Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are implementing Microsoft Entra Verified ID to issue verifiable credentials to employees for proof of employment. Which component is required to issue and verify credentials?

⚠ Common exam trap

It's easy for candidates to assume a traditional PKI certificate or a premium license is required, but Microsoft Entra Verified ID relies on decentralized identifiers (DIDs) and a trusted identity system, not on CA-issued certificates or specific license tiers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A decentralized identifier (DID) and a trusted identity system

Microsoft Entra Verified ID uses a decentralized identity model where each issuer and verifier has a unique decentralized identifier (DID) and a trusted identity system (such as a blockchain-based ION network or a web-based DID method) to publish and resolve DID documents. The DID and the trusted identity system are the core components required to cryptographically sign verifiable credentials and verify them without relying on a central authority, making option D correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID P2 licenses for all users

    Why it's wrong here

    Microsoft Entra ID P2 licenses are tied to advanced identity protection, access reviews, and privileged identity management features, none of which underpin the decentralized identity model that Verified ID relies on. Verified ID issuance and verification do not require any specific Entra ID license tier; even users with no P2 license can participate as holders or verifiers. The free capacity and the standard tenant configuration suffice for most Verified ID deployments.

  • ✗

    A certificate from a public certificate authority (CA)

    Why it's wrong here

    A certificate from a public CA relies on a centralized hierarchy of trust, where the CA roots and issues certificates to bind identities to key material. Verified ID, in contrast, uses W3C-standard decentralized identifiers (DIDs) that are created, resolved, and revoked without any central authority. The trust model is based on distributed ledger technology or did:web where the identifier itself is cryptographically self-certifying, not on a certificate chain. While TLS certificates may secure the communication, they are not the identity trust mechanism for verifiable credentials.

  • ✗

    An Azure AD B2C tenant

    Why it's wrong here

    Azure AD B2C is a customer identity and access management service intended for external consumer-facing applications, such as social or local account sign-ins. Verified ID does not require a B2C tenant; it operates within a regular Microsoft Entra tenant and supports any user population, including employees, partners, and customers. B2C can optionally integrate with Verified ID as a verifier or issuer, but it is not a prerequisite or a source of the decentralized trust foundation. The DID and trust system are entirely independent of the tenant directory type.

  • ✓

    A decentralized identifier (DID) and a trusted identity system

    Why this is correct

    A decentralized identifier (DID) serves as the globally unique, cryptographically verifiable identifier for each participant in a verifiable credential ecosystem, paired with a trusted identity system that publishes and resolves DID documents. The DID document contains the public keys used to verify the credential issuer's signature, and the trust system establishes how DIDs are registered and discovered—through methods like did:ion or did:web. This combination replaces the need for a centralized CA, because trust is anchored in the cryptographic agreement of the DID infrastructure. Together, they form the core requirement for issuing and verifying verifiable credentials with Microsoft Entra Verified ID.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.