is the correct choice because it is specifically designed to automate the entire identity lifecycle, including the removal of access when an employee leaves. It can trigger access reviews and automatically deprovision accounts and group memberships based on joiner, mover, and leaver scenarios, integrating with HR systems like Workday or SuccessFactors.

Exam trap

The trap here is that candidates often confuse Entitlement Management (which handles access packages) with Lifecycle Workflows (which handles the full lifecycle automation), or they think Access Reviews alone can automate deprovisioning, when in fact Access Reviews only provide attestation without execution of removal actions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Entitlement Management manages access packages and approval workflows for resource access, but it does not automate the full identity lifecycle deprovisioning triggered by employee departure events. Option C is wrong because Microsoft Entra Access Reviews only provides periodic review and attestation of access, not automated deprovisioning or lifecycle triggers. Option D is wrong because Microsoft Entra Privileged Identity Management focuses on just-in-time privileged role activation and approval, not on automating the removal of all access for departing employees.

128
MCQmedium

You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The company has a requirement that all administrative roles must be activated only after approval by a designated approver. You configure Privileged Identity Management (PIM) for the Global Administrator role. You need to ensure that when a user activates the role, an approver must approve the request before the role is activated. What should you configure in the PIM role settings?

A.Enable 'Require multifactor authentication on activation'.
B.Enable 'Require approval to activate' and specify the approvers.
C.Set Activation maximum duration to 1 hour.
D.Configure 'Require justification on activation'.
AnswerB

In PIM role settings, the 'Require approval to activate' option enforces that a designated approver must approve an activation request. You can specify one or more approvers. This directly meets the requirement that administrative roles must be activated only after approval by a designated approver.

Why this answer

The 'Require approval to activate' setting in PIM role settings enforces an approval workflow. When a user requests activation, the designated approvers receive a notification and must approve the request before the role is activated. This ensures that administrative roles are activated only after explicit approval, meeting the company's requirement.

It is configured per role in PIM.

Exam trap

The trap here is confusing MFA on activation with approval on activation; MFA verifies the user's identity but does not require a second person's approval.

129
MCQeasy

Your organization requires that all administrators use phishing-resistant authentication methods. Which Microsoft Entra ID authentication method meets this requirement?

A.SMS-based verification
B.Microsoft Authenticator push notification
C.Temporary Access Pass
D.FIDO2 security key
AnswerD

FIDO2 security keys implement WebAuthn, generating a private/public key pair on the device and sending an assertion that is cryptographically bound to the exact Origin and RP ID of the legitimate resource. Even if a user is tricked into visiting a phony admin portal, the key will not release a usable assertion because the fake site's origin does not match the registered relying party. This origin-bound challenge-response design makes FIDO2 phishing-resistant and the correct choice for the org's requirement.

Why this answer

FIDO2 security keys are phishing-resistant because they use public-key cryptography and are bound to a specific website origin, preventing credential reuse on fake sites. This meets Microsoft's requirement for phishing-resistant authentication under Entra ID, as it satisfies the 'something you have' factor without exposing secrets to the relying party.

Exam trap

The trap here is that candidates confuse 'multi-factor authentication' with 'phishing-resistant authentication,' assuming any MFA method (like push notifications) is sufficient, but Microsoft explicitly requires methods that resist credential theft via phishing, which only FIDO2, Windows Hello for Business, or certificate-based authentication satisfy.

How to eliminate wrong answers

Option A is wrong because SMS-based verification relies on a phone number and can be intercepted via SIM-swapping or SS7 attacks, making it vulnerable to phishing. Option B is wrong because Microsoft Authenticator push notifications use OTP or number matching, which can be intercepted by a man-in-the-middle or tricked via MFA fatigue attacks, and are not considered phishing-resistant. Option C is wrong because Temporary Access Pass is a time-limited password used for onboarding or recovery, not a phishing-resistant method; it can be phished if the user is tricked into entering it on a fake site.

← PreviousPage 2 of 2 · 129 questions total

Ready to test yourself?

Try a timed practice session using only Implement and manage Microsoft Entra identity and access questions.