Courseiva

CCNA Entra Capabilities Questions

75 of 338 questions · Page 3/5 · Entra Capabilities topic · Answers revealed

151
MCQhard

A company needs to provide a developer with temporary, time-bound administrative access to Azure resources to debug a production issue. The access must require approval from the manager and automatically expire after 4 hours. Which Microsoft Entra capability should they use?

A.Privileged Identity Management (PIM)
B.Conditional Access
C.Identity Protection
D.Entitlement Management
AnswerA

Privileged Identity Management (PIM) in Microsoft Entra ID Governance is specifically designed to manage, control, and monitor access to important resources. It enables just-in-time (JIT) activation of privileged roles, allowing users to activate administrative permissions only when needed and for a predefined, limited duration. This includes requiring approval for activation and providing comprehensive audit trails, directly addressing the requirement for temporary, time-bound administrative access.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access to Azure resources with time-bound activation, approval workflows, and automatic expiration. This directly matches the requirement for temporary, manager-approved administrative access that expires after 4 hours.

Exam trap

The trap here is confusing Entitlement Management (which manages access to apps/groups via access packages) with PIM (which manages time-bound role activation for Azure resources), leading candidates to pick D when the scenario explicitly requires Azure resource administrative access with automatic expiration.

How to eliminate wrong answers

Option B (Conditional Access) is wrong because it enforces access policies based on signals like location or device compliance, not time-bound role activation with approval. Option C (Identity Protection) is wrong because it detects and remediates identity-based risks like leaked credentials, not manages privileged access. Option D (Entitlement Management) is wrong because it governs access to applications and groups via access packages, not Azure resource roles with automatic expiration.

152
MCQhard

A company uses Microsoft Entra ID. They have a critical application that requires additional security. The security team wants to enforce multifactor authentication (MFA) for every access to the application, but they also want users to reauthenticate with MFA if a session lasts longer than 60 minutes, regardless of device compliance. Which Conditional Access control should the administrator configure?

A.Grant control: Require multifactor authentication
B.Session control: Sign-in frequency
C.Session control: Application enforced restrictions
D.Grant control: Require device to be marked as compliant
AnswerB

Sign-in frequency is a session control that forces reauthentication after a set interval, here 60 minutes, irrespective of device compliance state. MFA is then re-enforced at each reauthentication, matching the requirement for periodic MFA regardless of compliance.

Why this answer

The requirement to force reauthentication with MFA after a specific time period (60 minutes) is a session-level control, not a grant control. The 'Sign-in frequency' session control in Conditional Access allows administrators to define how often a user must reauthenticate, including re-prompting for MFA, regardless of device compliance. This directly meets the scenario's need for a time-based reauthentication policy.

Exam trap

The trap here is that candidates confuse 'Grant controls' (which enforce conditions at sign-in) with 'Session controls' (which manage behavior after sign-in), leading them to select 'Require multifactor authentication' instead of 'Sign-in frequency' for time-based reauthentication.

How to eliminate wrong answers

Option A is wrong because 'Grant control: Require multifactor authentication' enforces MFA at initial sign-in but does not enforce reauthentication after a session duration; it lacks the time-based re-prompting capability. Option C is wrong because 'Session control: Application enforced restrictions' relies on the application itself to enforce policies (e.g., via device-based conditional access in Exchange Online), not on Entra ID to force reauthentication after a fixed time. Option D is wrong because 'Grant control: Require device to be marked as compliant' checks device health at sign-in but does not enforce a session timeout or reauthentication frequency, and the scenario explicitly states 'regardless of device compliance'.

153
MCQeasy

A user reports they cannot access the company portal from their personal device. The device is not enrolled in Microsoft Intune. The admin wants to ensure only compliant devices can access corporate resources. What should the admin configure?

A.Conditional Access policy requiring device compliance
B.Enable password writeback
C.Enable Identity Protection sign-in risk policy
D.Microsoft Entra Privileged Identity Management
AnswerA

Conditional Access policies evaluate specific conditions, such as device state, before granting access to cloud applications like the company portal. By requiring a device to be marked as compliant by Microsoft Intune, these policies ensure that only devices meeting organizational security standards (e.g., OS version, encryption, antivirus) can access sensitive resources. This directly addresses a user's inability to access the portal if their device fails compliance checks, making it the correct solution.

Why this answer

A is correct because a Conditional Access policy can require device compliance before granting access to corporate resources. When the device is not enrolled in Microsoft Intune, it cannot report compliance status, so the policy blocks access. This ensures only managed, compliant devices can access the company portal.

Exam trap

The trap here is that candidates confuse device compliance policies with sign-in risk policies or identity governance features, mistakenly thinking risk-based controls or PIM can enforce device health, when only Conditional Access with Intune compliance can block non-enrolled personal devices.

How to eliminate wrong answers

Option B is wrong because password writeback is a feature for on-premises password synchronization to Entra ID, not for controlling device access. Option C is wrong because Identity Protection sign-in risk policy evaluates user sign-in risk (e.g., anonymous IP, leaked credentials), not device compliance. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation, not device-level access control.

154
MCQhard

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs. Which statement is true?

A.jdoe's sign-in had no risk detected.
B.jdoe's sign-in failed Conditional Access.
C.asmith's sign-in was likely from an application or service principal.
D.asmith's sign-in had a high risk level.
AnswerC

asmith's sign-in was indeed likely from an application or service principal, as indicated by the 'NonInteractiveUser' sign-in type. This specific type signifies that the authentication request originated from a client application, script, or service principal, rather than a direct interactive session initiated by a human user, facilitating automated access to resources.

Why this answer

The sign-in log entry for asmith shows an 'Application' sign-in type, which indicates the authentication was performed by an application or service principal rather than a user. In Microsoft Entra ID, sign-ins from applications or service principals are logged with a distinct sign-in type, and the exhibit displays 'Application' for asmith's entry, confirming this.

Exam trap

The trap here is that candidates may assume all sign-in logs represent user sign-ins and overlook the 'Sign-in type' column, leading them to misinterpret the risk level or Conditional Access status for a service principal entry.

How to eliminate wrong answers

Option A is wrong because the sign-in log for jdoe shows a 'Risk level' of 'Medium', indicating risk was detected, not 'No risk'. Option B is wrong because the sign-in log for jdoe shows 'Conditional Access' status as 'Success', not 'Failure', meaning Conditional Access policies were satisfied. Option D is wrong because the sign-in log for asmith shows a 'Risk level' of 'Low', not 'High'.

155
MCQmedium

A company uses Microsoft Entra ID. They want to ensure that users who are traveling to a high-risk country, based on the sign-in IP address, are prompted for multi-factor authentication before accessing the company's CRM application. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Azure AD Join
AnswerA

Conditional Access policies are the primary mechanism in Microsoft Entra ID for enforcing access decisions based on various conditions, including user location. Administrators can define "Named locations" using IP ranges or countries/regions, then create policies that require specific controls, such as multi-factor authentication (MFA), when users attempt to access applications from outside these trusted locations. This directly addresses the requirement to enforce location-based MFA for application access.

Why this answer

Conditional Access is the correct feature because it allows administrators to create policies that evaluate sign-in signals—such as the user's location derived from the IP address—and enforce access controls like requiring multi-factor authentication (MFA) before granting access to a specific application (e.g., the CRM app). By configuring a Conditional Access policy with a location condition targeting high-risk countries, the company can ensure that only users signing in from those IP ranges are prompted for MFA, while other sign-ins proceed normally.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA (which uses machine learning on user behavior) with Conditional Access's location-based MFA (which uses static IP-to-country mapping), leading them to select Identity Protection when the question explicitly specifies a high-risk country based on IP address rather than a risk score.

Why the other options are wrong

B

Identity Protection provides risk detection and remediation, but it does not enforce access controls like MFA prompts. Conditional Access is required to apply policies based on sign-in risk or location.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not enforce location-based multi-factor authentication prompts for specific applications.

D

Azure AD Join is used to join devices to Azure AD for single sign-on and management, not to enforce conditional access policies based on sign-in risk or location.

156
MCQeasy

A company needs to allow external business partners to securely access internal SharePoint Online sites and Teams channels. The partners use various identity providers, including Microsoft Entra ID and Google. The company wants to manage these external users in their directory and assign access policies. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra B2C (Business to Customer)
B.Microsoft Entra External ID (B2B Collaboration)
C.Microsoft Entra Domain Services
D.Microsoft Entra Identity Protection
AnswerB

Microsoft Entra External ID (B2B Collaboration) is the correct solution, specifically designed for securely collaborating with external business partners. It allows guest users from partner organizations to use their existing corporate or social identities to access specific applications and resources within your Microsoft Entra tenant. This integrates partners directly into your organization's access management framework, providing controlled and managed access to internal systems.

Why this answer

Microsoft Entra External ID (B2B Collaboration) is the correct capability because it allows the company to invite external business partners (B2B users) from any identity provider, including Microsoft Entra ID and Google, into their own Microsoft Entra directory. This enables the company to manage these external users in their directory, assign conditional access policies, and grant them secure access to internal SharePoint Online sites and Teams channels without requiring a separate application or customer-facing identity system.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2C (for customers) with B2B Collaboration (for business partners), leading them to select B2C because both involve external users, but B2C is for consumer-facing apps, not for granting access to internal resources like SharePoint and Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2C (Business to Customer) is designed for customer-facing applications where external users sign in with social or local identities, not for managing business partners in the company's directory with access to internal resources like SharePoint and Teams. Option C is wrong because Microsoft Entra Domain Services provides managed domain services like LDAP, Kerberos, and NTLM for legacy applications, not for inviting and managing external business partners. Option D is wrong because Microsoft Entra Identity Protection is a security tool that detects identity-based risks and vulnerabilities, not a capability for inviting or managing external users.

157
Multi-Selecthard

Which TWO of the following are supported identity types for Microsoft Entra External ID? (Select two.)

Select 2 answers
A.OAuth 2.0 token identities
B.Social identities (e.g., Google, Facebook)
C.X.509 certificate-based identities
D.Enterprise identities from SAML/WS-Federation identity providers
E.Biometric identities (fingerprint, face)
AnswersB, D

Microsoft Entra External ID (formerly Azure AD External ID) fully supports social identities, enabling users to sign in to applications using their existing credentials from popular social identity providers like Google, Facebook, and Microsoft accounts. This capability simplifies the registration and login process for external users, leveraging their familiar accounts. These identities are managed by the respective social providers, with claims securely passed to the application via standard protocols like OpenID Connect.

Why this answer

Microsoft Entra External ID supports social identities such as Google and Facebook (option B), allowing consumers to sign in with existing accounts from these providers via built-in identity providers. It also supports enterprise identities from SAML/WS-Federation identity providers (option D), enabling federation with external organizations' IdPs for B2B collaboration scenarios. These two identity types are core to External ID's design for customer and partner access.

OAuth 2.0 token identities (A) describe a protocol flow, not a supported identity type. X.509 certificate-based identities (C) are not a native External ID identity type. Biometric identities (E) are handled by the device/authenticator, not defined as an External ID identity type.

Exam trap

The trap here is that candidates confuse authentication methods (like biometrics or certificates) with identity provider types, or assume OAuth 2.0 tokens are an identity type rather than a protocol used to exchange identity information.

158
Multi-Selectmedium

Which THREE of the following are capabilities of Microsoft Entra ID Governance?

Select 3 answers
A.Self-service password reset
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
E.Conditional access
AnswersB, C, D

Access reviews are a capability within Microsoft Entra Identity Governance that allows organizations to efficiently manage group memberships, access to enterprise applications, and roles. They enable administrators, or even resource owners, to periodically review who has access to what resources, ensuring that only authorized users maintain appropriate permissions and helping to prevent privilege creep. This systematic validation of access rights is a core component of maintaining a strong security posture and meeting compliance requirements.

Why this answer

Entitlement management (D) is a core Entra ID Governance capability that lets organizations manage the lifecycle of access through access packages, catalogs, and policies, automating granting, revoking, and expiration of access for internal and external users. Access reviews (B) are also part of Entra ID Governance, enabling periodic recertification of group memberships, application assignments, and privileged role assignments to ensure users retain only the access they need. Privileged Identity Management (C) is included in Entra ID Governance, providing just-in-time privileged access, approval workflows, access reviews, and audit history for Microsoft Entra roles, Azure resources, and other workloads.

Self-service password reset (A) is an Entra ID authentication feature, not a governance capability, and Conditional Access (E) is an Entra ID access-control policy engine, so neither belongs to the Entra ID Governance feature set.

Exam trap

The trap here is that candidates often confuse security features like Conditional Access or SSPR with governance capabilities, but Microsoft Entra ID Governance specifically focuses on identity lifecycle management, access reviews, entitlement management, and privileged identity management, not on authentication or policy enforcement.

159
MCQmedium

A company with Microsoft 365 wants employees to access corporate applications from their personal Android and iOS devices. The security team requires that these devices be enrolled in mobile device management (MDM) for compliance policies, and that company data can be selectively wiped from the device without affecting personal data. Which Microsoft Entra device identity type should they configure for these personal devices?

A.Microsoft Entra registered
B.Microsoft Entra joined
C.Microsoft Entra hybrid joined
D.Microsoft Entra managed
AnswerA

Microsoft Entra registered devices are typically personal devices (Bring Your Own Device - BYOD) that users want to access corporate resources from. This identity type allows devices to be enrolled in Mobile Device Management (MDM) solutions like Microsoft Intune, enabling conditional access policies and selective wipe capabilities to protect organizational data without fully controlling the user's personal device.

Why this answer

Microsoft Entra registered is the correct device identity type for personal (BYOD) devices because it supports enrollment in MDM for compliance policies and enables selective wipe of company data without affecting personal data. This identity type registers the device with Entra ID without requiring organizational ownership, allowing users to access corporate applications while maintaining personal data separation.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra joined' with 'Microsoft Entra registered' because both involve device identity, but Entra joined implies full organizational control and no selective wipe capability, making it unsuitable for BYOD scenarios.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra joined is designed for organization-owned devices that are fully managed by the organization, not for personal BYOD devices, and it does not support selective wipe of only company data. Option C is wrong because Microsoft Entra hybrid joined requires on-premises Active Directory domain join and is intended for organization-owned devices that need both on-premises and cloud access, not for personal devices. Option D is wrong because 'Microsoft Entra managed' is not a valid device identity type in Microsoft Entra; the valid types are Entra registered, Entra joined, and hybrid Entra joined.

160
Multi-Selecteasy

Which two scenarios are examples of using Microsoft Entra business-to-business (B2B) collaboration? (Choose two.)

Select 2 answers
A.A user from a partner organization is invited to access a SharePoint Online site.
B.An employee uses their Microsoft Entra ID to sign in to a third-party SaaS application.
C.Two internal departments share resources within the same tenant.
D.A vendor employee uses their own work email to access a Power BI dashboard shared by your company.
E.Customers use their Facebook accounts to sign in to a company's web application.
AnswersA, D

This scenario exemplifies Microsoft Entra B2B collaboration, where an organization extends access to its internal resources, such as a SharePoint Online site, to an external user from a partner organization. By inviting the partner user, a guest account is created in the inviting organization's Microsoft Entra tenant, allowing the external user to authenticate with their existing corporate credentials and securely access the shared resource. This facilitates secure inter-organizational cooperation.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external users from partner organizations to access your company's resources, such as a SharePoint Online site. The invited user authenticates using their own home tenant credentials, and a B2B guest user object is created in your directory to represent them.

Exam trap

The trap here is confusing B2B collaboration (inviting external business partners with work/school accounts) with B2C collaboration (allowing consumers to sign in with social identities like Facebook or Google), leading candidates to incorrectly select Option E.

161
MCQmedium

A company uses Microsoft Entra ID and requires that all guest users from a partner organization must sign in using Microsoft Authenticator for MFA. The partner organization manages their own identities. What should you configure?

A.Enable Microsoft Entra ID Protection and configure MFA registration policy for guests
B.Use Microsoft Entra ID Governance to require access reviews for guests
C.Configure cross-tenant access settings to trust MFA from the partner's Microsoft Entra ID tenant
D.Create a Conditional Access policy that requires MFA for guest users
AnswerC

Cross-tenant access settings offer granular control over how users from other Microsoft Entra ID tenants interact with your resources. By configuring inbound trust settings, your tenant can be explicitly set to accept multi-factor authentication claims issued by the partner's home tenant. This crucial capability eliminates redundant MFA prompts for guest users, allowing your organization to leverage the partner's security controls and provide a seamless, yet secure, access experience.

Why this answer

Cross-tenant access settings in Microsoft Entra ID allow you to trust MFA claims from an external partner's tenant. Since the partner manages their own identities, trusting their MFA ensures that guest users from that partner organization can satisfy MFA requirements using their own Microsoft Authenticator without needing to register again in your tenant.

Exam trap

The trap here is that candidates often assume a Conditional Access policy (Option D) is the standard way to enforce MFA for guests, but they overlook the cross-tenant trust mechanism that allows the partner to manage their own MFA without guest user registration in the resource tenant.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection's MFA registration policy applies to users in your own tenant, not to guest users from a partner organization that manages their own identities. Option B is wrong because access reviews are used to periodically review and certify guest access, not to enforce MFA authentication requirements. Option D is wrong because a Conditional Access policy requiring MFA for guest users would force them to register for MFA in your tenant, which contradicts the requirement that the partner organization manages their own identities and that guests sign in using their own Microsoft Authenticator.

162
MCQmedium

A company wants to reduce the risk of privileged account misuse. They need to provide temporary, time-bound access to administrative roles in Microsoft Entra ID (Microsoft Entra ID) and require approval from a manager before granting the access. Which Microsoft Entra capability should they use?

A.Conditional Access policies
B.Microsoft Entra Privileged Identity Management (PIM)
C.Identity Protection
D.Entra ID Governance (Access Reviews)
AnswerB

Microsoft Entra Privileged Identity Management (PIM) directly addresses the risk of privileged account misuse by implementing just-in-time (JIT) access. It enables users to activate privileged roles only when needed, for a limited duration, and often requires an explicit approval workflow before elevation. This significantly reduces the attack surface by eliminating standing privileged access and provides comprehensive auditing of all privilege activations.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing administrators to activate roles for a limited, time-bound duration. It also supports approval workflows, requiring a manager's approval before role activation is granted, directly addressing the need for temporary, approved access to administrative roles.

Exam trap

The trap here is that candidates often confuse PIM with Conditional Access or Access Reviews, mistakenly thinking those services can enforce time-bound approvals, but only PIM combines JIT activation with an approval workflow for privileged roles.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies enforce access controls based on conditions like location or device compliance, but they do not provide time-bound role activation or approval workflows for privileged roles. Option C is wrong because Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not manage privileged role activation or require approval for role assignment. Option D is wrong because Entra ID Governance (Access Reviews) enables periodic review of existing role assignments to ensure they are still needed, but it does not provide temporary, time-bound activation with an approval process.

163
MCQhard

Your organization has implemented Microsoft Entra ID Governance. You need to review and attest to the access rights of users in a specific group every quarter. The group contains both direct members and members from nested groups. Which Microsoft Entra feature should you use to automate this review?

A.Lifecycle workflows
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
AnswerB

Microsoft Entra access reviews are a critical component of identity governance, specifically designed to enable organizations to efficiently manage access by regularly reviewing who has access to what resources. They allow designated reviewers, such as group owners or managers, to periodically attest to the continued necessity of access for users to groups, applications, or roles. This process ensures that access remains appropriate, adheres to the principle of least privilege, and helps maintain compliance with organizational policies and regulatory requirements.

Why this answer

Access Reviews in Microsoft Entra ID Governance allow you to create recurring reviews of group membership, including both direct members and transitive members from nested groups. This feature automates the attestation process by sending reviewers notifications and tracking their decisions, ensuring compliance with quarterly review requirements.

Exam trap

The trap here is confusing Entitlement Management (which handles access requests and packages) with Access Reviews (which handle periodic attestation), leading candidates to pick D when the question explicitly requires a recurring review and attestation workflow.

How to eliminate wrong answers

Option A is wrong because Lifecycle Workflows automate joiner-mover-leaver processes (e.g., provisioning/deprovisioning accounts), not periodic access attestation. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time activation and oversight of privileged roles, not recurring reviews of standard group membership. Option D is wrong because Entitlement Management manages access packages and catalogs for requesting resources, but does not natively provide recurring attestation workflows for existing group members.

164
MCQhard

Refer to the exhibit. You are reviewing Microsoft Entra sign-in logs for a user. The user successfully signed in from a mobile device running iOS, located in the US, with medium risk level. The sign-in did not require MFA. You have a Conditional Access policy that requires MFA for all users when sign-in risk is medium or higher. Why was MFA not triggered?

A.The Conditional Access policy may exclude 'Mobile Apps and Desktop clients' client apps.
B.The device is not compliant, so MFA was not required.
C.The sign-in risk level is medium, which is below the threshold.
D.The user is not assigned to the Conditional Access policy.
AnswerA

Conditional Access policies offer granular control over client applications. If a policy requiring MFA is specifically configured to apply only to 'Browser' client apps, then sign-ins originating from 'Mobile Apps and Desktop clients' would be explicitly excluded from that policy's enforcement. This allows the sign-in to proceed without triggering the MFA requirement, as the policy's scope does not encompass that particular client type. Such exclusions are common for compatibility or specific use cases.

Why this answer

The Conditional Access policy can be configured to exclude specific client apps, such as 'Mobile Apps and Desktop clients'. If the policy excludes these client apps, the sign-in from an iOS mobile device would not be subject to the MFA requirement, even though the sign-in risk is medium. The sign-in logs confirm MFA was not required, indicating the policy did not apply to this client app type.

Exam trap

The trap here is that candidates assume a medium risk level always triggers MFA, overlooking the client apps exclusion condition that can bypass the policy for specific device types.

How to eliminate wrong answers

Option B is wrong because device compliance is not a condition in the described policy; the policy only requires MFA based on sign-in risk, not device compliance. Option C is wrong because the policy explicitly requires MFA when sign-in risk is medium or higher, and the sign-in risk is medium, so the threshold is met. Option D is wrong because the user successfully signed in, and the policy applies to 'all users' unless specifically excluded; the logs show the policy did not trigger, which points to a client app exclusion rather than user assignment.

165
MCQeasy

Your company is implementing a passwordless authentication strategy. You want users to be able to sign in using the Microsoft Authenticator app on their mobile devices. Which Microsoft Entra feature should you enable?

A.Windows Hello for Business
B.Passwordless phone sign-in with Microsoft Authenticator
C.FIDO2 security keys
D.Temporary Access Pass
AnswerB

Passwordless phone sign-in with Microsoft Authenticator leverages the user's mobile device as a second factor and a cryptographic key. When attempting to sign in, the user receives a notification on their Authenticator app, which they approve by matching a number or using biometrics, effectively eliminating the need to type a password. This method offers a convenient, secure, and widely applicable passwordless experience across various applications and services integrated with Azure Active Directory.

Why this answer

Passwordless phone sign-in with Microsoft Authenticator allows users to sign in without entering a password by approving a notification or entering a number displayed on the screen. This directly aligns with the requirement to use the Microsoft Authenticator app on mobile devices for a passwordless authentication strategy.

Exam trap

The trap here is that candidates may confuse 'passwordless' with any non-password method, but the question specifically requires the Microsoft Authenticator app, which eliminates Windows Hello for Business (device-bound) and FIDO2 (hardware-bound) as valid options.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business is a biometric or PIN-based credential tied to a specific Windows device, not a mobile app-based solution. Option C is wrong because FIDO2 security keys are hardware-based external devices (e.g., USB keys) that require physical possession, not the Microsoft Authenticator app on a mobile phone. Option D is wrong because Temporary Access Pass is a time-limited passcode used for onboarding or recovery scenarios, not a persistent passwordless sign-in method using the Authenticator app.

166
MCQhard

Your organization is implementing Microsoft Entra Internet Access (formerly Microsoft Entra Internet Access). You need to secure access to public internet apps by enforcing traffic routing through Microsoft's network. Which feature should you enable?

A.Conditional Access
B.Global Secure Access
C.DDoS protection
D.Network segmentation
AnswerB

Microsoft Entra Global Secure Access is Microsoft's unified Security Service Edge (SSE) solution, designed to extend identity-centric security to network access. It functions as a cloud-delivered proxy, routing both internet-bound and private application traffic through Microsoft's global network security perimeter. This capability enables comprehensive traffic inspection, policy enforcement, and threat protection for all network flows, directly addressing the need for secure traffic routing and robust network security for an organization's users and devices.

Why this answer

Microsoft Entra Internet Access (part of Global Secure Access) routes traffic from users and devices through the Microsoft network to enforce security policies for public internet apps. Enabling Global Secure Access allows you to configure traffic forwarding profiles that redirect internet-bound traffic through Microsoft Entra Internet Access, ensuring consistent policy enforcement and threat protection.

Exam trap

The trap here is that candidates often confuse Conditional Access (an identity-based policy tool) with network-level traffic routing, not realizing that Global Secure Access is the specific feature designed to enforce traffic routing through Microsoft's network for internet-bound apps.

How to eliminate wrong answers

Option A is wrong because Conditional Access is an identity-driven policy engine that enforces access controls based on signals like user, device, and location, but it does not route traffic through Microsoft's network. Option C is wrong because DDoS protection (Azure DDoS Protection) mitigates distributed denial-of-service attacks at the network layer, not traffic routing or secure access to internet apps. Option D is wrong because network segmentation (e.g., virtual networks, subnets) isolates network traffic within an organization's infrastructure but does not redirect internet-bound traffic through Microsoft's network.

167
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) to manage user access to cloud applications. The security team wants to enforce that users must provide a second form of authentication, such as a phone call or mobile app notification, in addition to their password. Which Microsoft Entra capability should they enable?

A.Conditional Access
B.Identity Protection
D.Privileged Identity Management
AnswerC

Multi-Factor Authentication (MFA) is the security feature specifically designed to enhance account security by requiring users to provide two or more distinct verification factors to prove their identity. These factors typically come from different categories, such as something you know (password), something you have (phone, authenticator app), or something you are (biometrics). MFA directly implements and provides the additional authentication factor beyond the primary password, making it the correct choice for adding a second verification method.

Why this answer

Multi-Factor Authentication (MFA) is the correct capability because it requires users to provide a second form of authentication (e.g., phone call, mobile app notification) in addition to their password. This directly addresses the security team's requirement for a second authentication factor, which is the core function of MFA in Microsoft Entra ID.

Exam trap

The trap here is that candidates may confuse Conditional Access (which can *require* MFA) with the actual MFA capability itself, but the question asks for the capability that *provides* the second form of authentication, not the policy that enforces it.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces conditions (e.g., location, device state) to grant access, but it does not itself provide a second authentication factor; it can require MFA as a control, but the capability to provide the second factor is MFA. Option B is wrong because Identity Protection uses risk signals (e.g., leaked credentials, anonymous IP addresses) to detect and respond to potential identity threats, but it does not enforce a second authentication factor; it can trigger MFA via Conditional Access, but the second factor itself is MFA. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not the enforcement of a second authentication factor for all users.

168
MCQmedium

A company uses Microsoft Entra ID. The security team wants to automatically detect user behaviors that indicate possible compromise, such as leaked credentials, impossible travel, or anomalous login patterns. When a user is determined to be at high risk, the system should automatically require the user to reset their password the next time they sign in. Which Microsoft Entra capability should they use?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Identity Governance
AnswerB

Microsoft Entra ID Protection is specifically designed to detect and remediate identity-based risks. It analyzes sign-in and user behavior to identify threats like impossible travel, leaked credentials, or unfamiliar sign-in properties. Crucially, it allows administrators to configure user risk policies that can automatically enforce actions such as requiring a password reset or blocking access when a user's risk level is deemed high, directly addressing the need for automated remediation.

Why this answer

Identity Protection is the correct Microsoft Entra capability because it is specifically designed to automatically detect risky user behaviors such as leaked credentials, impossible travel, and anomalous sign-in patterns. It assigns a risk level to users and sign-ins, and can be configured with a Conditional Access policy to enforce actions like requiring a password reset at next sign-in when a user is deemed high risk. This directly matches the security team's requirement for automated detection and remediation.

Exam trap

Microsoft often tests the distinction between detection and enforcement: candidates mistakenly choose Conditional Access because it enforces the password reset, but the question asks for the capability that automatically detects the risky behaviors, which is Identity Protection—Conditional Access is the enforcement mechanism, not the detection engine.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls based on conditions (e.g., location, device state), but it does not itself detect risky behaviors like leaked credentials or impossible travel; it relies on Identity Protection to provide the risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation, approval workflows, and access reviews for administrative roles, not on detecting user compromise behaviors or enforcing password resets for risky users. Option D is wrong because Identity Governance manages user lifecycle, access certifications, and entitlement management (e.g., access reviews, group membership), but it does not include risk detection or automatic remediation for compromised accounts.

169
MCQeasy

A company uses Microsoft Entra ID. A new IT support technician is hired and needs to be able to reset passwords for users but must not be allowed to delete user accounts or modify group memberships. Which built-in Microsoft Entra ID role should be assigned to this technician?

A.User Administrator
B.Password Administrator
C.Helpdesk Administrator
D.Global Administrator
AnswerB

The Password Administrator role in Microsoft Entra ID is specifically designed for helpdesk personnel who need to reset passwords for users and manage service requests related to identity issues. This role grants the necessary permissions to perform password resets without conferring broader administrative rights, such as the ability to create or delete user accounts, modify group memberships, or manage other user properties. It perfectly adheres to the principle of least privilege by providing only the capabilities essential for password management tasks.

Why this answer

The Password Administrator role is the correct choice because it grants the specific permissions required to reset passwords for all users, including administrators, while explicitly excluding permissions to delete user accounts or modify group memberships. This role is designed for scenarios where a technician needs to perform password-related tasks without broader user management capabilities.

Exam trap

The trap here is that candidates often confuse the Password Administrator role with the Helpdesk Administrator role, mistakenly thinking the latter is more restrictive, when in fact the Helpdesk Administrator has broader user management capabilities including modifying user properties and managing support tickets.

Why the other options are wrong

A

The User Administrator role can reset passwords but also allows deleting user accounts and modifying group memberships, which exceeds the required permissions.

C

The Helpdesk Administrator role can reset passwords, but it also allows managing support tickets and other helpdesk functions, which is broader than the requirement. However, the key issue is that the Password Administrator role is more restrictive and specifically designed for password resets, making it the correct choice.

D

The Global Administrator role has full access to all Microsoft Entra ID features, including deleting user accounts and modifying group memberships, which exceeds the technician's required permissions.

170
MCQmedium

A company has several custom-developed web applications hosted on-premises. The company wants to provide employees with secure remote access to these applications without deploying a traditional VPN. Employees should be able to sign in using their existing Microsoft Entra ID credentials, and the solution should pass through multi-factor authentication policies. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra Application Proxy
B.Microsoft Entra Domain Services
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Identity Protection
AnswerA

Microsoft Entra Application Proxy is the correct solution because it provides secure remote access to on-premises web applications by acting as a reverse proxy. It integrates these applications with Microsoft Entra ID, allowing users to authenticate using their Entra ID credentials, including multi-factor authentication and Conditional Access policies. The Application Proxy connector, installed on the on-premises network, establishes an outbound-only connection to the Entra ID cloud service, eliminating the need for inbound firewall rules or a VPN.

Why this answer

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by acting as a reverse proxy. It allows employees to sign in with their existing Microsoft Entra ID credentials and enforces conditional access policies, including multi-factor authentication, without requiring a traditional VPN.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Application Proxy with a traditional VPN or assume that Microsoft Entra Domain Services is needed for authentication, but the key requirement is secure remote access without VPN, which only Application Proxy fulfills by acting as a reverse proxy with Entra ID integration.

Why the other options are wrong

B

Microsoft Entra Domain Services provides managed domain services like domain join and LDAP, not secure remote access to on-premises web applications with Microsoft Entra ID authentication and MFA.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not provide secure remote access to on-premises web applications. The question requires a solution for remote application access, not identity governance.

D

Microsoft Entra Identity Protection is a risk-based detection and remediation tool, not a remote access solution. It does not provide secure access to on-premises web applications or pass through authentication to them.

171
Multi-Selectmedium

Which THREE of the following are features of Microsoft Entra ID Governance? (Select three.)

Select 3 answers
A.Access reviews
B.Privileged Identity Management (PIM)
C.Entitlement management
D.Self-service password reset
E.Multifactor authentication
AnswersA, B, C

Microsoft Entra Access Reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and roles. They help ensure that users only have the access they need, reducing the risk of excessive or stale permissions. These reviews can be scheduled periodically or triggered on demand, requiring reviewers (e.g., group owners, managers) to attest to continued access necessity.

Why this answer

Access reviews (A) are a core Microsoft Entra ID Governance capability that lets organizations periodically recertify users' group memberships, application access, and role assignments to ensure least privilege. Privileged Identity Management (B) is included in Entra ID Governance and provides just-in-time privileged role activation, approval workflows, access reviews, and audit history for privileged access. Entitlement management (C) is also a governance feature that automates access request workflows, access packages, and lifecycle policies for internal and external users.

Self-service password reset (D) is an authentication/credential-management feature, not a governance capability, and multifactor authentication (E) is an authentication method for strengthening sign-in security, so neither belongs to Entra ID Governance.

Exam trap

The trap here is that candidates confuse security features like MFA and SSPR (which are part of Microsoft Entra ID's core authentication and protection capabilities) with governance features, which specifically focus on access lifecycle, attestation, and privileged role management.

172
MCQmedium

Refer to the exhibit. The JSON snippet shows an app registration in Microsoft Entra ID. The password credential endDateTime is set to 2025-12-31. What will happen when that date is reached?

A.The secret will renew automatically.
B.The app will be unable to authenticate using that secret.
C.The app registration will be automatically deleted.
D.The app will be blocked from signing in.
AnswerB

When an application's client secret reaches its expiration date, it becomes invalid and can no longer be used to authenticate with Azure Active Directory. Any attempt by the application to acquire an access token using this expired secret will result in an authentication failure. This prevents the application from accessing protected resources or performing actions on behalf of itself.

Why this answer

When the password credential (client secret) reaches its endDateTime, the secret expires and becomes invalid. Microsoft Entra ID does not automatically renew secrets; the application must use a valid secret to authenticate. Once expired, any authentication attempt using that secret will fail, preventing the app from obtaining tokens.

Exam trap

The trap here is that candidates may assume secrets auto-renew or that the app registration is deleted, but Microsoft Entra ID treats secrets as static credentials that must be manually managed before expiration.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID does not automatically renew client secrets; the secret must be manually rotated or renewed by an administrator or via automation. Option C is wrong because an expired secret does not trigger deletion of the app registration; the registration remains intact and can be updated with a new secret. Option D is wrong because the app itself is not blocked from signing in; only the specific expired secret becomes invalid, and the app can still authenticate using a different valid secret or certificate.

173
MCQmedium

A company uses Microsoft 365 and requires that users access corporate email and SharePoint from managed devices that meet security policy requirements, such as having encryption enabled and antivirus software running. The security team wants to enforce this access control within Microsoft Entra ID so that unmanaged devices are blocked. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Access Reviews
D.Privileged Identity Management
AnswerB

Conditional Access policies in Azure AD evaluate various signals, including user, location, application, and device state, at the time of a sign-in attempt. These policies can specifically enforce requirements such as a device being marked as compliant by Microsoft Intune or being hybrid Azure AD joined, before granting access to Microsoft 365 cloud applications like Exchange Online or SharePoint Online. This directly addresses the need to control access based on specific device compliance criteria.

Why this answer

Conditional Access is the Microsoft Entra ID feature that enforces access control policies based on conditions such as device compliance, location, and user risk. By configuring a policy that requires devices to be marked as compliant (e.g., with encryption enabled and antivirus running) and blocking access from unmanaged devices, the security team can meet the stated requirement. This is the correct choice because Conditional Access directly integrates with Microsoft Intune device compliance policies to evaluate device health before granting access to corporate email and SharePoint.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based signals like leaked credentials) with Conditional Access (which enforces broader policies including device compliance), leading them to select A instead of B.

Why the other options are wrong

A

Identity Protection is used to detect and respond to identity-based risks (e.g., leaked credentials, sign-in anomalies), not to enforce device compliance or block unmanaged devices from accessing resources.

C

Access Reviews are used to audit and recertify user access rights, not to enforce real-time device compliance policies. The question requires blocking unmanaged devices at sign-in, which is a Conditional Access policy action.

174
MCQmedium

Your company uses Microsoft Entra ID. You need to ensure that when a user's account is compromised and used to send spam, the account is automatically blocked from signing in. Which feature should you configure?

A.Microsoft Entra Conditional Access policy to block sign-ins from high-risk users
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra Identity Protection with a user risk policy to block high-risk users
D.Microsoft Entra Self-Service Password Reset
AnswerC

Microsoft Entra Identity Protection is the dedicated service for detecting, investigating, and remediating identity-based risks. A user risk policy within Identity Protection continuously monitors for suspicious activities, such as leaked credentials or impossible travel, to calculate a user's aggregate risk level. When this risk level crosses a configured threshold, the policy can be set to automatically block the user's sign-in attempt, directly fulfilling the requirement to prevent high-risk users from accessing resources.

Why this answer

Microsoft Entra Identity Protection uses machine learning to detect user risk, such as when an account is compromised and used to send spam. A user risk policy can be configured to automatically block sign-ins for high-risk users, directly addressing the requirement to block the compromised account from signing in.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with Identity Protection user risk policies, but the question specifically asks for the feature that automatically blocks based on compromise (spam), which is the user risk policy in Identity Protection, not a general Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy can block sign-ins based on risk, but it requires a license (e.g., P2) and is typically used in conjunction with Identity Protection; however, the question specifically asks for the feature that automatically blocks based on compromise (spam), which is directly the user risk policy in Identity Protection. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time access and approval workflows for privileged roles, not automatic blocking of compromised accounts. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords, but it does not automatically block sign-ins when an account is compromised.

175
MCQeasy

A company wants to ensure that only users with specific IP addresses can access its critical applications. Which Microsoft Entra feature should they configure?

A.Identity Protection
B.Privileged Identity Management
C.Conditional Access
D.Self-Service Password Reset
AnswerC

Azure AD Conditional Access serves as the policy engine for enforcing access controls based on specific conditions, making it the correct solution for IP-based restrictions. Administrators can define 'named locations' using public IP address ranges or country/region lists, then create policies that grant or block access if users are signing in from these specified locations. This allows precise control over who can access resources from particular network segments, directly addressing the company's requirement for IP-specific access.

Why this answer

Conditional Access is the correct feature because it allows administrators to create policies that enforce access controls based on conditions such as IP address location. By configuring a Conditional Access policy with a 'Locations' condition that includes only trusted IP address ranges, the company can block or grant access to critical applications based on the user's network location. This directly meets the requirement to restrict access to specific IP addresses.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access (which uses IP reputation) with the explicit IP address location control provided by Conditional Access policies, leading them to select Identity Protection instead.

How to eliminate wrong answers

Option A is wrong because Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not provide granular IP address-based access control policies. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not network-level access restrictions based on IP addresses. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords without administrator intervention, and it has no capability to restrict application access by IP address.

176
MCQmedium

Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to ensure that users can use the same password on-premises and in the cloud without having to sync password hashes. Additionally, you want to prevent accounts from being locked out after a few bad password attempts in the cloud. Which Microsoft Entra feature should you implement?

A.Use password hash synchronization and set up custom lockout policies.
B.Deploy password writeback and enable Microsoft Entra smart lockout.
C.Implement federation with Active Directory Federation Services (AD FS).
D.Implement pass-through authentication and configure on-premises lockout thresholds.
AnswerB

Deploying password writeback, a feature of Microsoft Entra Connect, allows users to reset or change their Microsoft Entra ID password and have that new password synchronized back to their on-premises Active Directory account. This ensures password consistency across the hybrid environment and enables cloud-initiated password management for on-premises accounts. Concurrently, enabling Microsoft Entra smart lockout protects user accounts from brute-force attacks by intelligently locking out malicious actors while allowing legitimate users to continue accessing their accounts, specifically preventing lockouts in Microsoft Entra ID.

Why this answer

Password writeback enables password changes made in the cloud to be written back to on-premises Active Directory, ensuring the same password is used without syncing password hashes. Microsoft Entra smart lockout prevents accounts from being locked out after a few bad password attempts in the cloud by intelligently recognizing and blocking malicious sign-in attempts while allowing legitimate users to continue, without locking the on-premises account.

Exam trap

The trap here is that candidates often confuse pass-through authentication with password writeback, thinking that pass-through authentication alone prevents cloud lockouts, but it does not—smart lockout is required to decouple cloud lockout from on-premises lockout thresholds.

How to eliminate wrong answers

Option A is wrong because password hash synchronization requires syncing password hashes to the cloud, which contradicts the requirement to avoid syncing password hashes, and custom lockout policies in Entra ID do not prevent cloud lockouts from affecting on-premises accounts. Option C is wrong because federation with AD FS still requires password hash synchronization or pass-through authentication for cloud authentication, and it does not inherently prevent cloud lockouts from locking on-premises accounts. Option D is wrong because pass-through authentication validates passwords against on-premises Active Directory but does not prevent cloud lockouts; on-premises lockout thresholds would still cause account lockout after a few bad attempts in the cloud.

177
MCQhard

A company has a Microsoft Entra ID tenant with thousands of users. They need to ensure that only users with a 'Manager' attribute populated can access a sensitive app. Which approach should they use?

A.Use HR-driven provisioning to populate an on-premises attribute and sync it
B.Create a dynamic group rule that includes users with a non-empty Manager attribute, then target the group in a Conditional Access policy
C.Create an access package in Entitlement Management that requires manager approval
D.Create an Administrative Unit for users with managers and assign the app to that unit
AnswerB

This is the most efficient and cloud-native solution. A dynamic group in Microsoft Entra ID can be configured with a rule (e.g., user.manager -ne null) to automatically include all users who have a manager assigned, ensuring membership is always up-to-date. This dynamic group can then be directly targeted by a Conditional Access policy, allowing granular control over application access or other security requirements for this specific user population.

Why this answer

A dynamic group rule can evaluate the 'Manager' attribute and include only users where it is populated. This group can then be assigned to a Conditional Access policy that requires the group membership for access to the sensitive app, ensuring only users with a manager can authenticate.

Exam trap

The trap here is confusing attribute-based dynamic group membership with approval workflows or administrative delegation, leading candidates to choose Entitlement Management or Administrative Units instead of the correct Conditional Access and dynamic group combination.

How to eliminate wrong answers

Option A is wrong because HR-driven provisioning populates attributes from an HR system, but it does not enforce access control based on the Manager attribute; it merely syncs data. Option C is wrong because an access package in Entitlement Management with manager approval manages access requests and approvals, but it does not automatically restrict access based on whether the Manager attribute is populated; it requires manual approval. Option D is wrong because Administrative Units are for delegating administrative scope over users and groups, not for controlling application access via attribute-based membership.

178
MCQhard

Refer to the exhibit. An administrator runs the PowerShell cmdlet shown. What is the purpose of this command?

A.To show the dynamic membership rules of the Sales group.
B.To list all groups in the Sales department.
C.To list Azure AD roles assigned to the Sales group.
D.To display the display name and user principal name of members of the Sales group.
AnswerD

The command Get-AzureADGroupMember successfully retrieves all direct members of the Azure AD group specified by its object ID. Piping this output to Select-Object DisplayName, UserPrincipalName then precisely extracts and displays only the user's friendly name and their unique sign-in identifier. This combination accurately fulfills the objective of reporting specific identity attributes for each member of the Sales group.

Why this answer

The PowerShell cmdlet `Get-AzureADGroupMember -ObjectId <SalesGroupObjectId>` retrieves the members of a specific Azure AD group. By default, it returns the members' display names and user principal names (UPNs), which are the primary identifiers for users in Microsoft Entra ID. Option D correctly identifies this purpose.

Exam trap

The trap here is that candidates confuse retrieving group members (Option D) with viewing dynamic membership rules (Option A), because both involve Azure AD groups, but the cmdlet names and parameters differ significantly.

How to eliminate wrong answers

Option A is wrong because the cmdlet `Get-AzureADGroupMember` retrieves members, not membership rules; dynamic membership rules are viewed using `Get-AzureADMSGroup` with the `-GroupType DynamicMembership` parameter. Option B is wrong because the cmdlet targets a single group by its ObjectId, not all groups in a department; listing groups by department would require `Get-AzureADGroup` with a filter on the `Department` attribute. Option C is wrong because Azure AD role assignments are retrieved using `Get-AzureADDirectoryRoleMember` or `Get-AzureADMSRoleAssignment`, not `Get-AzureADGroupMember`.

179
MCQhard

Refer to the exhibit. You are reviewing a Privileged Identity Management (PIM) configuration for a role in Microsoft Entra ID. The roleDefinitionId corresponds to a specific role. What is the effect of this configuration?

A.The user is permanently activated for the role for 1 hour.
B.The user is permanently assigned the role for 1 hour.
C.The user can activate the role without approval for up to 1 hour.
D.The user is eligible for the role indefinitely, but activation requires approval and lasts up to 1 hour.
AnswerD

Eligible assignment with no end date, approval required, activation max 1 hour.

Why this answer

The configuration shown in the exhibit sets the role assignment to 'Eligible' with an activation duration of 1 hour and requires approval (the approval toggle is on). An 'Eligible' assignment means the user is not permanently active; they must activate the role when needed. The requirement for approval ensures that an authorized approver must approve each activation request.

The 1-hour duration limits how long each activation lasts. This matches the description of being eligible indefinitely, with activation requiring approval and lasting up to 1 hour.

Exam trap

The trap here is that candidates confuse 'Eligible' with 'Active' assignments, assuming that an eligible assignment with no approval required means the user is automatically active, when in fact they must still manually activate the role.

How to eliminate wrong answers

Option A is wrong because 'permanently activated' implies the user is always active in the role, but the configuration shows an 'Eligible' assignment, not an 'Active' assignment. Option B is wrong because 'permanently assigned the role for 1 hour' is contradictory; a permanent assignment has no time limit, and the 1-hour duration applies only to activation, not to the assignment itself. Option C is wrong because while the user can activate without approval (as the approval toggle is off), the configuration shows an 'Eligible' assignment, not an 'Active' one; the user is not automatically activated and must perform an activation step.

180
MCQmedium

A company uses Microsoft Entra ID. The IT team needs to ensure that when employees leave the organization, their access to all Microsoft 365 applications is revoked immediately and their account is disabled. Which Microsoft Entra capability should the team use?

A.Microsoft Entra ID Governance lifecycle workflows
B.Microsoft Entra Conditional Access policies
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra self-service password reset (SSPR)
AnswerA

Lifecycle workflows in Microsoft Entra ID Governance automate joiner, mover, and leaver processes. For a leaver, you can configure a workflow that disables the account and revokes access to all applications immediately upon triggering. This directly addresses the requirement by automating offboarding tasks, ensuring no residual access remains. It is the correct capability for this scenario.

Why this answer

Lifecycle workflows in Microsoft Entra ID Governance are designed to automate identity lifecycle tasks, including offboarding. When an employee leaves, a leaver workflow can immediately disable the account and remove access to all integrated applications, ensuring compliance and security. Other options do not provide this end-to-end automation for termination scenarios.

Exam trap

The trap here is assuming that Conditional Access or PIM can fully handle offboarding, but they lack the automation to disable accounts and revoke all access immediately upon termination.

181
MCQmedium

A company wants to reduce help desk calls by allowing users to reset their own passwords. The security team requires that users verify their identity using a registered mobile phone or alternative email before resetting. Additionally, the company policy states that passwords cannot be reused until at least five new passwords have been used. Which Microsoft Entra ID features should they configure to meet these requirements?

A.Self-Service Password Reset (SSPR) and password protection policies (password history enforcement)
B.Self-Service Password Reset (SSPR) and Conditional Access policies
C.Multi-Factor Authentication (MFA) and password protection policies
D.Identity Protection and Authentication Strengths
AnswerA

Self-Service Password Reset (SSPR) directly enables users to reset their forgotten or expired passwords independently, significantly reducing help desk calls. When combined with password protection policies, which are a feature of Microsoft Entra ID, the system enforces rules such as preventing the reuse of a specified number of previous passwords. This combination effectively addresses both requirements: empowering users for self-service and maintaining strong password hygiene through history enforcement.

Why this answer

Self-Service Password Reset (SSPR) allows users to reset their own passwords, reducing help desk calls. The security requirement for identity verification via registered mobile phone or alternative email is met by SSPR's authentication methods. The password history enforcement (preventing reuse until at least five new passwords have been used) is configured through password protection policies, specifically the 'password history' setting that enforces a minimum of 5 unique passwords before reuse.

Exam trap

The trap here is that candidates often confuse Conditional Access with password policies, thinking that Conditional Access can enforce password history, when in fact password history is a separate setting under password protection policies, not a Conditional Access control.

Why the other options are wrong

B

Conditional Access policies control access based on conditions like location or device state, but they do not enforce password history rules. The requirement to prevent password reuse until five new passwords are used is a password protection policy, not a Conditional Access policy.

C

MFA provides identity verification but does not include password history enforcement; password protection policies alone do not enforce password history. The question requires both self-service reset with verification and password history, which SSPR and password protection policies together fulfill.

D

Identity Protection and Authentication Strengths do not include password history enforcement to prevent password reuse, which is explicitly required by the policy.

182
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Device Management
B.Identity Protection
C.Endpoint Detection and Response
D.Privileged Identity Management
E.Information Protection
AnswersB, D

Identity Protection is a core capability within Microsoft Entra ID that focuses on detecting, investigating, and remediating identity-based risks. It leverages machine learning and heuristics to identify suspicious activities, such as anomalous sign-ins, leaked credentials, or impossible travel, across user accounts. This feature can automatically block risky sign-ins or enforce multi-factor authentication, significantly enhancing the security posture of user identities within the organization.

Why this answer

Microsoft Entra ID (formerly Azure AD) includes Identity Protection (option B), a risk-based service that detects and remediates risky sign-ins and compromised user credentials using signals like leaked credentials and atypical sign-in behavior. It also includes Privileged Identity Management (option D), which provides just-in-time privileged role activation, approval workflows, access reviews, and time-bound role assignments for administrative roles. These are both core Entra ID capabilities within the Entra suite.

Device Management (option A) is primarily a Microsoft Intune capability, not Entra ID itself. Endpoint Detection and Response (option C) belongs to Microsoft Defender for Endpoint, and Information Protection (option E) is delivered by Microsoft Purview, so neither is an Entra ID capability.

Exam trap

Microsoft often tests the distinction between identity management (Entra ID) and endpoint security (Defender for Endpoint) or comprehensive device management (Intune). While Entra ID manages device *identities* and enables device-based conditional access, the broader 'Device Management' (e.g., configuration, app deployment, patching) is primarily handled by solutions like Intune.

183
MCQmedium

A company uses Microsoft Entra ID. They want to configure a Conditional Access policy that requires multi-factor authentication (MFA) when a sign-in is assessed as medium or high risk by Microsoft's identity protection signals. For sign-ins with no detected risk, MFA should not be required. Which feature or service provides the risk assessment signals that can be consumed by Conditional Access policies?

A.Identity Protection
B.Privileged Identity Management (PIM)
C.Entitlement Management
D.Identity Governance
AnswerA

Microsoft Entra ID Protection continuously monitors sign-in attempts and user behavior for anomalous activities, such as impossible travel, unfamiliar sign-in properties, or leaked credentials. It assigns a real-time risk score to each sign-in and user, which can then be directly consumed as a condition within Microsoft Entra Conditional Access policies. This allows organizations to enforce adaptive access controls, like multi-factor authentication or blocking access, based on the detected risk level.

Why this answer

Identity Protection is the Microsoft Entra service that analyzes billions of sign-in signals using machine learning to assign a risk level (low, medium, high) for each authentication attempt. Conditional Access policies can then consume these risk assessments directly as a condition, enabling granular MFA enforcement only when the sign-in risk is medium or high, while allowing low-risk sign-ins to proceed without MFA.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with Identity Protection because both involve 'identity' and 'security,' but PIM handles role activation and approval workflows, not risk-based sign-in analysis.

Why the other options are wrong

B

Privileged Identity Management (PIM) manages just-in-time access and role activation, not risk assessment signals. Risk signals for Conditional Access policies come from Identity Protection, not PIM.

C

Entitlement Management manages access packages and resource access rights, not risk assessment signals. Conditional Access policies require risk signals from Identity Protection, not from Entitlement Management.

D

Identity Governance provides tools for managing user identities, access reviews, and lifecycle, but does not generate risk assessment signals for sign-ins. Risk signals come from Identity Protection, which analyzes user and sign-in behavior.

184
MCQhard

Your organization uses Microsoft Entra ID P2 licenses. You need to implement a process to automatically remove users from a group if they have not signed in for 90 days. Which feature should you use?

A.Conditional Access policy
B.Privileged Identity Management
C.Access reviews in Identity Governance
D.Microsoft Entra ID Protection
AnswerC

Access reviews, a core component of Microsoft Entra Identity Governance, enable organizations to efficiently manage group memberships, application access, and role assignments. They allow administrators or group owners to periodically review who has access to what, and crucially, can be configured to automatically remove users from groups if they fail to attest to their continued need for access or if they are identified as inactive based on sign-in data. This capability directly addresses the requirement to maintain clean group memberships by removing inactive users.

Why this answer

Access reviews in Identity Governance allow you to automate the review and removal of group memberships based on inactivity criteria, such as users who haven't signed in for 90 days. This feature is specifically designed for periodic attestation and lifecycle management of group memberships, leveraging Microsoft Entra ID P2 licenses.

Exam trap

The trap here is confusing Access Reviews (which handle membership lifecycle based on inactivity) with Conditional Access (which controls access at sign-in) or Privileged Identity Management (which focuses on privileged roles).

How to eliminate wrong answers

Option A is wrong because Conditional Access policies enforce access controls during sign-in (e.g., requiring MFA or blocking locations) but cannot automatically remove users from groups based on inactivity. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and assignment, not general group membership lifecycle based on sign-in activity. Option D is wrong because Microsoft Entra ID Protection detects and responds to identity risks (e.g., leaked credentials, impossible travel) but does not automate group membership removal based on inactivity.

185
MCQhard

A company wants to implement just-in-time (JIT) privileged access management for their Global Administrators in Microsoft Entra ID. They require that a user must request activation of the Global Administrator role, the request must be approved by a separate administrator, and the role will automatically expire after 4 hours. Additionally, they need an audit trail of all activations. Which Microsoft Entra feature should they use?

A.Microsoft Entra Conditional Access
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management (PIM)
D.Azure Role-Based Access Control (RBAC)
AnswerC

Microsoft Entra Privileged Identity Management (PIM) is the dedicated service for managing, controlling, and monitoring access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It enables Just-In-Time (JIT) access by allowing users to activate privileged roles only when needed, for a limited duration, and often requiring multi-factor authentication or an approval workflow. PIM also enforces time-bound assignments and provides comprehensive auditing and review capabilities for all privileged role activations, directly addressing the requirement for JIT privileged access management.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing users to activate roles like Global Administrator on-demand, requiring approval from designated approvers, setting a maximum activation duration (e.g., 4 hours), and automatically deactivating the role upon expiry. It also maintains a full audit trail of all activations, approvals, and role assignments via the PIM audit history and Azure AD audit logs, meeting all the stated requirements.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which manages Azure resource permissions) with PIM (which manages Microsoft Entra ID directory roles and JIT activation), leading them to select option D despite Azure RBAC lacking approval workflows and automatic expiry for directory roles.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access enforces access policies based on signals like user location or device compliance, but it does not provide JIT role activation, approval workflows, or automatic role expiry. Option B is wrong because Microsoft Entra Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) but does not manage privileged role activation or approval processes. Option D is wrong because Azure Role-Based Access Control (RBAC) manages permissions for Azure resources (e.g., VMs, storage) using role definitions and assignments, but it does not support JIT activation, approval workflows, or time-bound expiry for Microsoft Entra ID directory roles like Global Administrator.

186
MCQmedium

A company uses Microsoft Entra ID. They want to enforce multifactor authentication (MFA) for all access to a sensitive HR application. However, they only want to require MFA when the sign-in risk is assessed as medium or high, and block access if the risk is high. Which Conditional Access components must the administrator configure to meet these requirements? (Choose the best answer)

A.Assignments (Users and cloud apps) and Session controls (Sign-in frequency)
B.Conditions (Sign-in risk) and Grant controls (Require multifactor authentication, Block access)
C.Conditions (Device platforms) and Grant controls (Require approved client app)
D.Grant controls (Require multifactor authentication) and Session controls (Application enforce restrictions)
AnswerB

Correct. The conditions specify when a policy applies (e.g., when risk is medium or high). Grant controls enforce the required actions: require MFA for medium/high risk and block for high risk. Block access is an available grant control.

Why this answer

The scenario requires evaluating sign-in risk as a condition, which is configured under Conditions (Sign-in risk) in Conditional Access. The Grant controls then enforce 'Require multifactor authentication' for medium/high risk and 'Block access' for high risk, directly matching the requirements.

Exam trap

The trap here is that candidates confuse Conditions (sign-in risk) with Conditions (device platforms) or Session controls, overlooking that risk-based MFA requires both the risk condition and specific grant controls to enforce different actions per risk level.

How to eliminate wrong answers

Option A is wrong because Session controls like Sign-in frequency manage session lifetime, not risk-based MFA enforcement or blocking. Option C is wrong because Device platforms condition filters by OS type, not sign-in risk, and Require approved client app is a grant control for device compliance, not risk-based access. Option D is wrong because Grant controls alone (Require MFA) cannot differentiate risk levels, and Session controls (Application enforce restrictions) do not provide risk-based blocking or conditional MFA.

187
MCQmedium

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user passwords and enable password writeback for self-service password reset. Which tool should you use?

A.Microsoft Entra admin center
B.Microsoft Entra Connect Sync
C.Active Directory Federation Services (AD FS)
D.Azure AD Connect (deprecated)
AnswerB

Microsoft Entra Connect Sync is the designated on-premises agent responsible for synchronizing user identities, groups, and other objects from an on-premises Active Directory to Microsoft Entra ID. It supports various synchronization features crucial for migration, including password hash synchronization (PHS), which securely transfers a hash of the on-premises password to the cloud, enabling single sign-on for users. This tool is fundamental for hybrid identity scenarios, ensuring a consistent user experience across both environments.

Why this answer

Microsoft Entra Connect Sync (formerly Azure AD Connect) is the correct tool because it synchronizes on-premises Active Directory objects, including password hashes, to Microsoft Entra ID and supports password writeback, which enables self-service password reset (SSPR) to write changed passwords back to on-premises AD. The question specifically requires both password synchronization and writeback, which are core features of Entra Connect Sync.

Exam trap

The trap here is that candidates may confuse the deprecated name 'Azure AD Connect' (Option D) with the current tool, or mistakenly think that AD FS (Option C) can handle password synchronization and writeback, when in fact AD FS only handles authentication federation and not directory synchronization or writeback operations.

How to eliminate wrong answers

Option A is wrong because the Microsoft Entra admin center is a web-based management portal for configuring cloud settings, but it cannot perform the actual synchronization or writeback of passwords from on-premises AD; it relies on a sync engine like Entra Connect Sync. Option C is wrong because Active Directory Federation Services (AD FS) is a federation service used for single sign-on and claims-based authentication, not for synchronizing password hashes or enabling password writeback for SSPR. Option D is wrong because Azure AD Connect is the deprecated name for the tool that has been rebranded as Microsoft Entra Connect Sync; while it functionally could perform the task, the exam expects the current, correct name.

188
MCQhard

A company is planning to migrate from on-premises Active Directory to Microsoft Entra ID. They have multiple on-premises applications that use LDAP for authentication. They want to enable single sign-on (SSO) to these applications from the cloud without modifying the applications. Which approach should they use?

A.Microsoft Entra Domain Services
B.Federation with Active Directory Federation Services (AD FS)
C.Pass-through authentication
D.Password hash synchronization with Seamless SSO
AnswerA

Microsoft Entra Domain Services provides a managed domain environment that is fully compatible with traditional Active Directory Domain Services (AD DS). It offers essential domain services like LDAP, Kerberos, and NTLM authentication, which are critical for legacy applications that cannot be easily re-architected to use modern authentication protocols. This service allows companies to lift-and-shift these applications to the cloud without deploying or managing domain controllers, while still leveraging their existing Microsoft Entra ID identities for authentication and directory lookups.

Why this answer

Microsoft Entra Domain Services provides managed domain services such as LDAP, Kerberos, and NTLM authentication without requiring you to deploy and manage domain controllers. Since the on-premises applications use LDAP for authentication and cannot be modified, Entra Domain Services can be used to lift and shift these applications into Azure while enabling SSO from the cloud, as it presents a compatible LDAP interface that the applications can continue to use.

Exam trap

The trap here is that candidates often confuse authentication methods (like Pass-through or Federation) with directory services, not realizing that legacy LDAP-based applications require a domain service that exposes an LDAP endpoint, not just a cloud authentication protocol.

How to eliminate wrong answers

Option B is wrong because Federation with AD FS requires modifying the applications to support SAML or WS-Federation, and it does not natively provide an LDAP interface for legacy applications. Option C is wrong because Pass-through authentication validates passwords against on-premises Active Directory but does not expose an LDAP endpoint for applications to authenticate against; it is an authentication method for cloud apps, not a replacement for LDAP directory services. Option D is wrong because Password hash synchronization with Seamless SSO enables cloud authentication for web-based apps using Kerberos tickets but does not provide an LDAP interface for legacy on-premises applications that require direct LDAP binds.

189
MCQhard

Refer to the exhibit. A Conditional Access policy is defined as shown. Which client applications will be blocked?

A.Browser-based applications accessing Office 365.
B.Exchange ActiveSync clients only.
C.Legacy authentication clients such as IMAP, POP, and SMTP.
D.Applications using modern authentication (e.g., Outlook for Windows with OAuth).
AnswerC

This Conditional Access policy specifically targets legacy authentication clients by including both "Exchange ActiveSync clients" and "Other clients" in its scope. Protocols like IMAP, POP, and SMTP inherently utilize legacy authentication methods, which are encompassed within the "Other clients" category. By targeting these client types, the policy effectively applies its controls to connections made using these older, less secure authentication flows.

Why this answer

The policy targets 'Legacy authentication clients' such as IMAP, POP, and SMTP, which do not support modern authentication protocols like OAuth 2.0. These protocols rely on basic authentication and are blocked by Conditional Access policies configured to require modern authentication. Option C is correct because the policy explicitly blocks these legacy protocols.

Exam trap

The trap here is that candidates may confuse 'Exchange ActiveSync clients' (which can use modern authentication) with legacy protocols like IMAP/POP/SMTP, or assume that all browser-based apps are blocked, when the policy specifically targets legacy authentication clients only.

How to eliminate wrong answers

Option A is wrong because browser-based applications accessing Office 365 typically use modern authentication (e.g., OAuth 2.0 via the browser) and are not blocked unless the policy specifically targets browser-based apps. Option B is wrong because Exchange ActiveSync clients can use modern authentication (e.g., OAuth 2.0) and are not inherently blocked; the policy targets legacy authentication, not all ActiveSync clients. Option D is wrong because applications using modern authentication (e.g., Outlook for Windows with OAuth) are explicitly allowed by the policy, as it only blocks legacy authentication clients.

190
Multi-Selectmedium

Which TWO Microsoft Entra ID features can be used to protect against credential theft? (Choose two.)

Select 2 answers
A.Passwordless authentication
B.Self-Service Password Reset (SSPR)
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
E.Conditional Access policies that require MFA
AnswersA, E

Passwordless authentication significantly enhances security by eliminating the primary target for many credential theft attacks: the password itself. By replacing passwords with more secure methods like FIDO2 security keys, Windows Hello for Business, or the Microsoft Authenticator app, organizations remove the risk of passwords being phished, brute-forced, or stolen through credential stuffing. This approach fundamentally reduces the attack surface for identity-based breaches.

Why this answer

Passwordless authentication (A) is correct because it removes the password from the sign-in process entirely, using methods such as Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app, so there is no password credential for attackers to phish, replay, or steal. Conditional Access policies that require MFA (E) are correct because they enforce a second verification factor at sign-in, so even if a password is compromised through phishing or breach, the stolen credential alone is insufficient to authenticate. SSPR (B) only lets users reset forgotten passwords and does not itself prevent credential theft.

Microsoft Entra ID Domain Services (C) provides managed domain services such as LDAP and domain join for legacy workloads, and Microsoft Entra ID Connect (D) synchronizes on-premises identities to Entra ID; neither feature directly protects credentials from theft.

Exam trap

The trap here is that candidates often confuse SSPR (a recovery mechanism) with a preventive control, or mistakenly think Entra ID Connect or Domain Services offer security features they do not, when the question specifically asks for features that protect against credential theft.

191
Multi-Selecthard

Which THREE components are part of the Microsoft Entra External Identities suite?

Select 3 answers
A.B2B direct connect
B.Conditional Access
C.B2C (business-to-consumer)
D.B2B collaboration
E.Identity Protection
AnswersA, C, D

Azure AD B2B, now a foundational component within Microsoft Entra External ID, specifically enables organizations to collaborate securely with external partners. It allows guest users from other Microsoft Entra tenants or social identity providers to access applications and resources in your directory using their existing credentials, streamlining external access management. This capability is central to managing external identities for business-to-business scenarios.

Why this answer

Microsoft Entra External Identities is the suite of capabilities for managing external users, and it comprises three components: B2B collaboration (D), B2B direct connect (A), and B2C (business-to-consumer) (C). B2B collaboration (D) lets you invite partner users as guests into your tenant, where they authenticate with their own credentials and appear as guest objects in your directory. B2B direct connect (A) enables a mutual, two-way trust with another Microsoft Entra tenant so users can seamlessly access shared resources such as Teams shared channels without being represented as guests in your directory.

B2C (C) provides identity and access management for consumer-facing applications, letting customers sign in with local or social identities. Conditional Access (B) and Identity Protection (E) are Microsoft Entra ID security features that govern and protect sign-ins, but they are not components of the External Identities suite.

Exam trap

The trap here is that candidates often confuse security features like Conditional Access or Identity Protection with the core identity management components of the External Identities suite, because Microsoft bundles these services under the broader Microsoft Entra umbrella, but the exam specifically tests which services directly handle external user identity lifecycle and collaboration.

192
MCQmedium

An organization uses Microsoft Entra ID. They want to automatically detect when a user's sign-in shows a high risk of compromise (e.g., impossible travel, anonymous IP address) and immediately require the user to reset their password. Which Microsoft Entra capability should they use?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Access Reviews
AnswerB

Microsoft Entra ID Protection is the correct service for this scenario, as it specializes in detecting identity-based risks, including compromised credentials and suspicious sign-ins. It leverages machine learning to identify user and sign-in risks, and its risk-based policies can be configured to automatically enforce remediation actions. When a high user risk is detected, Identity Protection can be set to require a user to perform a secure password change as a self-remediation step, directly addressing the compromised identity.

Why this answer

B is correct because Microsoft Entra ID Identity Protection uses machine learning to detect risk signals such as impossible travel and anonymous IP addresses. When a user's sign-in is flagged as high risk, Identity Protection can be configured to automatically trigger a password reset as a remediation action, enforcing the principle of least privilege and reducing the window of compromise.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, but Conditional Access is the policy enforcement layer that can use Identity Protection risk detections as a condition, not the detection and remediation engine itself.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-in) based on conditions, but it does not itself detect risk signals or automatically trigger password resets; it relies on Identity Protection risk detections as a condition. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not user sign-in risk detection or password reset automation. Option D is wrong because Access Reviews are used for periodic attestation of group memberships or role assignments, not for real-time risk-based sign-in detection or password reset enforcement.

193
MCQmedium

Your company uses Microsoft Entra ID with P2 licenses. You want to require approval for users to activate the Global Administrator role. Which feature should you configure?

A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access
D.Access reviews
AnswerA

Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. It enables approval workflows for role activation, requiring users to request elevation and obtain approval before gaining temporary administrative rights. This directly addresses the need for a controlled and auditable process for activating privileged roles.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time privileged access, including the ability to require approval for role activation. By configuring PIM for the Global Administrator role, you can enforce that users must request activation and receive approval before gaining the role's permissions, ensuring least-privilege and auditability.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls sign-in conditions) with PIM's approval workflow, but Conditional Access cannot enforce a multi-step approval process for role activation; only PIM provides that capability.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and responding to identity risks (e.g., compromised accounts, risky sign-ins) and does not manage role activation workflows or approval requirements. Option C (Conditional Access) is wrong because it enforces access policies based on conditions like location or device state, but it does not provide approval-based role activation; it controls sign-in access, not role elevation. Option D (Access reviews) is wrong because it periodically recertifies existing role assignments, ensuring they are still needed, but it does not enforce an approval step for activating a role in real time.

194
Multi-Selecteasy

Which TWO Microsoft Entra features can be used to enforce multifactor authentication (MFA)?

Select 2 answers
A.Self-Service Password Reset
B.Security defaults
C.Identity Protection
D.Privileged Identity Management
E.Conditional Access
AnswersB, E

Security defaults are a foundational set of pre-configured identity security settings within Microsoft Entra ID designed to protect organizations from common identity-related attacks. When enabled, security defaults automatically enforce multi-factor authentication registration and usage for all users and administrators, requiring MFA for high-risk events and administrative tasks. This feature directly enforces MFA across the entire tenant, providing a strong baseline security posture.

Why this answer

Security defaults (B) is correct because it is a Microsoft Entra ID setting that, when enabled, automatically enforces MFA for all users, requiring them to register for MFA and use it at sign-in. Conditional Access (E) is correct because it lets administrators create policies that require MFA based on conditions such as user, group, application, location, or risk, making it the primary policy engine for enforcing MFA. Self-Service Password Reset (A) only allows users to reset or unlock their accounts and does not enforce MFA at sign-in.

Identity Protection (C) detects and reports risky sign-ins and users and can feed risk signals into Conditional Access, but by itself it does not enforce MFA. Privileged Identity Management (D) manages just-in-time role activation and approvals for privileged roles, not MFA enforcement for general sign-ins.

Exam trap

The trap here is that candidates often confuse Identity Protection or PIM as direct MFA enforcement features, when in reality they are risk-detection or privilege-management services that rely on Conditional Access to actually enforce MFA.

195
MCQhard

A healthcare organization uses Microsoft Entra ID and needs to enforce that only users from the United States and Canada can access patient records. Access attempts from all other locations must be blocked. Which Microsoft Entra ID Conditional Access condition should be configured to meet this requirement?

A.Device state
B.Sign-in risk
C.Locations
D.Client apps
AnswerC

The Locations condition in Microsoft Entra Conditional Access is specifically designed to control access based on the network location from which a user is attempting to sign in. Administrators can define 'named locations' using specific public IPv4 ranges, representing trusted corporate networks, or by selecting entire countries/regions, allowing for granular policies to grant access only from approved geographies or block access from high-risk areas. This directly addresses the need to restrict access based on a user's physical or network geographic location.

Why this answer

The Locations condition in Microsoft Entra ID Conditional Access allows administrators to define named locations (e.g., countries or IP ranges) and then grant or block access based on those locations. By configuring a policy that blocks access from all countries except the United States and Canada, the organization can enforce geographic restrictions on patient record access.

Exam trap

The trap here is that candidates often confuse the Locations condition with Sign-in risk, mistakenly thinking that blocking by country is a risk-based control rather than a straightforward geographic restriction.

How to eliminate wrong answers

Option A is wrong because Device state controls access based on whether a device is marked as compliant or hybrid Azure AD joined, not based on geographic location. Option B is wrong because Sign-in risk is a condition that detects suspicious sign-in behavior (e.g., anonymous IP, leaked credentials) and is used for risk-based policies, not for blocking by country. Option D is wrong because Client apps condition filters access by application type (e.g., browser, mobile app, legacy auth), not by the user's physical or network location.

196
MCQmedium

A company uses Microsoft Entra ID (Azure AD). They have a cloud-based HR system (e.g., Workday) that contains employee records. They want to automate the process of creating user accounts in Microsoft Entra ID for new hires and deactivating accounts for terminated employees based on information from the HR system. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra Connect
B.Microsoft Entra Application Provisioning
C.Self-Service Password Reset (SSPR)
D.Microsoft Entra Access Reviews
AnswerB

Microsoft Entra Application Provisioning is a robust feature designed to automate the end-to-end lifecycle management of user identities. It directly integrates with cloud-based Human Resources (HR) systems, such as Workday or SAP SuccessFactors, to automatically create, update, and delete user accounts in Microsoft Entra ID and connected SaaS applications. This automation streamlines onboarding and offboarding processes, ensuring that user access is consistently aligned with their employment status and reducing manual administrative overhead.

Why this answer

Microsoft Entra Application Provisioning (specifically HR-driven provisioning) is the correct feature because it automates the creation, update, and deactivation of user accounts in Microsoft Entra ID based on changes in an external HR system like Workday. It uses SCIM (System for Cross-domain Identity Management) protocol to synchronize employee lifecycle events from the HR source to Entra ID, enabling fully automated user provisioning without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (hybrid sync from on-prem AD) with HR-driven provisioning, but the question specifies a cloud-based HR system (Workday) with no on-premises AD involvement, making Application Provisioning the correct choice.

Why the other options are wrong

A

Microsoft Entra Connect is used for synchronizing on-premises Active Directory with Microsoft Entra ID, not for automating user provisioning from cloud HR systems like Workday.

C

Self-Service Password Reset (SSPR) allows users to reset their own passwords, but it does not automate the creation or deactivation of user accounts based on HR system data.

D

Access Reviews are used to review and certify existing access, not to automate the creation or deactivation of user accounts based on HR data.

197
MCQmedium

A company wants to allow its employees to reset forgotten passwords or unlock their accounts without contacting the help desk. The solution must verify the user's identity using a phone call or mobile app notification before allowing the action. Which Microsoft Entra ID feature should be enabled?

A.Microsoft Entra ID Protection
B.Self-Service Password Reset (SSPR)
C.Privileged Identity Management (PIM)
D.Conditional Access
AnswerB

Self-Service Password Reset (SSPR) is a core Microsoft Entra ID capability specifically designed to empower end-users to securely reset their forgotten passwords or unlock their own accounts without requiring IT helpdesk intervention. It leverages pre-registered authentication methods, such as mobile app notifications, phone calls, or security questions, to verify the user's identity before allowing the password change or account unlock. This significantly reduces helpdesk calls and improves user productivity by enabling immediate account recovery.

Why this answer

B is correct because Self-Service Password Reset (SSPR) enables users to reset forgotten passwords or unlock accounts without help desk intervention. It supports identity verification via phone call or mobile app notification (Microsoft Authenticator), meeting the stated requirement exactly.

Exam trap

The trap here is confusing SSPR with Conditional Access or ID Protection, as both involve authentication controls, but only SSPR directly provides the self-service password reset and account unlock functionality with phone call or app notification verification.

Why the other options are wrong

A

Microsoft Entra ID Protection is designed to detect and respond to identity risks, not to enable users to reset their own passwords or unlock accounts via phone call or app notification.

C

Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles in Microsoft Entra ID, but it does not provide self-service password reset or account unlock capabilities with phone call or mobile app verification.

D

Conditional Access is a policy engine that enforces access controls based on signals like user location or device state, but it does not directly provide the self-service password reset or account unlock functionality with phone call or mobile app verification.

198
MCQeasy

An organization wants to automatically revoke access to cloud apps when an employee leaves the company. Which Microsoft Entra feature should they use?

A.Conditional Access
B.Automated user provisioning
C.Privileged Identity Management
D.Identity Protection
AnswerB

Automated user provisioning, often managed by services like Azure AD Connect or Azure AD provisioning to SaaS apps, synchronizes identity data between authoritative sources and target applications. When a user's account is disabled or deleted in the authoritative source (e.g., HR system or on-premises AD), the provisioning service detects this change and automatically propagates it to connected applications. This process disables the user's account and revokes their access to those applications and their associated data, directly addressing the requirement for automatic access revocation upon termination.

Why this answer

Automated user provisioning (B) is the correct answer because it can automatically disable or remove a user's access to cloud apps when the user is deleted or deactivated in the HR system or on-premises directory. This feature synchronizes identity lifecycle events (e.g., termination) to connected SaaS applications, ensuring revocation of access without manual intervention.

Exam trap

The trap here is that candidates confuse Conditional Access (which blocks new sign-ins) with full deprovisioning, not realizing that Conditional Access does not terminate existing sessions or remove the user account from the cloud app.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces access policies based on signals like location or device compliance at sign-in time, but it does not automatically revoke access when an employee leaves; it blocks new sign-ins but does not terminate existing sessions or deprovision accounts. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged role activation and approval workflows, but it is not designed to deprovision standard user access to cloud apps upon termination. Option D is wrong because Identity Protection detects risks like leaked credentials or anomalous sign-ins and triggers remediation like requiring MFA, but it does not handle lifecycle-based deprovisioning when an employee leaves.

199
MCQeasy

Your company, Contoso, uses Microsoft Entra ID for employee identity management. You need to ensure that when an employee leaves the company, their access to all SaaS applications is automatically revoked within 24 hours. The HR department updates the employee status in a cloud HR system (Workday). What should you do?

A.Ask HR to manually disable each user in Microsoft Entra ID after termination.
B.Configure Microsoft Entra ID provisioning from Workday to automatically disable users when their employment status changes.
C.Use Microsoft Graph API to write a custom application that polls Workday and disables users.
D.Create an Azure Automation runbook that runs daily and checks Workday for terminated employees, then disables them in Entra ID.
AnswerB

Configuring Microsoft Entra ID provisioning from Workday leverages Workday as the authoritative system of record for employee status. This automated, event-driven integration uses the SCIM protocol to automatically update user accounts in Entra ID, including disabling them, immediately upon a status change in Workday. This ensures timely and accurate deprovisioning, consistently meeting the 24-hour requirement for access revocation and enhancing overall security and compliance.

Why this answer

Microsoft Entra ID supports automated user provisioning from Workday via the built-in Workday to Entra ID provisioning connector. When an employee's status changes to 'terminated' in Workday, the provisioning service automatically disables the corresponding user account in Entra ID, typically within 40 minutes (well under the 24-hour requirement). This eliminates manual intervention and ensures timely revocation of access to all SaaS applications integrated with Entra ID.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing custom development (C or D) or manual processes (A), failing to recognize that Microsoft provides a native, automated provisioning connector specifically designed for this exact HR-driven lifecycle scenario.

How to eliminate wrong answers

Option A is wrong because manually disabling users in Entra ID is inefficient, error-prone, and does not meet the automated 24-hour revocation requirement. Option C is wrong because using Microsoft Graph API to build a custom polling application is unnecessarily complex, requires development and maintenance overhead, and is not the recommended out-of-box solution when the native Workday provisioning connector exists. Option D is wrong because an Azure Automation runbook that polls Workday daily introduces latency (up to 24 hours) and requires custom scripting, whereas the native provisioning service provides near-real-time synchronization without additional infrastructure.

200
Multi-Selecteasy

Which TWO capabilities are part of Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Application management
B.Single sign-on (SSO)
C.Cloud security posture management
D.Mobile device management (MDM)
E.Security information and event management (SIEM)
AnswersA, B

Application management is a core Microsoft Entra ID capability, covering app registration, single sign-on configuration, provisioning and access policies for cloud and on-premises applications. It satisfies the stem's requirement by being one of the two listed capabilities genuinely delivered by the service, rather than by a separate product such as Defender or Purview.

Why this answer

Application management (A) is a core Microsoft Entra ID capability, allowing administrators to register, configure, and assign enterprise applications and manage app roles, permissions, and provisioning. Single sign-on (B) is also a native Entra ID feature, enabling users to authenticate once and access integrated SaaS and on-premises applications via protocols such as SAML, OAuth 2.0, and OpenID Connect. Cloud security posture management (C) belongs to Microsoft Defender for Cloud, not Entra ID.

Mobile device management (D) is provided by Microsoft Intune, and security information and event management (E) is delivered by Microsoft Sentinel, so neither is an Entra ID capability.

Exam trap

The trap here is that candidates confuse Microsoft Entra ID's identity and access management capabilities with broader security tools like Defender for Cloud (CSPM) or Sentinel (SIEM), or with device management tools like Intune (MDM), because all are part of Microsoft's security portfolio but serve distinct functions.

201
MCQeasy

You need to allow users to reset their own passwords without contacting the help desk. Which Microsoft Entra feature should you enable?

A.Microsoft Authenticator
B.Identity Governance
C.Self-service password reset
D.Conditional Access
AnswerC

Self-service password reset (SSPR) is a Microsoft Entra ID feature that allows users to reset or unlock their own passwords without requiring administrator or help desk intervention. Users are prompted to verify their identity using pre-registered authentication methods, such as a mobile app, phone call, or email, before they can set a new password. This capability significantly reduces help desk calls and improves user productivity by providing immediate password recovery.

Why this answer

Self-service password reset (SSPR) is the Microsoft Entra feature that allows users to reset their own passwords without contacting the help desk. It is designed to reduce help desk costs and improve user productivity by enabling password changes or unlocks through a verified authentication method, such as email, phone, or security questions.

Exam trap

The trap here is that candidates often confuse the authentication app (Microsoft Authenticator) with the self-service password reset feature, thinking the app itself provides password reset capabilities, when in fact it only provides a second factor for authentication.

How to eliminate wrong answers

Option A is wrong because Microsoft Authenticator is a multi-factor authentication app that provides a second factor for sign-in, not a self-service password reset mechanism. Option B is wrong because Identity Governance focuses on managing user access rights, certifications, and lifecycle, not on enabling users to reset their own passwords. Option D is wrong because Conditional Access is a policy engine that enforces access controls based on conditions like location or device state, but it does not provide a direct password reset capability.

202
MCQmedium

A company uses Microsoft Entra ID. The security team wants to allow users to sign in only from devices that are known and managed by the organization, and to block sign-ins from personal devices. They need to enforce this for all users accessing Microsoft 365 apps. What should they configure?

A.A Conditional Access policy that requires the device to be marked as compliant or Microsoft Entra hybrid joined.
B.Multi-factor authentication (MFA) registration for all users, enforced through Security Defaults.
C.A named location in Microsoft Entra ID that includes only the corporate network IP ranges, and a Conditional Access policy that blocks all other locations.
D.A Microsoft Entra ID Protection risk policy that blocks sign-ins with a high sign-in risk.
AnswerA

Conditional Access can evaluate device state as a condition. By requiring the device to be compliant or Microsoft Entra hybrid joined, only organizational devices allowed by Intune or joined to on-premises AD are permitted. This directly enforces the requirement to block personal devices for Microsoft 365 apps.

Why this answer

Conditional Access is the policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and app to make access decisions. Requiring the device to be compliant or Microsoft Entra hybrid joined ensures that only devices managed by the organization are granted access. This directly satisfies the need to block personal devices while allowing corporate-managed devices.

Exam trap

The trap here is confusing device-based Conditional Access with risk-based ID Protection policies, which assess compromise likelihood rather than device ownership.

203
MCQhard

Refer to the exhibit. An administrator runs the Azure CLI commands shown. What is the purpose of these commands?

A.To create a new service principal.
B.To list all Azure subscriptions.
C.To log in to Azure as a user with MFA.
D.To authenticate a service principal for automated tasks.
AnswerD

The `az login --service-principal` command is precisely engineered for non-interactive authentication, making it ideal for automated processes. By providing the application ID and either a client secret or certificate, it enables scripts, CI/CD pipelines, and other unattended applications to securely access Azure resources without human intervention. This method ensures programmatic access for tasks where a human user login is impractical or undesirable.

Why this answer

The Azure CLI commands shown are used to authenticate a service principal for automated tasks. Specifically, `az login --service-principal -u <app-id> -p <password> --tenant <tenant-id>` authenticates using the service principal's credentials without interactive user login, enabling non-interactive automation or scripts.

Exam trap

The trap here is that candidates confuse the `az login` command with creating a service principal, but `az ad sp create-for-rbac` is the command for creation, while `az login --service-principal` is strictly for authentication.

How to eliminate wrong answers

Option A is wrong because the commands do not create a new service principal; they authenticate an existing one using its app ID and password. Option B is wrong because the commands do not list Azure subscriptions; they perform a login operation, and listing subscriptions would require a separate command like `az account list`. Option C is wrong because the commands use `--service-principal` with a password, which bypasses MFA; MFA is only triggered for interactive user logins, not service principal authentication.

204
MCQmedium

A multinational corporation uses Microsoft Entra ID. The IT department wants to allow regional IT administrators in Europe to manage users and groups only for their own region, without granting them permissions to manage users in other regions. Which Microsoft Entra ID feature should they use?

A.A. Conditional Access
B.B. Administrative Units
C.C. Privileged Identity Management
D.D. Identity Governance
AnswerB

Administrative Units (AUs) in Microsoft Entra ID are designed to enable granular delegation of administrative responsibilities by allowing an organization to logically group a subset of users, groups, or devices. This feature is crucial for large enterprises or multinational corporations that need to assign specific administrative roles, such as User Administrator or Group Administrator, to regional IT staff. By scoping these roles to an AU, administrators can manage objects strictly confined to their assigned unit, preventing over-privileging and enhancing security.

Why this answer

Administrative Units (AUs) in Microsoft Entra ID allow you to delegate administrative permissions scoped to a subset of users, groups, or devices. By creating an AU for the Europe region and assigning regional IT administrators to it, you restrict their management scope to only those objects within that AU, preventing them from managing users in other regions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with scope delegation, not realizing that PIM controls when a role is activated, not where it can be applied.

Why the other options are wrong

A

Conditional Access is used to enforce access controls based on conditions like location or device state, not to delegate administrative permissions over specific subsets of users or groups.

C

Privileged Identity Management (PIM) provides time-based and approval-based role activation to manage privileged access, but it does not restrict administrative scope to specific regions or organizational boundaries. It cannot limit user/group management to a subset of users based on geography.

D

Identity Governance focuses on managing user access rights, certifications, and lifecycle, not on delegating administrative permissions to manage users and groups within specific boundaries like regions.

205
MCQhard

Your organization uses Microsoft Entra ID and has deployed Microsoft Entra ID Governance for entitlement management. You need to allow external partners to request access to a specific application, but only if they have a valid email address from an approved domain. Once approved, their access should automatically expire after 30 days. You also need to ensure that the partner's access is reviewed quarterly by the application owner. What should you configure?

A.Create an access package with a connected organization for the partner's domain, add the application as a resource, configure approval, set expiration to 30 days, and add a quarterly access review.
B.Create an access package with a connected organization for the partner's domain, add the application as a resource, configure approval, and set expiration to 30 days.
C.Create a dynamic group based on partner email domain and assign the application to the group with a 30-day expiration policy.
D.Add the partner as a guest user manually and assign the application directly with an expiration date.
AnswerA

Creating an access package with a connected organization is the optimal solution as it fully leverages Microsoft Entra ID Identity Governance capabilities. This approach allows the organization to define a self-service workflow for external partners from a specific domain, ensuring that access to the application is granted only after an approval process. The access package also enforces a 30-day expiration, automatically revoking access, and mandates a quarterly access review to continuously validate the necessity of ongoing access, thereby meeting all specified security and compliance requirements comprehensively.

Why this answer

It combines all required components: a connected organization restricts access to approved partner domains, the access package includes the application as a resource, approval ensures authorization, a 30-day expiration enforces automatic access removal, and a quarterly access review satisfies ongoing compliance. Microsoft Entra ID Governance entitlement management uses access packages to bundle resources, policies, and reviews for external collaboration.

Exam trap

The trap here is that candidates often confuse access packages with simple group-based assignment or manual guest user creation, overlooking that entitlement management's connected organization and policy-driven lifecycle are required to meet domain validation, automatic expiration, and recurring review requirements simultaneously.

How to eliminate wrong answers

Option B is wrong because it omits the quarterly access review, which is explicitly required for ongoing compliance and periodic attestation by the application owner. Option C is wrong because dynamic groups do not support expiration policies or access reviews natively; they are for automatic membership based on attributes, not for time-bound external access with governance workflows. Option D is wrong because manually adding guest users and assigning applications directly bypasses entitlement management's automated approval, expiration, and review capabilities, and does not enforce domain validation or quarterly reviews.

206
MCQmedium

A user is locked out of their account after multiple failed sign-in attempts. You need to reduce false lockouts while maintaining security. What should you do?

A.Require MFA for all users
B.Disable account lockout
C.Enable Smart Lockout
D.Increase lockout threshold to 20 attempts
AnswerC

Enabling Smart Lockout is the most effective solution because it leverages cloud intelligence and machine learning to differentiate between legitimate users making typos and malicious attackers. Instead of a static threshold, Smart Lockout tracks failed sign-in attempts across various IP addresses and locations. It intelligently locks out suspicious attempts from unfamiliar sources while allowing a legitimate user to continue trying from a known location, significantly reducing false lockouts without compromising security.

Why this answer

Microsoft Entra Smart Lockout is designed to protect against brute-force attacks while reducing false lockouts for legitimate users. It uses a combination of familiar location and unfamiliar location thresholds to differentiate between malicious attempts and valid users who may have mistyped their password. Enabling Smart Lockout allows you to set a higher threshold for familiar locations and a lower threshold for unfamiliar locations, thus maintaining security without locking out legitimate users.

The other options either do not address false lockouts (MFA) or weaken security (disabling lockout, increasing threshold globally).

Exam trap

SC-900 often tests the misconception that increasing the lockout threshold or disabling lockout is a good way to reduce false lockouts, when the correct answer is to use Smart Lockout, which intelligently differentiates based on location.

How to eliminate wrong answers

Option A is wrong because requiring MFA for all users adds a security layer but does not directly reduce false lockouts from failed sign-in attempts; it may even increase lockouts if MFA prompts fail. Option B is wrong because disabling account lockout entirely removes protection against brute-force attacks, which is a security risk. Option D is wrong because increasing the lockout threshold to 20 attempts globally makes it easier for attackers to guess passwords and does not differentiate between familiar and unfamiliar locations, so it does not intelligently reduce false lockouts.

207
MCQhard

A company uses Microsoft Entra ID and Intune for mobile device management. They want to enforce different access requirements for their finance application: when users access from an unmanaged personal device, they must perform multi-factor authentication (MFA). When they access from a corporate-managed device that is marked as compliant (e.g., joined to Azure AD, antivirus up-to-date, encryption enabled), MFA should not be required. Device compliance is reported by Intune. Which Microsoft Entra ID feature should they use to define these rules?

A.Identity Protection risk policies
B.Conditional Access policies
C.Privileged Identity Management (PIM)
D.Intune device compliance policies
AnswerB

Conditional Access policies in Microsoft Entra ID are the enforcement engine that evaluates various signals, including device compliance status reported by Intune, user location, and sign-in risk. Based on these conditions, a policy can then enforce specific access controls, such as requiring multi-factor authentication (MFA), blocking access, or requiring a compliant device. This directly addresses the need to control access and enforce MFA based on device state.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define granular access rules based on signals such as user, device, location, and application. In this scenario, the policy can be configured to require MFA when the device is not marked as compliant (e.g., unmanaged personal device) and to allow access without MFA when the device is reported as compliant by Intune. This is the correct feature because it directly evaluates device compliance status from Intune and enforces the specified access requirements.

Exam trap

The trap here is that candidates often confuse Intune device compliance policies (which define the rules for compliance) with Conditional Access policies (which enforce access decisions based on that compliance status), leading them to select Option D instead of the correct feature that actually enforces the MFA requirement.

Why the other options are wrong

A

Identity Protection risk policies focus on user and sign-in risk (e.g., leaked credentials, anonymous IP) to trigger MFA or block access, not on device compliance or management status. The question requires differentiating access based on device compliance (managed vs. unmanaged), which is a Conditional Access condition, not a risk policy.

C

Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not access rules based on device compliance or MFA requirements for applications.

D

Intune device compliance policies define the compliance requirements (e.g., antivirus, encryption) but do not enforce access rules like requiring MFA based on device compliance status. Conditional Access policies are needed to combine compliance status with access controls.

208
MCQmedium

Your organization is using Microsoft Entra ID with P2 licenses. You need to enforce a policy that requires administrators to request approval before activating their privileged roles, and approvals must expire after 8 hours. Additionally, you need to ensure that all privileged role activations are logged for auditing. Which combination of Microsoft Entra capabilities should you use?

A.Implement Identity Protection user risk policy to block high-risk admins, and use sign-in logs.
B.Configure Privileged Identity Management (PIM) for role activation with approval and expiration, and use PIM audit logs.
C.Create a Conditional Access policy requiring multi-factor authentication for admins, and use activity logs.
D.Set up Azure AD Access Reviews to require monthly review of privileged roles, and enable diagnostic settings.
AnswerB

Configuring Privileged Identity Management (PIM) directly addresses the need for just-in-time (JIT) access to privileged roles. PIM allows administrators to activate roles only when needed, for a specified duration, and can enforce approval workflows and multi-factor authentication during activation. The comprehensive PIM audit logs provide a detailed record of all role activations, approvals, and deactivations, ensuring accountability and compliance with least privilege principles.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time role activation with configurable approval workflows and expiration durations, meeting the requirement for administrators to request approval and for approvals to expire after 8 hours. PIM audit logs capture all activation events, including who approved, when, and for which role, fulfilling the auditing requirement. This combination directly addresses the policy needs without relying on unrelated capabilities like user risk policies or access reviews.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control sign-in conditions) with PIM (which controls role activation), leading them to choose Option C because they think MFA enforcement is sufficient for privileged role security.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policy blocks users based on risk level, not role activation approval or expiration, and sign-in logs do not capture privileged role activation events. Option C is wrong because Conditional Access policies enforce authentication requirements like MFA during sign-in, not role activation approval workflows or expiration, and activity logs lack the granularity of PIM-specific activation auditing. Option D is wrong because Azure AD Access Reviews are for periodic attestation of role membership, not for controlling activation with approval and expiration, and diagnostic settings export logs but do not enforce the approval or expiration policy.

209
MCQmedium

Your company, Wingtip Toys, uses Microsoft Entra ID with a Premium P1 license. You have a third-party SaaS application that supports Security Assertion Markup Language (SAML) 2.0. You need to enable single sign-on (SSO) for users to access this application. The app requires attributes like department and employee ID in the SAML token. You also need to ensure that only users from a specific security group can access the app. What should you do?

A.Register the app using OpenID Connect and assign users to the app.
B.Add the app from the gallery using password-based SSO and configure group assignment.
C.Use Microsoft Entra Application Proxy to publish the app and configure pre-authentication.
D.Add the app from the gallery as a SAML application, configure claims mapping to include department and employee ID, and assign the app to the security group.
AnswerD

Adding the application from the Microsoft Entra gallery as a SAML application is the correct approach, as it aligns with the third-party app's supported authentication protocol. Configuring claims mapping allows for the precise inclusion of required attributes like department and employee ID within the SAML assertion sent to the service provider. Finally, assigning the app to a security group ensures efficient and scalable management of user access, meeting all specified requirements for secure and attribute-rich single sign-on.

Why this answer

With Microsoft Entra ID Premium P1, you can add the SaaS application from the gallery as a SAML application, configure custom claims to include department and employee ID in the SAML token, and assign the application to the security group. OpenID Connect is not SAML SSO. Password-based SSO cannot provide SAML attributes.

Application Proxy is used for on-premises applications, not SaaS apps.

Exam trap

Don't confuse SAML SSO with OpenID Connect, password-based SSO, or Application Proxy. Also remember that custom SAML claims mapping requires Microsoft Entra ID Premium P1 or P2.

How to eliminate wrong answers

Option A is wrong because OpenID Connect is an authentication protocol built on OAuth 2.0, not SAML 2.0, and it does not support the SAML token format or custom SAML attribute claims required by the app. Option B is wrong because password-based SSO does not use SAML tokens and cannot include custom attributes like department and employee ID in a token; it relies on form-fill or credential injection, not SAML assertions. Option C is wrong because Microsoft Entra Application Proxy is used for publishing on-premises apps, not for third-party SaaS applications, and it does not provide SAML token customization or gallery-based SAML configuration.

210
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically block sign-ins from users whose credentials have been compromised and require them to change their password before access is granted. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra ID Protection
B.Conditional Access policies
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerA

Microsoft Entra ID Protection is specifically designed to detect and remediate identity-based risks, including compromised credentials. It leverages machine learning to identify suspicious activities like leaked credentials, anomalous sign-ins, and impossible travel. Upon detection, it can automatically enforce policies such as blocking sign-ins, requiring multi-factor authentication, or prompting for a password change, thereby directly protecting against credential compromise.

Why this answer

Microsoft Entra ID Protection is the correct capability because it automatically detects compromised credentials by analyzing telemetry from Microsoft's Threat Intelligence and the wider ecosystem. When a user's credentials are found in a known leak, Entra ID Protection can enforce a policy that blocks sign-in and requires the user to change their password via an integrated remediation workflow, directly addressing the scenario.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with risk-based policies, but Conditional Access alone cannot detect compromised credentials or enforce password changes—it requires Entra ID Protection as the risk signal source.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies are a decision engine that enforces access controls based on signals (like location or device state), but they do not inherently detect compromised credentials or trigger password changes; they rely on other services like Entra ID Protection for risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation, access reviews, and auditing for administrative roles, not on detecting or remediating compromised user credentials. Option D is wrong because Self-Service Password Reset (SSPR) allows users to voluntarily reset their own passwords, but it does not automatically block sign-ins or force a password change based on compromised credential detection; it requires user initiation.

211
MCQmedium

An organization uses Microsoft Entra ID and wants to require users to re-authenticate every 4 hours when accessing a critical financial application, even if the user already has an active sign-in session. Which Conditional Access control should be configured?

A.Grant control 'Require multi-factor authentication'
B.Session control 'Sign-in frequency'
C.Session control 'Persistent browser session'
D.Grant control 'Require device to be marked as compliant'
AnswerB

The 'Sign-in frequency' session control directly addresses the requirement to force re-authentication after a specific time interval. This control mandates that users must re-enter their credentials, potentially including MFA, after a defined period (e.g., 4 hours), even if their session is still active and valid. It ensures periodic re-verification of identity throughout the user's workday, enhancing security by limiting the window of compromise for a stolen session token.

Why this answer

The 'Sign-in frequency' session control in Conditional Access allows administrators to specify the time interval after which a user must re-authenticate, even if they have an active session. By setting this to 4 hours, the organization ensures that users re-authenticate before accessing the critical financial application, overriding any existing session tokens.

Exam trap

The trap here is confusing session controls (which manage token lifetime and re-authentication behavior) with grant controls (which enforce conditions at initial sign-in), leading candidates to select 'Require multi-factor authentication' thinking it will force periodic re-authentication.

How to eliminate wrong answers

Option A is wrong because 'Require multi-factor authentication' is a grant control that enforces an additional verification factor at sign-in, but it does not enforce a re-authentication interval; once MFA is satisfied, the session persists until token expiry. Option C is wrong because 'Persistent browser session' controls whether the browser keeps the user signed in after closing, not the frequency of re-authentication during an active session. Option D is wrong because 'Require device to be marked as compliant' ensures the device meets compliance policies (e.g., OS updates, antivirus), but it does not enforce a time-based re-authentication requirement.

212
MCQeasy

You are viewing an application registration in Microsoft Entra ID. What can you conclude about this app?

A.The app is disabled and cannot be used
B.The app is a single-tenant application that is enabled but has no app roles defined
C.The app has custom roles for role-based access
D.The app is multi-tenant and can be used by other tenants
AnswerB

This statement is correct as it accurately describes the application's configuration. The 'signInAudience' property being set to 'AzureADMyOrg' confirms it is a single-tenant application, restricted to users within the registering tenant. Furthermore, the 'AppRoles' collection is empty, indicating that no custom application-specific roles have been defined for granular access control within the application itself, while the 'Enabled' status is 'True'.

Why this answer

The application registration shows 'App roles' with a value of 0, which means no app roles are defined. The 'Supported account types' setting indicates 'Accounts in this organizational directory only', confirming it is a single-tenant application. The 'Enabled for users to sign-in?' toggle is set to 'Yes', so the app is enabled and can be used.

Exam trap

The trap here is that candidates often confuse a disabled app (where the 'Enabled for users to sign-in?' toggle is set to 'No') with an app that has no app roles defined, leading them to incorrectly select option A when the app is actually enabled but lacks roles.

How to eliminate wrong answers

Option A is wrong because the 'Enabled for users to sign-in?' toggle is set to 'Yes', meaning the app is enabled and can be used. Option C is wrong because the 'App roles' count is 0, indicating no custom roles are defined; custom roles would require at least one app role to be listed. Option D is wrong because the 'Supported account types' is set to 'Accounts in this organizational directory only', which explicitly restricts the app to a single tenant, not multi-tenant.

213
MCQeasy

An organization wants to allow users to reset their own passwords without help desk intervention. Which Microsoft Entra feature should they enable?

A.Conditional Access
B.Self-service password reset
C.Privileged Identity Management
D.Identity Protection
AnswerB

Self-service password reset (SSPR) is the dedicated Azure AD feature that empowers users to securely reset their own forgotten or expired passwords without requiring administrator intervention. Users must first register and verify authentication methods, such as a mobile phone or alternate email, which are then used to confirm their identity during the reset flow. This capability directly addresses the organization's need to allow users to manage their own passwords, enhancing both security and user productivity.

Why this answer

Self-service password reset (SSPR) is the Microsoft Entra feature specifically designed to allow users to reset their own passwords without requiring help desk intervention. It enforces security through authentication methods (e.g., phone, email, security questions) and can be configured to meet organizational policies. This directly addresses the scenario of reducing help desk workload for password resets.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access after authentication) with SSPR (which handles the password reset process itself), leading them to select A because they think 'self-service' implies a policy-based control.

How to eliminate wrong answers

Option A is wrong because Conditional Access is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals like user, device, or location — it does not provide a mechanism for users to reset their own passwords. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation, approval workflows, and access reviews for elevated roles; it does not handle end-user password resets. Option D is wrong because Identity Protection uses risk detection (e.g., leaked credentials, anonymous IP addresses) to trigger automated responses like blocking sign-ins or requiring MFA — it does not enable users to reset their own passwords.

214
MCQmedium

Your organization uses Microsoft Entra ID. You need to ensure that only users from the finance department can access a sensitive application, and they must be granted access dynamically based on their department attribute. What should you configure?

A.Create an administrative unit for the finance department.
B.Create a dynamic group with rule: user.department -eq "Finance".
C.Enable self-service group management.
D.Configure entitlement management with an access package for the finance application.
AnswerB

Creating a dynamic group with the rule user.department -eq "Finance" directly fulfills the requirement for automatic group membership. Microsoft Entra ID dynamic groups continuously evaluate user attributes against defined rules, automatically adding users whose 'department' attribute matches "Finance" and removing those who no longer meet the criteria. This ensures that the group membership remains accurate and up-to-date without manual intervention, significantly reducing administrative overhead. This feature requires a Microsoft Entra ID P1 or P2 license.

Why this answer

A dynamic group in Microsoft Entra ID automatically adds or removes members based on a rule, such as `user.department -eq "Finance"`. This ensures that only users whose department attribute equals "Finance" are granted access to the sensitive application, and membership updates dynamically as the attribute changes, without manual intervention.

Exam trap

The trap here is that candidates often confuse administrative units (which manage administrative boundaries) with dynamic groups (which manage access based on attributes), leading them to select Option A instead of the correct dynamic group solution.

How to eliminate wrong answers

Option A is wrong because administrative units are used to delegate administrative scopes (e.g., managing users in a specific department), not to control access to applications dynamically based on user attributes. Option C is wrong because self-service group management allows users to create and manage their own groups, but it does not enforce dynamic membership rules based on the department attribute; it relies on manual or approval-based membership. Option D is wrong because entitlement management with access packages provides a governance framework for requesting and approving access, but it does not automatically assign membership based on a dynamic attribute like department; it typically requires manual assignment or approval workflows.

215
MCQhard

A company uses Microsoft Entra ID Privileged Identity Management (PIM) to manage elevated access to Microsoft Entra ID roles. They want to ensure that a user who activates a privileged role must provide a justification and receive approval from their manager before activation is complete. Which PIM configuration should be used?

A.Configure role settings to require multi-factor authentication on activation
B.Configure role settings to require approval on activation
C.Configure role settings to assign the user as permanently active
D.Configure role settings to require an Microsoft Entra ID compliant device
AnswerB

Configuring role settings to require approval on activation directly addresses the need for a manager to authorize privileged access. When a user attempts to activate a role, Microsoft Entra ID PIM routes the request to predefined approvers, who are typically managers or security administrators. The role remains inactive until at least one designated approver explicitly grants permission, ensuring an independent review and authorization before elevated privileges are granted.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) allows administrators to configure role settings that require approval before a role is activated. By enabling the 'Require approval to activate' setting, a designated approver (such as the user's manager) must review and approve the activation request, ensuring that the justification is validated before access is granted.

Exam trap

The trap here is that candidates often confuse 'require approval' with 'require MFA' or 'require compliant device,' not realizing that only the approval setting introduces a separate review step by another person, which is explicitly needed for manager authorization.

How to eliminate wrong answers

Option A is wrong because requiring multi-factor authentication (MFA) on activation enforces additional identity verification but does not involve a separate approval workflow or manager review. Option C is wrong because assigning the user as permanently active eliminates the need for activation entirely, bypassing both justification and approval requirements. Option D is wrong because requiring a Microsoft Entra ID compliant device enforces device health policies but does not implement an approval process for role activation.

216
MCQmedium

A company requires that all users accessing a financial application from outside the corporate network must complete multi-factor authentication (MFA). The IT team is configuring a Microsoft Entra ID Conditional Access policy to enforce this requirement. Which component of the policy should be configured to apply the MFA requirement?

A.Conditions
B.Assignments
C.Session controls
D.Grant controls
AnswerD

Grant controls are the specific mechanisms within a Conditional Access policy that determine how access is granted or denied, and what requirements must be satisfied before access is permitted. By configuring 'Require multi-factor authentication' under Grant controls, the policy explicitly mandates that users must successfully complete an MFA challenge before they can gain access to the protected resource. This directly enforces the MFA requirement, making it the correct choice for this scenario.

Why this answer

Grant controls are the component of a Conditional Access policy that enforce the actual access requirements, such as requiring multi-factor authentication (MFA). By configuring the 'Require multi-factor authentication' checkbox under Grant controls, the policy ensures that users must complete MFA before accessing the financial application. This is the correct setting to apply the MFA requirement.

Exam trap

The trap here is confusing Grant controls (which enforce the MFA requirement) with Conditions (which define the 'when' of the policy), leading candidates to incorrectly select Conditions because they think it controls the MFA trigger rather than the enforcement action.

Why the other options are wrong

A

Conditions define when the policy applies (e.g., location, device state), not what happens when conditions are met. The MFA requirement is enforced via Grant controls, which specify the access requirements.

B

Assignments define which users, groups, or applications the policy applies to, not what happens after access is granted. The MFA requirement is enforced via Grant controls, which specify the conditions that must be met for access.

C

Session controls manage user experience during a session (e.g., sign-in frequency, app restrictions), not enforce MFA. MFA enforcement is done via Grant controls, which require specific conditions to be met before access is granted.

217
MCQeasy

You need to provide external partners with access to your organization's SharePoint site. The partners must use their own credentials. Which Microsoft Entra feature should you use?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra Identity Governance
C.Privileged Identity Management
D.Microsoft Entra ID Protection
AnswerA

Microsoft Entra B2B collaboration is the correct solution for securely providing external partners with access to your organization's resources. It enables guest users to sign in using their own existing identities, such as work, school, or social accounts, without requiring them to create new credentials in your tenant. This streamlined process facilitates collaboration by inviting external users to access specific applications or documents while maintaining administrative control over their permissions.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it enables external users (partners) to access your organization's resources using their own identities (e.g., work, social, or other Azure AD accounts). It leverages the existing Azure AD tenant to issue guest user objects and supports SAML/WS-Federation or OIDC for authentication, allowing partners to authenticate with their own credentials without requiring a separate account or password in your tenant.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C (not listed), or mistakenly think Identity Governance or PIM can handle external authentication, when in fact B2B collaboration is the only feature that allows external users to bring their own credentials for resource access.

How to eliminate wrong answers

Option B (Microsoft Entra Identity Governance) is wrong because it focuses on managing the lifecycle of identities and access rights (e.g., access reviews, entitlement management) but does not itself provide the mechanism for external users to authenticate with their own credentials. Option C (Privileged Identity Management) is wrong because it is designed to manage, control, and monitor privileged roles and just-in-time access within your own directory, not to enable external authentication. Option D (Microsoft Entra ID Protection) is wrong because it is a security tool that detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not facilitate external user sign-in with their own credentials.

218
MCQeasy

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without help desk intervention, while maintaining security by requiring multi-factor authentication (MFA) during the reset process. Which feature should you enable?

A.Microsoft Entra Identity Protection.
B.Microsoft Entra Multi-Factor Authentication.
C.Conditional Access policies.
D.Microsoft Entra self-service password reset (SSPR).
AnswerD

Microsoft Entra self-service password reset (SSPR) is a crucial feature that empowers users to reset their forgotten or locked passwords without administrator intervention. SSPR can be configured to require users to verify their identity through multiple authentication methods, including MFA, before they can successfully reset their password, thereby enhancing both convenience and security for password management within the organization.

Why this answer

Microsoft Entra self-service password reset (SSPR) is the feature specifically designed to allow users to reset their own passwords without help desk intervention. When combined with Microsoft Entra Multi-Factor Authentication (MFA) as a registration and reset requirement, SSPR enforces MFA during the reset process, meeting both the self-service and security requirements.

Exam trap

The trap here is that candidates often confuse the authentication enforcement mechanism (MFA or Conditional Access) with the actual self-service reset feature, mistakenly selecting MFA or Conditional Access instead of SSPR, which is the only option that directly provides the password reset functionality.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection is a risk-based detection and remediation service that can trigger automated responses (e.g., requiring MFA or blocking sign-ins) but does not itself enable users to reset passwords. Option B is wrong because Microsoft Entra Multi-Factor Authentication alone provides an additional verification step during authentication but does not include the self-service password reset capability. Option C is wrong because Conditional Access policies enforce access controls (e.g., requiring MFA or blocking locations) based on conditions, but they do not directly enable users to reset their own passwords.

219
MCQeasy

Your company uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts. Which Microsoft Entra feature should you configure?

A.Microsoft Entra External ID
B.Microsoft Entra B2B collaboration
C.Conditional Access policies
D.Privileged Identity Management
AnswerA

Microsoft Entra External ID is the comprehensive solution for managing all external identities, including customers, partners, and citizens, across various applications. It specifically supports integrating social identity providers like Google, Facebook, and Microsoft accounts, as well as enterprise identity providers, allowing users to sign in to your applications using their existing credentials. This capability is crucial for consumer-facing applications that require flexible and convenient sign-up and sign-in experiences without creating new accounts.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2C) is the correct feature because it is specifically designed to enable external identities, including social identity providers like Google, Facebook, and Microsoft accounts, for customer-facing applications. It supports standards such as OAuth 2.0 and OpenID Connect to allow users to sign in with their existing social media accounts without needing a separate Microsoft Entra ID account.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration (for business partners) with Microsoft Entra External ID (for customers/consumers), mistakenly thinking B2B can also handle social identity providers, but B2B only supports organizational accounts (e.g., work/school) and not social logins.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2B collaboration is designed for business-to-business scenarios, allowing external business partners to access your organization's resources using their own corporate identities, not for consumers signing in with social media accounts. Option C is wrong because Conditional Access policies are used to enforce access controls (e.g., MFA, location) after authentication, not to configure identity providers or enable social sign-in. Option D is wrong because Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within Microsoft Entra ID, and has no role in configuring external or social identity providers.

220
MCQhard

Refer to the exhibit. The Conditional Access policy shown is applied to all users accessing Office 365. A user with a compliant device but no MFA registered attempts to access Exchange Online. What will happen?

A.Access is blocked
B.Access is granted because the policy is only for Office 365 and the user uses Exchange Online
C.Access is granted after MFA registration prompt
D.Access is granted because the device is compliant
AnswerA

This policy explicitly requires both multi-factor authentication (MFA) and a compliant device as grant controls. For access to be permitted, all specified grant controls must be satisfied simultaneously. Since the user has not registered for MFA, this critical requirement is not met, leading to the conditional access policy blocking the access attempt.

Why this answer

The Conditional Access policy requires MFA registration for all users accessing Office 365 cloud apps. Since the user has not registered MFA, the policy's grant control (Require MFA registration) is not satisfied, and the policy blocks access. The device compliance status is irrelevant because the policy does not include device compliance as a grant control.

Exam trap

The trap here is that candidates assume a compliant device automatically satisfies Conditional Access policies, but the policy explicitly requires MFA registration, and device compliance is irrelevant unless included as a grant control.

How to eliminate wrong answers

Option B is wrong because Exchange Online is included under Office 365 in the Conditional Access policy's cloud apps assignment, so the policy applies to Exchange Online access. Option C is wrong because the policy does not grant access with an MFA registration prompt; it blocks access when the MFA registration requirement is not met. Option D is wrong because the policy does not have a 'Require compliant device' grant control, so device compliance alone does not satisfy the policy's requirements.

221
Multi-Selectmedium

Which TWO Microsoft Entra features can be used together to enforce risk-based conditional access?

Select 2 answers
A.Entra Verified ID
B.Conditional Access
C.Identity Protection
D.Self-Service Password Reset
E.Privileged Identity Management
AnswersB, C

Microsoft Entra Conditional Access is a policy engine that evaluates conditions, including user and sign-in risk levels detected by Identity Protection, to enforce specific access controls. It allows administrators to define "if-then" statements, such as "if a user is signing in from a risky location, then block access or require multi-factor authentication." This direct integration makes it crucial for implementing risk-based access policies.

Why this answer

Conditional Access (B) is correct because it is the policy engine that enforces access decisions based on signals, including risk levels. Identity Protection (C) is correct because it detects and calculates user and sign-in risk in real time using machine learning. Together, Identity Protection provides the risk assessment, and Conditional Access enforces the policy (e.g., block or require MFA) based on that risk.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with risk-based access, but PIM controls role activation, not risk evaluation, while Identity Protection is the dedicated risk detection service.

222
MCQmedium

A company uses Microsoft Entra ID and Intune for device management. The security team wants to create a Conditional Access policy for a sensitive research application. They require that: 1) The user must use a device that is marked as compliant by Intune, and 2) The user must accept the company's terms of use before accessing the app. Which grant control combination should they configure in the policy?

A.Select 'Require device to be marked as compliant' and 'Require terms of use' and choose 'Require one of the selected controls'
B.Select 'Require multi-factor authentication' and 'Require terms of use' and choose 'Require all the selected controls'
C.Select 'Require device to be marked as compliant' and 'Require terms of use' and choose 'Require all the selected controls'
D.Select only 'Require terms of use' and configure device compliance as a condition
AnswerC

This is the correct configuration because Microsoft Entra Conditional Access policies use 'Grant controls' to define the specific requirements for access. Selecting both 'Require device to be marked as compliant' (which leverages Intune's compliance policies) and 'Require terms of use' as grant controls, combined with the 'Require all the selected controls' operator, ensures that users must satisfy both prerequisites simultaneously to gain access to resources. This precisely fulfills the scenario's need for both device compliance and terms of use acceptance.

Why this answer

The policy requires both conditions—device compliance and terms of use—to be enforced simultaneously. In Microsoft Entra Conditional Access, when multiple grant controls are selected and set to 'Require all the selected controls', the user must satisfy every control to gain access. This matches the security team's requirement that the device must be compliant AND the terms of use must be accepted.

Exam trap

The trap here is that candidates often confuse 'Require one of the selected controls' with 'Require all the selected controls', mistakenly thinking that 'one of' is sufficient when the question explicitly states both conditions must be met.

Why the other options are wrong

A

The policy requires both device compliance and terms of use to be enforced simultaneously, so 'Require one of the selected controls' would allow access if only one condition is met, violating the requirement.

B

The policy requires both device compliance and terms of use, so 'Require all the selected controls' is needed. Option B incorrectly includes multi-factor authentication, which is not required, and uses 'Require one of the selected controls', which would allow bypassing one requirement.

D

Option D is wrong because it omits the 'Require device to be marked as compliant' grant control, which is explicitly required by the policy. Configuring device compliance as a condition only affects when the policy applies, not the grant requirements.

223
MCQmedium

A company wants to securely grant external business partners access to internal SharePoint sites and Teams channels. The partners use various identity providers, including Google and Microsoft personal accounts. The company needs to manage these external identities in their Microsoft Entra ID directory and enforce access policies. Which Microsoft Entra capability should they use?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra B2C (Business-to-Consumer)
C.Microsoft Entra Connect
D.Microsoft Entra Identity Protection
AnswerA

Microsoft Entra B2B collaboration is the correct solution for securely granting external business partners access to internal resources. This service enables organizations to invite external users, such as partners or vendors, to access specific applications and data within their Microsoft Entra tenant as guest users. It supports various identity providers, allowing partners to use their existing corporate or social credentials for authentication, thereby streamlining access while maintaining strong security controls over the shared resources.

Why this answer

Microsoft Entra B2B collaboration is designed to securely share applications and resources with external guest users from any identity provider, including Google and Microsoft personal accounts. It allows the company to manage these external identities in their Entra ID directory and enforce conditional access policies, meeting the requirement to grant partners access to SharePoint and Teams.

Exam trap

The trap here is confusing B2B collaboration (for business partners) with B2C (for customers), leading candidates to select B2C because it also supports external identities, but B2C is not designed for internal resource sharing like SharePoint or Teams.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2C is a customer-facing identity management service for external customers, not for business partners, and it does not integrate with internal resources like SharePoint or Teams. Option C is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory identities to the cloud, not to manage external partner identities. Option D is wrong because Microsoft Entra Identity Protection is a risk-detection and remediation tool for user accounts, not a solution for inviting or managing external identities.

224
MCQeasy

Your organization uses Microsoft Entra ID P1. You need to implement a solution that allows users to reset their own passwords without administrator intervention. The solution must also enforce a policy that requires users to verify their identity with two methods before resetting. What should you configure?

A.Configure Privileged Identity Management (PIM) to require approval for password reset.
B.Create an Identity Protection user risk policy to force password reset.
C.Configure a Conditional Access policy to require MFA for password changes.
D.Enable self-service password reset (SSPR) and configure the number of methods required to reset to 2.
AnswerD

Enabling Microsoft Entra ID Self-Service Password Reset (SSPR) directly addresses the requirement for users to reset their forgotten passwords without administrator intervention. By configuring the number of authentication methods required to 2, the organization enhances the security of the reset process, ensuring that users provide multiple proofs of identity (e.g., mobile app notification and phone call) before gaining access. This feature is precisely designed for secure, user-initiated password recovery.

Why this answer

Self-service password reset (SSPR) in Microsoft Entra ID P1 allows users to reset their own passwords without administrator intervention. By configuring SSPR and setting the number of methods required to reset to 2, you enforce the policy that users must verify their identity with two authentication methods before resetting their password.

Exam trap

The trap here is that candidates often confuse Conditional Access MFA policies with SSPR's multi-method verification, not realizing that SSPR has its own separate configuration for the number of required verification methods, while Conditional Access policies apply to authentication events, not the password reset workflow.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is used for managing, controlling, and monitoring access to privileged roles, not for enabling self-service password reset or enforcing multi-method verification for password resets. Option B is wrong because Identity Protection user risk policies trigger automatic password resets based on detected user risk, but they do not allow users to initiate their own password resets without administrator intervention, nor do they enforce a specific number of verification methods for the reset process. Option C is wrong because a Conditional Access policy requiring MFA for password changes would force users to authenticate with MFA when changing their password, but it does not enable self-service password reset; it only secures the change action, not the reset flow, and does not configure the number of methods required for reset.

225
MCQmedium

The exhibit shows a sign-in failure for John Doe. The admin wants to allow the sign-in while still enforcing MFA. What should the admin do?

A.Modify the Conditional Access policy to exclude Azure PowerShell or to support MFA for this client.
B.Disable MFA for the user.
C.Assign a Microsoft Entra ID P2 license to the user.
D.Reset the user's password.
AnswerA

This option correctly identifies that the sign-in failure for John Doe, an admin using Azure PowerShell, is likely due to a Conditional Access policy requiring Multi-Factor Authentication (MFA) that the client cannot satisfy. Azure PowerShell, especially older versions or specific cmdlets, may not fully support modern authentication flows required for MFA. Modifying the policy to either exclude this specific application from the MFA requirement or ensuring the client is updated and configured to properly handle MFA challenges would resolve the access issue while maintaining overall security for other access methods.

Why this answer

The sign-in failure is likely caused by a Conditional Access policy that blocks legacy authentication protocols like Azure PowerShell, which do not support MFA natively. Option A is correct because modifying the policy to exclude Azure PowerShell or to require MFA for that client app allows the sign-in while still enforcing MFA for other protocols. This ensures the user can authenticate using a modern authentication flow that supports MFA.

Exam trap

The trap here is that candidates may think resetting the password or disabling MFA is the quick fix, but the core issue is that the Conditional Access policy is blocking a client that cannot perform MFA, not that the user's credentials or license are invalid.

How to eliminate wrong answers

Option B is wrong because disabling MFA for the user removes the security requirement entirely, contradicting the admin's goal to still enforce MFA. Option C is wrong because assigning a Microsoft Entra ID P2 license provides advanced features like Identity Protection and Privileged Identity Management, but it does not directly resolve a sign-in failure caused by a Conditional Access policy blocking a non-MFA-capable client. Option D is wrong because resetting the user's password does not address the underlying policy that blocks the sign-in; the failure is due to the client app not supporting MFA, not due to incorrect credentials.

← PreviousPage 3 of 5 · 338 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Entra Capabilities questions.