Courseiva

MS-102 · topic practice

Implement and manage Microsoft Entra identity and access practice questions

This domain covers Microsoft Entra ID identity and access administration: hybrid identity with password hash sync, self-service password reset, Conditional Access, Entra ID P1/P2 licensing, Verified ID, and Defender for Cloud Apps integration. Questions are scenario-based, asking you to select the correct configuration, license, or component to meet a stated security or sign-in requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Implement and manage Microsoft Entra identity and access

What the exam tests

What to know about Implement and manage Microsoft Entra identity and access

Be able to configure hybrid identity sign-in blocking, SSPR, Conditional Access policies, and Verified ID issuance. The single most important thing is matching the required outcome to the correct license and feature, since many scenarios hinge on P1 versus P2 capabilities.

Hybrid identity sign-in blocking via Entra Connect sync rules and Password Hash Sync

Self-service password reset licensing and authentication method configuration in Entra ID

Conditional Access policy design for cloud apps and SAML-based custom SaaS applications

Microsoft Entra Verified ID components, credential issuance, and verification for employment proofs

Watch out for

Common Implement and manage Microsoft Entra identity and access exam traps

  • ▸Assuming disabled on-premises accounts block cloud sign-in instantly; sync latency and writeback configuration determine timing.
  • ▸Confusing Entra ID P1 and P2 licensing for SSPR, Conditional Access, and Verified ID features.
  • ▸Believing Conditional Access can protect any SAML app; unsupported apps require Defender for Cloud Apps session or access controls.

Practice set

Implement and manage Microsoft Entra identity and access questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following are valid authentication methods in Microsoft Entra ID that can be used as part of a Conditional Access policy? (Select two.)

Which THREE of the following are required to configure Microsoft Entra ID Governance for automated user provisioning to a third-party SaaS application? (Select three.)

You are reviewing the following Conditional Access policy JSON in Microsoft Entra ID. What does this policy do?

Exhibit

Refer to the exhibit.\n\n{\n  \"conditions\": {\n    \"users\": {\n      \"includeUsers\": [\"All\"],\n      \"excludeUsers\": [\"Admin@contoso.com\"]\n    },\n    \"applications\": {\n      \"includeApplications\": [\"All\"]\n    },\n    \"clientAppTypes\": [\"MobileAppsAndDesktopClients\"]\n  },\n  \"grantControls\": {\n    \"builtInControls\": [\"Mfa\"],\n    \"operator\": \"OR\"\n  }\n}

Your company has a Microsoft 365 tenant with Microsoft Entra ID. You are configuring Conditional Access policies to enforce multifactor authentication (MFA) for all users. However, you want to exclude break-glass emergency access accounts from MFA. What is the recommended best practice for managing these emergency access accounts?

Your organization uses Microsoft Entra ID Governance. You need to ensure that access reviews are automatically created for all guest users in the tenant and that reviews are sent to the guest users' managers for approval. You configure an access review policy. Which identity governance feature should you use?

Your organization uses Microsoft Entra ID and wants to implement Identity Protection to detect risky users. Which THREE risk types can be detected by Identity Protection? (Choose three.)

Your organization uses Microsoft Entra ID and wants to allow users to reset their own passwords using self-service password reset (SSPR). What is the minimum licensing required?

Your company uses Microsoft Entra ID and has an application that requires users to consent to permissions. You want to allow users to consent to low-risk permissions but require admin approval for high-risk permissions. What should you configure?

Your organization uses Microsoft Entra ID. You need to ensure that users cannot reuse their last 5 passwords when changing passwords. What should you configure?

Your organization uses Microsoft Entra ID and has a custom role that includes the permission 'microsoft.directory/applications/credentials/update'. You need to create a new role that includes all permissions of the existing role except the credential update permission. What is the best approach?

Which TWO of the following are required to configure Microsoft Entra ID self-service password reset (SSPR) for cloud-only users? (Choose two.)

Which TWO of the following are features of Microsoft Entra ID Identity Protection? (Choose two.)

Refer to the exhibit. You run the PowerShell command to check the authentication method policy registration campaign. Which of the following is true?

Exhibit

Refer to the exhibit.

PS C:\> (Get-MgPolicyAuthenticationMethodPolicy).RegistrationCampaign.Email
Value   : enabled
IncludeTargets : [{"targetType":"group","id":"all_users","isSystemTarget":true}]
ExcludeTargets : []
State : enabled

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can access internal applications using single sign-on (SSO) without storing passwords in the cloud. Which authentication method should you implement?

Your organization uses Microsoft Entra ID and plans to deploy Microsoft Copilot for Microsoft 365. You need to ensure that Copilot respects the conditional access policies you have configured for data access. What should you do?

Your organization uses Microsoft Entra ID. You need to implement a solution that allows users to sign in without a password using their smartphone. Which TWO authentication methods can be used?

Refer to the exhibit. You have created a conditional access policy as shown. Users report that they can still access cloud apps from non-compliant devices. What is the most likely reason?

Exhibit

Refer to the exhibit.

```json
{
  "displayName": "Block access for non-compliant devices",
  "conditions": {
    "users": {
      "includeUsers": ["All"]
    },
    "applications": {
      "includeApplications": ["All"]
    },
    "clientAppTypes": ["browser", "mobileAppsAndDesktopClients"],
    "devices": {
      "deviceStates": {
        "include": ["All"]
      }
    }
  },
  "grantControls": {
    "operator": "OR",
    "builtInControls": ["compliantDevice"]
  }
}
```

Refer to the exhibit. You run the KQL query in Microsoft Sentinel. The query returns zero results even though you know user@contoso.com has had failed sign-in attempts in the last 30 days. What is the most likely reason?

Exhibit

Refer to the exhibit.

```kusto
SigninLogs
| where TimeGenerated > ago(30d)
| where UserPrincipalName == "user@contoso.com"
| summarize TotalAttempts = count(), FailedAttempts = countif(ResultType != 0), Locations = make_set(Location) by AppDisplayName
| where FailedAttempts > 0
```

A company uses Microsoft Entra ID with group-based licensing. You assign a license to a group, but some members do not receive the license. There are no error messages in the audit logs. What is the most likely cause?

You need to enforce multifactor authentication (MFA) for all users in a Microsoft Entra ID tenant. The solution must not require users to register security info if they already have it. Which approach should you use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Implement and manage Microsoft Entra identity and access sessions

Start a Implement and manage Microsoft Entra identity and access only practice session

Every question in these sessions is drawn from the Implement and manage Microsoft Entra identity and access domain — nothing else.

Related practice questions

Related MS-102 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the MS-102 exam test about Implement and manage Microsoft Entra identity and access?
Be able to configure hybrid identity sign-in blocking, SSPR, Conditional Access policies, and Verified ID issuance. The single most important thing is matching the required outcome to the correct license and feature, since many scenarios hinge on P1 versus P2 capabilities.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Implement and manage Microsoft Entra identity and access questions in a focused session?
Yes — the session launcher on this page draws every question from the Implement and manage Microsoft Entra identity and access domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other MS-102 topics?
Use the topic links above to move to related areas, or go back to the MS-102 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the MS-102 exam covers. They are not copied from any real exam or dump site.