Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?

⚠ Common exam trap

Many candidates confuse Privileged Identity Management (PIM) as solely for role activation, but PIM enforces least-privilege by requiring just-in-time (JIT) elevation for admin roles, which is a core zero-trust requirement for privileged access, while Conditional Access handles continuous verification for all users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access

Conditional Access (A) is correct because it enforces least-privilege access by applying policies that require specific conditions (e.g., device compliance, location, risk level) before granting access to resources. It also enables continuous verification by evaluating signals in real time during each authentication request, ensuring that access is revoked if conditions change (e.g., user risk increases). This aligns directly with the zero-trust principle of 'never trust, always verify.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access is the core policy engine for zero trust, continuously evaluating signals like user risk, device compliance, location, and session context in real time. It enforces granular access controls—block, require MFA, or restrict session—before and during access, embodying the 'verify explicitly' principle of zero trust. Without it, other security controls lack a unified mechanism to apply context-aware, adaptive policies.

  • ✗

    Self-service password reset (SSPR)

    Why it's wrong here

    Self-service password reset (SSPR) primarily addresses password lifecycle self-management, reducing helpdesk tickets for forgotten credentials. It does not evaluate user identity, device health, or session risk, nor does it make any decisions about whether a user can access a resource. While it improves identity hygiene, it is not an access control mechanism and therefore does not enforce zero trust's continuous verification or least privilege.

  • ✓

    Privileged Identity Management (PIM)

    Why this is correct

    Privileged Identity Management (PIM) provides just-in-time, time-bound, and approval-based activation of privileged roles in Microsoft Entra ID and Azure resources. This directly supports zero trust's least-privilege principle by eliminating permanent standing admin access and requiring users to elevate rights only when needed. PIM also logs activations and can trigger alerts, giving visibility that is essential for an assume-breach posture.

  • ✗

    Application Proxy

    Why it's wrong here

    Application Proxy is a reverse proxy that publishes on-premises web applications to remote users, enabling external access without a VPN. It focuses on connectivity and authentication brokering, but it does not independently evaluate risk signals or enforce adaptive policies. Its value in zero trust is as a funnel to Conditional Access, not as a policy enforcement point itself, so it is not the primary implementation mechanism.

  • ✗

    Microsoft Entra Join

    Why it's wrong here

    Microsoft Entra Join creates a device identity by registering a device with Microsoft Entra ID, enabling single sign-on and compliance-based device management. It provides the device health and trust state that Conditional Access can consume as a signal, but it does not make any authorization decisions on its own. Essentially, it is an identity and management state, not a zero trust access control policy.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.