Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the Global Administrator. The security team reports that several users have been compromised due to weak passwords. You need to implement a solution that enforces strong password policies and blocks common passwords. The solution must also provide users with the ability to reset their own passwords securely if they forget them, without requiring help desk intervention. Additionally, you need to configure risk-based Conditional Access policies to block sign-ins from anonymous IP addresses and require MFA for high-risk sign-ins. You have the following options: A. Configure password protection in Microsoft Entra ID to enforce a custom banned password list and enable self-service password reset (SSPR) with MFA. Then create Conditional Access policies for sign-in risk and anonymous IP. B. Enable password hash sync and configure pass-through authentication. Create a Conditional Access policy to require MFA for all users. C. Implement Microsoft Entra ID Protection and enable MFA registration policy. Configure password expiration to 90 days. D. Use security defaults in Microsoft Entra ID and enable automatic password rollback. Which option should you choose?

⚠ Common exam trap

MS-102 often tests whether candidates conflate authentication methods (password hash sync, pass-through) with password policy enforcement — the trap is selecting an option that addresses identity synchronization instead of password strength and risk-based access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure password protection with custom banned list, SSPR with MFA, and risk-based Conditional Access policies

Option A directly addresses every stated requirement: Microsoft Entra Password Protection with a custom banned password list enforces strong passwords and blocks common ones, SSPR with MFA lets users reset passwords without help desk involvement, and risk-based Conditional Access policies (sign-in risk and anonymous IP) block risky sign-ins and require MFA for high-risk events. This combination uses the Entra ID P2 features already licensed in the E5 tenant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure password protection with custom banned list, SSPR with MFA, and risk-based Conditional Access policies

    Why this is correct

    This approach combines Microsoft Entra ID Password Protection custom banned list to block predictable passwords, SSPR with MFA to enable secure self-service recovery, and risk-based Conditional Access policies that require step-up authentication only when sign-in or user risk is elevated. It directly satisfies the requirement for password strength controls, offers a recovery path without helpdesk involvement, and adaptively enforces access based on real-time threat signals.

  • ✗

    Enable password hash sync, pass-through authentication, and require MFA for all

    Why it's wrong here

    Password hash sync and pass-through authentication are only authentication methods; they do nothing to enforce password strength or block weak passwords. Requiring MFA for all in this scenario is a static policy that doesn't account for risk and still permits users to select common passwords. The configuration omits Microsoft Entra ID Password Protection with a custom banned list and does not enable SSPR, leaving a critical recovery gap and failing to meet the stated requirement.

  • ✗

    Implement Identity Protection, enable MFA registration policy, set password expiration to 90 days

    Why it's wrong here

    While Identity Protection and an MFA registration policy are useful, the 90-day password expiration is an outdated security control that can actually encourage weaker, incrementally changed passwords. More importantly, no Self-Service Password Reset is configured, so users cannot recover accounts without calling the helpdesk. Without a custom banned list, common passwords like 'Spring2024!' remain valid, so this option doesn't satisfy the need for comprehensive password protection.

  • ✗

    Use security defaults and enable automatic password rollback

    Why it's wrong here

    Security defaults are a fixed, Microsoft-defined baseline that enforces MFA and blocks legacy authentication, but they offer no flexibility for custom banned lists or risk-based Conditional Access policies. 'Automatic password rollback' is not an actual Microsoft Entra ID feature, and it certainly doesn't address common-password prevention or secure self-service recovery. Additionally, security defaults do not enable SSPR, so the organization would still lack a critical self-service capability.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Contoso uses Microsoft Entra ID P2. Users report that password reset self-service does not work. You verify that the users have the required license. What should you check next?

easy
  • A.Ensure the users are in a group scoped for SSPR
  • B.Check that the users have registered for SSPR
  • C.Confirm the users have Microsoft Entra ID P1 licenses
  • ✓ D.Verify SSPR is enabled in Microsoft Entra ID

Why D: The users already have the required Microsoft Entra ID P2 license, which includes SSPR functionality. However, SSPR must be explicitly enabled at the tenant level in Microsoft Entra ID under 'Password reset' settings before users can use the self-service password reset feature. Without this tenant-wide enablement, even licensed users cannot reset their passwords.

Variation 2. Your organization has a hybrid identity deployment using Microsoft Entra Connect Sync. You need to ensure that password writeback is enabled so that users can reset their own passwords from the cloud. Which prerequisite must be met?

hard
  • ✓ A.Self-Service Password Reset (SSPR) must be enabled in Microsoft Entra ID
  • B.Password hash synchronization must be enabled
  • C.Azure MFA must be enabled for all users
  • D.Microsoft Entra ID P2 licenses must be assigned

Why A: Password writeback requires that Self-Service Password Reset (SSPR) is enabled in Microsoft Entra ID because writeback is a feature of SSPR that allows password changes initiated in the cloud to be written back to the on-premises Active Directory. Without SSPR enabled, the cloud tenant has no mechanism to trigger the writeback operation, even if the Entra Connect Sync configuration is correct.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.