MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?
⚠ Common exam trap
Many candidates confuse Privileged Identity Management (PIM) as solely for role activation, but PIM enforces least-privilege by requiring just-in-time (JIT) elevation for admin roles, which is a core zero-trust requirement for privileged access, while Conditional Access handles continuous verification for all users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access (A) is correct because it enforces least-privilege access by applying policies that require specific conditions (e.g., device compliance, location, risk level) before granting access to resources. It also enables continuous verification by evaluating signals in real time during each authentication request, ensuring that access is revoked if conditions change (e.g., user risk increases). This aligns directly with the zero-trust principle of 'never trust, always verify.'
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access
Why this is correct
Conditional Access is the core policy engine for zero trust, continuously evaluating signals like user risk, device compliance, location, and session context in real time. It enforces granular access controls—block, require MFA, or restrict session—before and during access, embodying the 'verify explicitly' principle of zero trust. Without it, other security controls lack a unified mechanism to apply context-aware, adaptive policies.
- ✗
Self-service password reset (SSPR)
Why it's wrong here
Self-service password reset (SSPR) primarily addresses password lifecycle self-management, reducing helpdesk tickets for forgotten credentials. It does not evaluate user identity, device health, or session risk, nor does it make any decisions about whether a user can access a resource. While it improves identity hygiene, it is not an access control mechanism and therefore does not enforce zero trust's continuous verification or least privilege.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) provides just-in-time, time-bound, and approval-based activation of privileged roles in Microsoft Entra ID and Azure resources. This directly supports zero trust's least-privilege principle by eliminating permanent standing admin access and requiring users to elevate rights only when needed. PIM also logs activations and can trigger alerts, giving visibility that is essential for an assume-breach posture.
- ✗
Application Proxy
Why it's wrong here
Application Proxy is a reverse proxy that publishes on-premises web applications to remote users, enabling external access without a VPN. It focuses on connectivity and authentication brokering, but it does not independently evaluate risk signals or enforce adaptive policies. Its value in zero trust is as a funnel to Conditional Access, not as a policy enforcement point itself, so it is not the primary implementation mechanism.
- ✗
Microsoft Entra Join
Why it's wrong here
Microsoft Entra Join creates a device identity by registering a device with Microsoft Entra ID, enabling single sign-on and compliance-based device management. It provides the device health and trust state that Conditional Access can consume as a signal, but it does not make any authorization decisions on its own. Essentially, it is an identity and management state, not a zero trust access control policy.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.