Courseiva

CCNA Entra Capabilities Questions

38 of 338 questions · Page 5/5 · Entra Capabilities topic · Answers revealed

301
MCQmedium

A company uses Microsoft Entra ID and Intune to manage devices. They want to enforce a policy that allows access to financial data from SharePoint Online only when the user's device is compliant (e.g., encrypted, patched) AND the user authenticates from a trusted IP address range. Additionally, if the sign-in risk is assessed as medium or high by Identity Protection, the user must also perform multifactor authentication (MFA). Which Conditional Access components should the administrator configure?

A.Configure conditions for sign-in risk and locations, and use Grant controls to require MFA and device compliance.
B.Configure a session control to require device compliance and an assignment for sign-in risk to trigger MFA.
C.Use Microsoft Entra ID Protection to automatically enforce MFA and device compliance for all users regardless of location.
D.Configure a compliance policy in Intune and link it directly to SharePoint Online to block non-compliant devices.
AnswerA

This correctly identifies that conditions (sign-in risk and locations) are used to define when the policy applies, and Grant controls enforce the requirements. The Grant control 'Require all the selected controls' can combine device compliance and MFA.

Why this answer

Conditional Access in Microsoft Entra ID allows combining multiple conditions (sign-in risk, locations) with grant controls (require MFA, require device compliance) to enforce the described policy. The administrator configures conditions for sign-in risk (medium/high) and locations (trusted IP range), then uses Grant controls to require MFA and device compliance, ensuring access is allowed only when all requirements are met.

Exam trap

The trap here is confusing session controls with grant controls, leading candidates to incorrectly select Option B, which misassigns device compliance as a session control instead of a grant control.

How to eliminate wrong answers

Option B is wrong because session controls (e.g., app enforced restrictions) cannot require device compliance; device compliance is a grant control, not a session control, and sign-in risk is a condition, not an assignment. Option C is wrong because Microsoft Entra ID Protection does not automatically enforce MFA and device compliance for all users regardless of location; it provides risk detection but relies on Conditional Access policies to apply controls. Option D is wrong because Intune compliance policies cannot be linked directly to SharePoint Online to block non-compliant devices; they require Conditional Access to enforce access restrictions based on compliance status.

302
MCQeasy

A company wants to allow employees to access corporate resources such as email and internal apps using their personal smartphones. The IT team does not want to fully manage or domain-join these devices but needs each device to have a simple identity that links the user's work account to the device. Which Microsoft Entra ID device identity option should they implement?

A.Microsoft Entra ID Registered
B.Microsoft Entra ID Joined
C.Hybrid Microsoft Entra ID Joined
D.Active Directory Joined
AnswerA

This option is specifically designed for Bring Your Own Device (BYOD) scenarios, allowing personal devices to establish a device identity in Microsoft Entra ID. It enables employees to securely access corporate resources, such as email and applications, through conditional access policies without the organization taking full management control of the device. The device is recognized and trusted, but not fully managed, making it ideal for personal devices.

Why this answer

Microsoft Entra ID Registered (formerly Azure AD Registered) provides a device identity for personal (BYOD) devices without requiring organizational domain join or full management. It links the user's work account to the device, enabling access to corporate resources via conditional access and Intune app protection policies. This matches the requirement of a simple identity for personal smartphones without full management.

Exam trap

SC-900 often tests the confusion between device join types; candidates may think 'Registered' means full management, but it is actually the lightest identity option for BYOD, while 'Joined' implies organizational ownership.

Why the other options are wrong

C

Hybrid Microsoft Entra ID Joined requires devices to be domain-joined and managed by on-premises AD with synchronization to Entra ID, which contradicts the requirement to avoid full management or domain-joining of personal smartphones.

D

Active Directory Joined requires devices to be domain-joined to an on-premises Active Directory, which involves full management and does not support personal smartphones that are not domain-joined. The question specifies that devices should not be fully managed or domain-joined.

303
MCQmedium

An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for all users accessing sensitive data from outside the corporate network. Which Microsoft Entra capability should they configure?

A.Conditional Access
B.B2B Collaboration
C.Privileged Identity Management
D.Identity Protection
AnswerA

Conditional Access policies evaluate real-time signals such as user location and network IP address, enabling the security team to enforce MFA specifically when access originates from outside the corporate network. This satisfies the stem’s constraint of restricting MFA to external access only, without affecting internal users. Unlike baseline or per-user MFA, Conditional Access provides granular, context-aware control based on the network location condition.

Why this answer

Conditional Access is the correct capability because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location. By configuring a policy that targets all users and applies the 'Require multi-factor authentication' grant control when the location is outside the corporate network, the security team can precisely meet the requirement. This policy evaluates the user's IP address against named locations defined in Entra ID before granting access to sensitive data.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA trigger with the ability to enforce MFA based on a static network location, but Identity Protection only responds to risk events and does not allow direct configuration of location-based conditions.

How to eliminate wrong answers

Option B (B2B Collaboration) is wrong because it is designed for inviting external users (guests) from partner organizations, not for enforcing MFA on internal users based on network location. Option C (Privileged Identity Management) is wrong because it focuses on just-in-time privileged role activation and approval workflows, not on location-based MFA enforcement for all users. Option D (Identity Protection) is wrong because it detects and remediates risks like leaked credentials or sign-ins from anonymous IPs, but it does not directly enforce MFA based on a static network boundary; it can trigger MFA via Conditional Access policies but is not the capability that configures the location condition itself.

304
MCQmedium

A company has an on-premises Active Directory and wants to synchronize user accounts to Microsoft Entra ID. They also need to enable password hash synchronization so users can sign in to cloud resources with the same password. Which Microsoft tool should they use?

A.Microsoft Entra Connect
B.Microsoft Entra ID Application Proxy
C.Microsoft Identity Manager
D.Microsoft Entra Domain Services
AnswerA

Microsoft Entra Connect is the essential Microsoft tool designed to achieve hybrid identity goals by synchronizing users, groups, and contacts from an on-premises Active Directory to Microsoft Entra ID. It facilitates various synchronization features, including password hash synchronization (PHS), pass-through authentication (PTA), and federation with Active Directory Federation Services (AD FS). PHS, enabled by default, securely synchronizes a hash of the user's password hash, allowing users to sign in to cloud services with their on-premises credentials.

Why this answer

Microsoft Entra Connect is the correct tool because it is specifically designed to synchronize on-premises Active Directory user accounts to Microsoft Entra ID and supports password hash synchronization (PHS). PHS enables users to sign in to cloud resources using the same password as their on-premises environment by synchronizing a hash of the password hash to Entra ID.

Exam trap

The trap here is that candidates may confuse Microsoft Entra Connect with Microsoft Identity Manager (MIM), but MIM is a legacy tool for on-premises identity management and does not natively support password hash synchronization to Microsoft Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications, not directory synchronization or password hash sync. Option C is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution for managing identities across heterogeneous directories, but it is not the primary tool for synchronizing to Microsoft Entra ID and does not natively enable password hash synchronization to Entra ID. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., Kerberos, LDAP) for cloud VMs, not user account synchronization or password hash sync from on-premises Active Directory.

305
MCQmedium

A company needs to grant IT administrators temporary and time-limited access to privileged roles in Microsoft Entra ID (Azure AD). The access must require approval from a manager and be automatically revoked after the task is completed. Which Microsoft Entra ID feature should be used?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Entitlement Management
AnswerC

Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft services. It enables just-in-time (JIT) access, allowing administrators to activate privileged roles only when needed, for a specific, time-limited duration. This includes features like multi-factor authentication (MFA) enforcement during activation, approval workflows, and comprehensive audit logs, directly fulfilling the requirement for temporary and time-limited administrative access.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access by allowing administrators to activate eligible role assignments for a limited duration. It supports approval workflows (e.g., manager approval) and automatically deactivates the role when the activation time expires or the task is completed, meeting the requirement for temporary, time-limited, approved, and auto-revoked access.

Exam trap

The trap here is confusing Entitlement Management (which manages access packages for non-privileged resources) with PIM (which specifically handles time-limited privileged role activation with approval), leading candidates to choose D because they see 'approval' and 'temporary access' without recognizing the privileged role context.

Why the other options are wrong

A

Conditional Access enforces access policies based on signals like user location or device state, but it does not provide time-limited, approval-based activation of privileged roles or automatic revocation.

B

Identity Protection is designed to detect and respond to identity-based risks, such as compromised credentials or suspicious sign-ins, not to manage time-limited privileged role assignments with approval workflows.

D

Entitlement Management manages access packages and resource access requests, but it does not provide time-limited, automatically revoked privileged role assignments with manager approval; PIM handles just-in-time privileged role activation.

306
MCQhard

You are the identity administrator for Contoso Ltd., a global company with over 10,000 employees. The company uses Microsoft Entra ID P2 and Microsoft Intune. Employees use both company-owned and personal devices. The security team requires that all access to corporate applications be protected with multifactor authentication (MFA). However, to minimize user friction, they want to exempt MFA for users who are on the corporate network and using compliant devices. Additionally, for users with privileged roles (e.g., Global Administrator), MFA must always be required regardless of location or device. You need to configure a Conditional Access policy to meet these requirements. Which of the following approaches should you take?

A.Create two Conditional Access policies: Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions.
B.Create one Conditional Access policy that targets all users and requires MFA. Create a second policy that targets privileged roles and excludes trusted locations.
C.Create one Conditional Access policy that targets all users, requires MFA, and excludes trusted locations and compliant devices. Do not create any additional policies.
D.Create one Conditional Access policy that targets all users and requires MFA. Use Microsoft Intune compliance policies to exempt compliant devices from MFA.
AnswerA

This solution correctly implements a layered security approach using two distinct Conditional Access policies. Policy 1 ensures that standard users require Multi-Factor Authentication (MFA) but allows for usability by excluding trusted locations and compliant devices. Policy 2 specifically targets privileged roles, enforcing MFA without any exclusions, thereby guaranteeing that these high-impact accounts always face the strongest authentication challenge, regardless of their location or device compliance status. This design effectively balances security for privileged identities with user experience for general users.

Why this answer

It uses two separate Conditional Access policies to handle the two distinct user groups. Policy 1 targets all users except privileged roles, requires MFA, and excludes trusted locations and compliant devices, which satisfies the requirement to minimize friction for users on the corporate network with compliant devices. Policy 2 targets privileged roles and requires MFA with no exclusions, ensuring that Global Administrators and other privileged role members always must perform MFA regardless of location or device compliance.

Exam trap

The trap here is that candidates often think a single policy with exclusions can handle all users, forgetting that privileged roles require unconditional MFA, which necessitates a separate policy with no exclusions to override the more permissive exclusions applied to regular users.

How to eliminate wrong answers

Option B is wrong because it creates a second policy that targets privileged roles and excludes trusted locations, which would exempt privileged role users from MFA when they are on the corporate network, violating the requirement that MFA must always be required for privileged roles. Option C is wrong because it creates only one policy targeting all users with exclusions for trusted locations and compliant devices, which would incorrectly exempt privileged role users from MFA when they meet those conditions. Option D is wrong because Intune compliance policies cannot be used to exempt devices from MFA in a Conditional Access policy; MFA enforcement is controlled by Conditional Access policies, not by compliance policies.

307
MCQmedium

An organization needs to grant its IT administrators temporary access to the Global Administrator role. The access should require a separate approval from a designated manager before activation, and the permissions should automatically expire after 4 hours. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Access Reviews
AnswerC

Azure AD Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources within an organization. It enables just-in-time (JIT) access, allowing administrators to activate privileged roles only when needed and for a limited duration. This process often includes an approval workflow, multi-factor authentication, and automatic deactivation of the role after the specified time, directly addressing the requirement for temporary, controlled access.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access, allowing IT administrators to activate the Global Administrator role for a limited time (e.g., 4 hours) only after receiving approval from a designated manager. This directly meets the requirement for temporary, approval-based, and auto-expiring permissions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Conditional Access, mistakenly thinking that Conditional Access can enforce time-limited role activation, when in fact PIM is the only feature that provides just-in-time privileged access with approval and automatic expiration.

Why the other options are wrong

A

Conditional Access enforces access policies based on signals like user location or device state, but it does not provide just-in-time role activation with approval and automatic expiry.

D

Access Reviews are used to audit and confirm the ongoing need for group memberships or role assignments, not to grant temporary, approval-based activation of privileged roles with automatic expiration.

308
MCQeasy

A company wants to provide secure external access to a partner application without creating user accounts manually. They need to allow partners to authenticate using their existing corporate identities (e.g., from other organizations) and configure policies for access. Which Microsoft Entra feature should they use?

A.Microsoft Entra Identity Protection
B.Microsoft Entra External ID (B2B collaboration)
C.Microsoft Entra Privileged Identity Management
D.Microsoft Entra Domain Services
AnswerB

Microsoft Entra External ID (B2B collaboration) is the correct solution as it specifically enables organizations to invite external users, such as partners, to access their applications and resources using their own existing identities. This feature integrates partner users into the inviting organization's Microsoft Entra tenant as guest users, allowing for the application of robust access policies and secure management of their access to partner applications.

Why this answer

Microsoft Entra External ID (B2B collaboration) allows organizations to securely share applications and resources with external partners by letting them authenticate using their own corporate identities (e.g., from other Azure AD tenants, Microsoft accounts, or social identity providers). It eliminates the need to manually create and manage user accounts for partners, while enabling you to apply conditional access policies for granular control over external access.

Exam trap

The trap here is that candidates often confuse B2B collaboration (External ID) with B2C (External Identities for customer-facing apps) or think that Privileged Identity Management is needed for external access, but the question specifically asks about allowing partners to use their existing corporate identities without manual account creation, which is the core purpose of B2B collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats (e.g., leaked credentials, sign-in anomalies) for users within your tenant, not a feature for inviting external partners or federating with their existing identities. Option C is wrong because Microsoft Entra Privileged Identity Management (PIM) manages, controls, and monitors access to privileged roles within your own directory (e.g., just-in-time admin access), not for enabling external partner authentication or collaboration. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for legacy on-premises applications in the cloud, not for external identity federation or B2B guest access.

309
MCQmedium

Your company uses Microsoft Entra ID. Security policy requires that all external guest users must be reviewed and their access approved by their sponsor every 90 days. If not approved, access should be automatically removed. Which feature should you use?

A.Microsoft Entra Conditional Access
B.Microsoft Entra B2B collaboration settings
C.Microsoft Entra entitlement management
D.Microsoft Entra access reviews
AnswerD

Microsoft Entra access reviews are specifically designed to enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments by scheduling periodic reviews. These reviews allow designated reviewers to confirm continued access necessity, and critically, they can be configured to automatically remove access for users who are not approved or whose review is not completed, directly addressing the requirement for periodic validation and automated revocation.

Why this answer

Microsoft Entra access reviews (Option D) allow you to configure recurring reviews of guest users' access, with automatic removal of access if not approved. This directly meets the requirement for a 90-day review cycle with automatic enforcement, as access reviews can be scoped to guest users and integrated with entitlement management or groups.

Exam trap

The trap here is that candidates confuse entitlement management (which creates access packages) with the actual review and removal mechanism, but access reviews are the specific feature that enforces periodic attestation and automatic cleanup.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access controls access based on conditions like location or device state, but it does not provide periodic review or automatic removal of access based on approval. Option B is wrong because Microsoft Entra B2B collaboration settings manage invitation policies and external user properties, but they lack the recurring review and auto-removal workflow. Option C is wrong because Microsoft Entra entitlement management manages access packages and catalogs, but the actual review and removal process is implemented through access reviews, not entitlement management alone.

310
MCQmedium

A company uses Microsoft Entra ID and wants to enforce multifactor authentication (MFA) for all users accessing a sensitive customer relationship management (CRM) application, but only when the access request originates from outside the corporate network. Which component of a Conditional Access policy should the administrator configure to specify this location-based requirement?

A.Assignments
B.Conditions
C.Grant controls
D.Session controls
AnswerB

Conditions are the "if" part of a Conditional Access policy, evaluating specific attributes of a sign-in attempt to determine if the policy applies. This includes critical contextual factors such as the user's sign-in risk level, the device platform being used, the client application, and crucially, the network location from which the access request originates. The location condition specifically allows administrators to define trusted or untrusted IP ranges, enabling enforcement based on geographic or network-specific access points.

Why this answer

The 'Conditions' section of a Conditional Access policy allows administrators to define the circumstances under which the policy is applied, including the location from which an access request originates. By configuring a location condition, you can specify that MFA is enforced only when users access the CRM application from outside the corporate network, using named locations or IP ranges. This is the correct component to enforce the location-based requirement.

Exam trap

The trap here is that candidates often confuse 'Assignments' (who/what) with 'Conditions' (when/where), mistakenly selecting Assignments because they think location is part of the user or app assignment, whereas Conditions specifically handle environmental factors like location, device state, and risk.

How to eliminate wrong answers

Option A is wrong because 'Assignments' define which users, groups, or applications the policy applies to, not the conditions under which it is triggered. Option C is wrong because 'Grant controls' specify what actions to take (e.g., require MFA, require compliant device) after the policy conditions are met, not the location condition itself. Option D is wrong because 'Session controls' manage session-level behaviors like app-enforced restrictions or sign-in frequency, not the location-based trigger for MFA enforcement.

311
MCQmedium

A company uses Microsoft Entra ID. They need to provide temporary access to a set of external auditors so they can review financial documents stored in SharePoint Online. The auditors must use their own email addresses to receive an access code. Which Microsoft Entra feature should the company configure?

A.Microsoft Entra Privileged Identity Management (PIM)
B.Microsoft Entra Conditional Access
C.Microsoft Entra B2C
D.Microsoft Entra B2B collaboration with email one-time passcode
AnswerD

Microsoft Entra B2B collaboration allows you to invite external users as guest users. With email one-time passcode, the invited users can authenticate using a code sent to their email, without needing a Microsoft account or Azure AD account. This meets the requirement for auditors to use their own email addresses and receive a code. It is the appropriate feature for temporary external access.

Why this answer

Microsoft Entra B2B collaboration enables you to invite external users as guests and allows them to authenticate using email one-time passcode. This is ideal for temporary access scenarios like audits, where external users can use their own email addresses without creating Microsoft accounts. It simplifies management and ensures secure access to resources like SharePoint Online.

Exam trap

The trap here is confusing B2B collaboration with B2C, but B2B is for business partners while B2C is for customers, and only B2B supports email one-time passcode for guests.

312
MCQeasy

A company uses Microsoft Entra ID. Employees often forget their passwords and contact the IT helpdesk to reset them. The company wants to reduce helpdesk costs by allowing users to reset their own passwords using a verified mobile phone number or email address. Which Microsoft Entra ID feature should the administrator enable?

A.Microsoft Entra ID Identity Protection
B.Self-Service Password Reset (SSPR)
C.Privileged Identity Management (PIM)
D.Conditional Access
AnswerB

Self-Service Password Reset (SSPR) is a crucial Microsoft Entra ID feature that empowers users to reset their forgotten passwords without requiring assistance from IT helpdesk staff. Users must pre-register at least two authentication methods, such as a mobile phone number or an alternate email address, which are then used to verify their identity during the reset process. This capability significantly reduces helpdesk call volumes and improves user productivity by enabling immediate password recovery.

Why this answer

Self-Service Password Reset (SSPR) is the correct feature because it allows users to reset their own passwords without helpdesk intervention, using a verified mobile phone number or email address as authentication methods. This directly reduces helpdesk costs by shifting password reset responsibility to the user, while maintaining security through verification of registered contact methods.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with self-service password reset, because both involve 'management' of identities, but PIM is strictly for privileged role activation, not end-user password changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a risk-based security tool that detects potential identity vulnerabilities and automated remediation, but it does not provide self-service password reset capabilities. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews, not end-user password resets. Option D is wrong because Conditional Access enforces access policies based on signals like user location or device state, but it does not enable users to reset their own passwords.

313
MCQmedium

A company uses Microsoft Entra ID to manage identities. They want to enforce access policies based on user location, device compliance, and application sensitivity. Which Microsoft Entra ID capability should they use?

A.Microsoft Entra ID Protection
B.Conditional Access
C.Privileged Identity Management (PIM)
D.Microsoft Entra Connect Sync
AnswerB

Conditional Access is the precise solution for defining and enforcing granular access policies based on a wide array of conditions. Administrators can configure policies that evaluate user attributes, device state (e.g., compliant vs. non-compliant), location, application being accessed, and sign-in risk. This allows for dynamic access control, enabling actions like requiring multi-factor authentication, blocking access, or allowing access only from managed devices, directly addressing the need for policy enforcement based on specific criteria.

Why this answer

Conditional Access is the correct capability because it allows administrators to create policies that enforce access controls based on conditions such as user location, device compliance, and application sensitivity. These policies evaluate signals at sign-in time and can require multi-factor authentication, block access, or grant limited access based on the defined conditions.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Protection (which deals with risk detection) with Conditional Access (which enforces policies based on conditions like location and device compliance), but ID Protection does not directly enforce location- or device-based access rules.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, anonymous IP addresses) and does not directly enforce policies based on device compliance or application sensitivity. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and role activation workflows, not location- or device-based access policies. Option D is wrong because Microsoft Entra Connect Sync is a tool for synchronizing on-premises directory objects to Entra ID and has no role in enforcing access policies.

314
MCQhard

You are analyzing a PIM activation request. The roleDefinitionId corresponds to the Global Administrator role. What is the duration of the activation?

A.4 hours
B.8 hours
C.8 minutes
D.8 days
AnswerA

The ISO 8601 duration string "PT8H" explicitly defines an eight-hour period for role activation. Therefore, interpreting this as 4 hours is an incorrect reading of the specified duration. Azure AD PIM relies on precise time definitions to enforce Just-In-Time access, and any deviation from the configured "PT8H" value would contradict the role's maximum activation setting.

Why this answer

By default, the activation duration for a PIM role is 4 hours. While the maximum allowed activation duration for any role, including Global Administrator, is 8 hours, the system's default setting is 4 hours if no custom configuration is applied. Highly privileged roles like Global Administrator are often configured with an 8-hour maximum by organizations, but the system default is 4 hours.

Exam trap

The trap here is that candidates confuse the *default* activation duration for PIM roles (4 hours) with the *maximum allowed* duration (8 hours), or the 8-minute activation window for temporary access passes, leading them to select the wrong option. For highly privileged roles like Global Administrator, while 8 hours is the maximum and often configured, the system default is 4 hours.

How to eliminate wrong answers

Option A is wrong because 4 hours is not the default maximum activation duration for Global Administrator; it is a possible custom duration but not the default. Option C is wrong because 8 minutes is far too short for a Global Administrator activation; PIM allows durations in hours, not minutes, for such roles. Option D is wrong because 8 days would violate the principle of just-in-time access; PIM enforces a maximum of 8 hours for Global Administrator to prevent persistent elevation.

315
MCQeasy

A company wants to grant temporary, time-limited access to a critical Azure resource for an external consultant. Which Microsoft Entra feature should they use?

A.Entra Verified ID
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerB

Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) capabilities. It allows administrators to grant temporary, time-limited access to privileged roles, which can be activated on demand for a specified duration. This ensures that users only have elevated permissions when absolutely necessary, significantly reducing the attack surface.

Why this answer

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access to Azure resources, allowing administrators to grant time-bound, temporary access that automatically expires. This aligns directly with the requirement for temporary, time-limited access for an external consultant, as PIM supports activation windows, approval workflows, and audit logging for such scenarios.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Conditional Access, thinking that Conditional Access can enforce time-limited access, but Conditional Access only controls sign-in conditions, not the duration of privileged role assignments.

How to eliminate wrong answers

Option A is wrong because Entra Verified ID is a decentralized identity verification solution using verifiable credentials (based on W3C standards) and does not provide time-limited access management to Azure resources. Option C is wrong because Identity Protection is a risk-detection and remediation service that identifies compromised identities or risky sign-ins, not a tool for granting or managing temporary access. Option D is wrong because Conditional Access enforces policies based on conditions like location or device state at sign-in time, but it does not grant or schedule time-limited privileged access to specific resources.

316
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to ensure that access to a critical application is reviewed every 90 days by the application owner. If the review is not completed, access should be revoked automatically. Which feature should you configure?

A.Terms of use
B.Access reviews
C.Privileged Identity Management
D.Entitlement management
AnswerB

Microsoft Entra ID Access Reviews are specifically designed to manage the lifecycle of access to resources, groups, and applications by enabling regular, scheduled reviews. Administrators can configure these reviews to recur periodically, assign reviewers, and set up automatic actions, such as revoking access for users who are not approved or whose review is not completed within a specified timeframe. This functionality directly addresses the requirement for recurring access validation and automated revocation.

Why this answer

Access reviews in Microsoft Entra ID Governance allow you to create recurring reviews of group memberships or application assignments, with automatic revocation of access if the review is not completed. By configuring a review every 90 days and setting the 'Auto apply' action to 'Remove access', you ensure that the application owner must certify access or it is automatically revoked.

Exam trap

The trap here is that candidates confuse Entitlement management (which handles access packages and lifecycle) with Access reviews (which specifically handle recurring attestation and automatic revocation), leading them to pick D instead of B.

How to eliminate wrong answers

Option A is wrong because Terms of use are used to present legal or policy documents that users must accept before accessing applications, not to schedule recurring access reviews with automatic revocation. Option C is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and approval workflows, not for recurring attestation of access to a critical application. Option D is wrong because Entitlement management handles access packages and automated provisioning/deprovisioning based on policies, but it does not provide the recurring review cycle with automatic revocation if the review is not completed; that is the specific function of Access reviews.

317
MCQhard

A multinational company uses Microsoft Entra ID. They want to ensure that users from a specific country only access a sensitive application from compliant devices. Additionally, they want to block access if the sign-in risk is medium or high. Which combination of policies should they create?

A.A Conditional Access session policy to enforce sign-in frequency
B.A device compliance policy in Microsoft Intune
C.A Conditional Access policy requiring MFA from that country
D.A Conditional Access policy with conditions for location, device compliance, and sign-in risk
AnswerD

This Conditional Access policy effectively combines multiple critical signals to provide robust, risk-adaptive access control. By including conditions for location, device compliance, and sign-in risk (from Microsoft Entra ID Protection), it allows the system to evaluate the user's context comprehensively. This enables granular decisions, such as blocking access or requiring stronger authentication, specifically when a sign-in attempt is identified as risky based on these combined factors, directly addressing the company's security requirements.

Why this answer

A single Conditional Access policy can combine multiple conditions—such as location (country), device compliance (via integration with Intune), and sign-in risk—to enforce granular access controls. This allows the company to require compliant devices and block access when sign-in risk is medium or high, all within one policy.

Exam trap

The trap here is that candidates think they need separate policies for each condition (location, device compliance, risk), but Microsoft Entra ID allows combining all three conditions into a single Conditional Access policy, which is more efficient and aligns with the scenario's requirements.

How to eliminate wrong answers

Option A is wrong because sign-in frequency is a session control that re-prompts for authentication after a set time, not a condition to restrict access by location, device compliance, or risk. Option B is wrong because a device compliance policy in Intune defines compliance rules (e.g., encryption, OS version) but does not enforce access decisions or block based on sign-in risk; it only marks devices as compliant or non-compliant. Option C is wrong because requiring MFA from that country does not address device compliance or sign-in risk; it only adds an authentication step, not a block for medium/high risk or non-compliant devices.

318
MCQmedium

Your company uses Microsoft Entra ID. You need to enable users to sign in to third-party SaaS applications using their corporate credentials without storing passwords in those apps. Which Microsoft Entra feature should you configure?

A.Configure single sign-on (SSO) using federation
B.Deploy Microsoft Entra Self-Service Password Reset
C.Configure conditional access policies with MFA
D.Enable Microsoft Entra Identity Protection
AnswerA

Configuring single sign-on (SSO) using federation establishes a trust relationship where Microsoft Entra ID acts as the identity provider. When users access an application, they are redirected to Entra ID for authentication. Upon successful verification, Entra ID issues a security token to the application, granting access without the application ever storing or directly handling the user's password, thereby centralizing authentication and eliminating application-specific credential storage.

Why this answer

Configuring single sign-on (SSO) using federation allows users to authenticate against Microsoft Entra ID (their corporate identity provider) and then pass a security token to third-party SaaS applications. This eliminates the need for the SaaS app to store or manage user passwords, as authentication happens via standards like SAML 2.0 or WS-Federation, and the app trusts the token issued by Entra ID.

Exam trap

The trap here is that candidates often confuse Conditional Access or Identity Protection with the core mechanism for passwordless federation, not realizing that SSO via federation is the specific feature that removes password storage in the third-party app.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Self-Service Password Reset (SSPR) enables users to reset their own passwords, but it does not provide a mechanism to sign in to third-party SaaS apps without storing passwords in those apps. Option C is wrong because Conditional Access policies with MFA enforce additional security controls (like requiring multi-factor authentication) during sign-in, but they do not eliminate the need for password storage in the SaaS app itself. Option D is wrong because Microsoft Entra Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, anomalous sign-ins), but it does not enable passwordless or federated authentication to third-party applications.

319
MCQeasy

A company has a hybrid identity environment with Active Directory synchronizing to Microsoft Entra ID. They want users to be able to reset their own on-premises passwords via the cloud SSPR portal. What is the minimum license required for this capability?

A.Microsoft Entra ID Free
B.Microsoft Entra ID P1
C.Microsoft Entra ID P2
D.Microsoft 365 Business Basic
AnswerB

Microsoft Entra ID P1 is the minimum required license tier to enable Self-Service Password Reset (SSPR) with password writeback in a hybrid identity environment. This tier provides the necessary functionality to allow users to reset their passwords in the cloud, and then have those changes securely synchronized back to their corresponding accounts in the on-premises Active Directory. This ensures a consistent password across both environments and fulfills the requirements of the question.

Why this answer

Microsoft Entra ID P1 is the minimum license required for password writeback, which enables users to reset their on-premises Active Directory passwords via the cloud SSPR portal. This feature requires Microsoft Entra ID P1 or higher because it involves synchronizing password changes back to on-premises AD using Microsoft Entra Connect.

Exam trap

The trap here is that candidates often assume Microsoft Entra ID Free or a basic Microsoft 365 license is sufficient for SSPR, forgetting that password writeback to on-premises AD is a premium feature requiring at least P1.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Free does not include password writeback; it only supports cloud-only SSPR without on-premises writeback. Option C is wrong because Microsoft Entra ID P2 includes P1 features plus Identity Protection and Privileged Identity Management, but P1 already provides password writeback, so P2 is not the minimum. Option D is wrong because Microsoft 365 Business Basic includes Microsoft Entra ID Free, not P1, and thus lacks password writeback capability.

320
MCQmedium

Your organization requires that all external guest users must sign in using Microsoft Authenticator for MFA. What should you configure?

A.Conditional Access policy
B.Microsoft Entra B2B collaboration settings
C.Access reviews
D.ID Protection policies
AnswerA

A Conditional Access policy is the definitive control plane in Microsoft Entra ID for enforcing specific access requirements, such as multi-factor authentication (MFA), based on various conditions. By targeting 'All guest and external users' and requiring MFA, organizations can ensure that all external collaborators must satisfy this strong authentication method before accessing resources, regardless of their home tenant's policies. This provides a robust security posture for external access by integrating MFA directly into the sign-in flow.

Why this answer

A Conditional Access policy is the correct choice because it allows you to enforce MFA requirements for specific users, including external guest users, based on conditions such as sign-in risk, location, or device state. By targeting the 'Guest or external users' directory role in a Conditional Access policy, you can require Microsoft Authenticator as the MFA method, overriding default settings. This provides granular control over authentication behavior for B2B collaboration guests.

Exam trap

The trap here is that candidates confuse the high-level B2B collaboration settings (which only control trust of MFA from the home tenant) with the ability to enforce a specific MFA method directly on guest users, which requires a Conditional Access policy.

How to eliminate wrong answers

Option B (Microsoft Entra B2B collaboration settings) is wrong because these settings control invitation, redemption, and cross-tenant access policies, but they do not directly enforce MFA methods like Microsoft Authenticator; they only set trust settings for MFA from the guest's home tenant. Option C (Access reviews) is wrong because access reviews are used to periodically review and recertify user access, not to enforce authentication methods or MFA requirements. Option D (ID Protection policies) is wrong because ID Protection policies focus on risk-based conditional access (e.g., sign-in risk, user risk) and can trigger MFA, but they do not allow you to specify a particular MFA method like Microsoft Authenticator; that is done via Conditional Access grant controls.

321
MCQmedium

A company uses Microsoft Entra ID. The security team needs to block all sign-in attempts from a list of known malicious IP addresses. They also want to block sign-ins that originate from anonymous proxy services. Which Microsoft Entra capability should they configure to meet these requirements?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Access Reviews
AnswerA

Microsoft Entra Conditional Access is the primary policy engine within Microsoft Entra ID for enforcing access decisions based on various conditions, including user location. By configuring "named locations," administrators can define specific trusted or untrusted IP address ranges. A Conditional Access policy can then be created to explicitly block sign-in attempts originating from these designated malicious IP ranges or from anonymous IP addresses, directly addressing the requirement to prevent access from specific unwanted network origins.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define conditions under which sign-ins are blocked or allowed. By configuring a policy that includes 'Locations' as a condition, you can specify a list of known malicious IP addresses and also enable the 'Anonymous IP address' risk detection to block sign-ins from anonymous proxy services. This directly meets the requirement to block sign-ins from both specific IPs and anonymous proxies.

Exam trap

The trap here is that candidates often confuse Identity Protection’s risk detection capabilities with the enforcement mechanism, mistakenly thinking Identity Protection alone can block sign-ins, when in fact it only identifies risks and requires Conditional Access to enforce the block.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because Identity Protection is a risk-based detection and remediation service that identifies suspicious sign-ins (e.g., from anonymous IPs) but does not itself enforce blocking; it relies on Conditional Access policies to take action. Option C (Privileged Identity Management) is wrong because PIM focuses on just-in-time privileged role activation and access governance, not on blocking sign-ins based on IP address or proxy services. Option D (Access Reviews) is wrong because Access Reviews are used to periodically audit and certify user access to resources, not to block sign-ins in real time based on location or network characteristics.

322
Multi-Selecthard

Which THREE of the following are valid components of Microsoft Entra Conditional Access? (Select THREE.)

Select 3 answers
A.Users and groups
B.Session
C.Conditions (e.g., locations, device platforms)
D.Cloud apps or actions
E.Grant
AnswersA, C, D

Users and groups are a fundamental component of Conditional Access policies, defining the scope of identities to which a policy applies. This 'who' element allows administrators to target specific users, security groups, or directory roles, or to exclude certain identities from policy enforcement. By precisely defining the user scope, policies can be tailored to ensure appropriate access for different organizational segments while preventing unintended restrictions or permissions.

Why this answer

In Microsoft Entra Conditional Access, a policy is built from assignments and access controls, and the assignment side includes Users and groups (A), which determines who the policy applies to (all users, specific users/groups, or directory roles). Conditions (C) is also a valid assignment component, letting you scope the policy by signals such as locations, device platforms, client apps, and sign-in risk. Cloud apps or actions (D) is the third valid assignment component, specifying which cloud applications or user actions (like registering security info) the policy protects.

Session (B) and Grant (E) are not standalone assignment components; they are categories of access controls (Session controls and Grant controls) that are configured after assignments, so they are not counted among the three assignment components asked for here.

Exam trap

The trap is to treat Grant and Session as assignment components. They are access controls, not assignments. Users and groups, Conditions, and Cloud apps or actions are the three assignment components; Grant and Session apply after the policy is triggered.

323
MCQmedium

A company uses Microsoft Entra ID. The security team wants to automatically block sign-ins from IP addresses that are known to be associated with malicious activity. They also want to receive alerts when users with leaked credentials attempt to sign in. Which Microsoft Entra feature should they use?

A.Microsoft Entra Conditional Access
B.Microsoft Entra Privileged Identity Management (PIM)
C.Microsoft Entra Password Protection
D.Microsoft Entra ID Protection
AnswerD

ID Protection detects risk events such as sign-ins from malicious IP addresses and leaked credentials. It can be configured with risk policies to automatically block sign-ins or require password changes. It also generates alerts and reports. This directly matches the requirement to block malicious IP sign-ins and alert on leaked credentials.

Why this answer

Microsoft Entra ID Protection detects risk events, including sign-ins from malicious IP addresses and users with leaked credentials. It can be configured with risk policies to automatically block sign-ins or require password changes, and it provides alerts and reports. This makes it the correct feature to both block malicious IP sign-ins and alert on leaked credentials.

Exam trap

The trap here is confusing ID Protection, which detects and responds to identity risks, with Conditional Access, which enforces policy based on signals but does not generate them.

324
MCQmedium

A user reports that they cannot access the corporate portal after a password reset. The user can access other cloud apps. You verify that the user account is enabled and not locked. What should you check next?

A.Disable and re-enable the user account
B.Verify the user's registered authentication methods
C.Reinstall the corporate portal application
D.Check if the user is assigned a Microsoft Entra ID P2 license
AnswerB

A common reason for portal access issues, especially after a password reset or if the user has new devices, is an outdated or missing multi-factor authentication (MFA) registration. If conditional access policies require MFA for portal access, and the user's registered methods (e.g., Microsoft Authenticator, phone number) are incorrect or not configured, they will be blocked from signing in. Verifying and potentially resetting these methods in Microsoft Entra ID is a critical troubleshooting step to restore access.

Why this answer

The user can access other cloud apps, which rules out a global authentication or network issue. Since the account is enabled and not locked, the most likely cause is that the user's registered authentication methods (e.g., phone, authenticator app, or email) are missing, outdated, or not configured for the password reset flow. Microsoft Entra ID requires verified authentication methods to complete a password reset and subsequent sign-in, especially when the user is prompted for multifactor authentication or self-service password reset (SSPR) verification.

Exam trap

The trap here is that candidates often assume a password reset always works seamlessly, but the SC-900 exam tests the understanding that authentication methods must be registered and up-to-date for the reset to succeed, especially when the user is prompted for additional verification.

How to eliminate wrong answers

Option A is wrong because disabling and re-enabling the account would not resolve a missing or misconfigured authentication method; it only toggles the account status, which is already enabled. Option C is wrong because reinstalling the corporate portal application addresses client-side corruption, not an identity or authentication method issue that prevents access after a password reset. Option D is wrong because a Microsoft Entra ID P2 license is not required for basic password reset or authentication method registration; P2 adds advanced features like Identity Protection and Privileged Identity Management, but the core SSPR and MFA registration work with P1 or even free tier licenses.

325
MCQmedium

A company uses Microsoft Entra ID. They want to require users to perform multifactor authentication (MFA) every 90 days on trusted devices, but force MFA for every sign-in on untrusted devices. Which Conditional Access session control must they configure to meet this requirement?

A.Sign-in frequency
B.Application enforced restrictions
C.Use app enforced restrictions
D.Persistent browser session
AnswerA

Sign-in frequency is a session control that determines how often a user must provide authentication credentials again, such as after a set number of days or hours. It can be configured differently for trusted and untrusted devices.

Why this answer

Sign-in frequency is the Conditional Access session control that allows administrators to define the time interval after which a user must re-authenticate, even on a trusted device. By setting the sign-in frequency to 90 days for trusted devices and requiring re-authentication for every sign-in on untrusted devices (by setting the frequency to 0 or 1), the requirement is met. This control directly manages the re-prompt interval for MFA, independent of the session token lifetime.

Exam trap

The trap here is that candidates confuse 'Persistent browser session' (which controls session persistence across browser closes) with 'Sign-in frequency' (which controls the re-authentication interval), leading them to choose the wrong option for MFA frequency requirements.

How to eliminate wrong answers

Option B is wrong because 'Application enforced restrictions' is not a valid Conditional Access session control; it is a generic term that does not exist in the Microsoft Entra Conditional Access policy settings. Option C is wrong because 'Use app enforced restrictions' is also not a valid session control; it is a misnomer and does not correspond to any configurable setting in Conditional Access. Option D is wrong because 'Persistent browser session' controls whether the browser session cookie persists after the browser is closed, not the frequency of MFA prompts; it affects session lifetime but not the re-authentication interval for MFA.

326
Drag & Dropmedium

Arrange the steps to investigate a user compromise using Azure AD Identity Protection.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Identity Protection investigation involves accessing the portal, reviewing risks, selecting a user, analyzing events, and taking action.

327
MCQmedium

A company wants to improve password security across its Microsoft Entra ID tenant. The security team wants to prevent users from setting passwords that appear on Microsoft's global banned password list, which includes commonly compromised passwords. Additionally, they need to add a custom banned password containing the company name so that users cannot use variations of it. Which Microsoft Entra ID feature should they configure to enforce these password policies?

A.Conditional Access
B.Identity Protection
C.Password Protection
D.Multi-factor authentication (MFA)
AnswerC

Microsoft Entra ID Password Protection directly addresses the goal of improving password security by enforcing policies that prevent users from creating weak, easily guessable, or commonly compromised passwords. It utilizes both a global banned password list, maintained by Microsoft, and allows administrators to configure a custom banned password list specific to their organization. This feature actively checks new or reset passwords against these lists, rejecting those that fail to meet the defined security standards and thereby reducing the risk of password-based attacks.

Why this answer

Password Protection in Microsoft Entra ID is the feature specifically designed to enforce both global and custom banned password lists. It prevents users from using commonly compromised passwords from Microsoft's global list and allows administrators to add custom terms, such as the company name, to block variations. This directly addresses the requirement to improve password security by blocking weak and organization-specific passwords.

Exam trap

The trap here is that candidates may confuse Identity Protection's 'leaked credentials' detection with the ability to block password creation, but Identity Protection only detects credentials that have already been compromised, not prevents users from setting weak passwords in the first place.

Why the other options are wrong

A

Conditional Access enforces access controls based on signals like user, location, or device state, but it does not manage password content policies such as banned password lists.

B

Identity Protection is designed to detect and respond to identity-based risks, such as leaked credentials or suspicious sign-ins, but it does not enforce password policies like banning specific passwords.

D

Multi-factor authentication (MFA) adds a second verification step during sign-in, but it does not enforce password content policies like banning specific passwords. The question specifically asks about preventing users from setting banned passwords, which is handled by Password Protection, not MFA.

328
MCQhard

Refer to the exhibit. You run the cmdlet and get a list of risk detections. What does this cmdlet retrieve?

A.Users who have been flagged for risky sign-ins
B.All risk detections in the tenant
C.All sign-in logs with unfamiliar properties
D.Risk detections for the unfamiliar sign-in properties risk event type
AnswerD

This option is correct because the `Get-MSRiskDetection` cmdlet is used to retrieve risk detections from Azure AD Identity Protection. The `-Filter "riskEventType eq 'unfamiliarSignInProperties'"` parameter precisely targets and returns only those risk detection objects where the `riskEventType` property matches 'unfamiliarSignInProperties'. This accurately identifies sign-ins exhibiting characteristics outside a user's typical patterns, as indicated by the specified risk event type.

Why this answer

The cmdlet `Get-MgRiskDetection` retrieves all risk detections in the tenant, but when combined with the `-Filter` parameter for `riskEventType eq 'unfamiliarSigninProperties'`, it specifically returns only those risk detections that match the unfamiliar sign-in properties risk event type. This is because the cmdlet supports filtering by the `riskEventType` property, which corresponds to the type of risk detection as defined by Microsoft Entra ID Protection.

Exam trap

The trap here is that candidates confuse retrieving risk detections (which are events) with retrieving risky users or sign-in logs, and they overlook the `-Filter` parameter that narrows the scope to a specific risk event type, leading them to choose the overly broad 'All risk detections' option.

How to eliminate wrong answers

Option A is wrong because `Get-MgRiskDetection` retrieves risk detection objects, not user objects; users flagged for risky sign-ins are retrieved using `Get-MgRiskyUser` or `Get-MgRiskDetection` with a different filter. Option B is wrong because the cmdlet in the exhibit includes a `-Filter` parameter that limits the results to a specific risk event type, not all risk detections in the tenant. Option C is wrong because sign-in logs with unfamiliar properties are a subset of risk detections, but the cmdlet retrieves risk detection objects (which include metadata like risk level, risk state, and detection timing), not raw sign-in logs; sign-in logs are retrieved via `Get-MgAuditLogSignIn`.

329
MCQmedium

An organization uses Microsoft Entra ID. The security team wants to require multi-factor authentication (MFA) for users who sign in from sessions that Microsoft Entra ID Protection determines to have medium or high sign-in risk. Users signing in from low-risk sessions should not be prompted for MFA. Which feature should the security team configure?

A.Configure a Conditional Access policy with Sign-in risk as a condition and MFA as a grant control
B.Configure a user risk policy in Microsoft Entra ID Protection
C.Assign the Global Administrator role with Privileged Identity Management (PIM) activation requiring MFA
D.Create an access review in Microsoft Entra ID Governance
AnswerA

Configuring a Conditional Access policy with 'Sign-in risk' as a condition and 'Require multi-factor authentication' as a grant control is the correct solution. This policy leverages real-time risk detections from Microsoft Entra ID Protection, dynamically enforcing MFA only when a user's sign-in attempt is deemed risky. This approach provides adaptive security, ensuring that users are prompted for additional verification specifically when their access attempt presents a potential threat, aligning with a Zero Trust model.

Why this answer

A Conditional Access policy can use Sign-in risk (a condition from Microsoft Entra ID Protection) to require MFA as a grant control. This allows the security team to enforce MFA only for sessions with medium or high sign-in risk, while low-risk sessions are not prompted, exactly matching the requirement.

Exam trap

The trap here is confusing sign-in risk (session-level) with user risk (user-level), leading candidates to choose the user risk policy (Option B) instead of the Conditional Access policy with sign-in risk condition.

Why the other options are wrong

B

The question requires MFA based on sign-in risk (session risk), not user risk. A user risk policy in ID Protection addresses user-level risk (e.g., compromised account), not sign-in risk from a specific session.

C

This option addresses privileged role activation requiring MFA, not sign-in risk-based MFA for all users. The question specifically requires MFA based on sign-in risk level (medium/high), which is a Conditional Access policy condition, not a PIM activation setting.

D

Access reviews are used to verify and manage user access rights periodically, not to enforce MFA based on sign-in risk. The question specifically requires MFA enforcement for medium/high risk sessions, which is done via Conditional Access policies with sign-in risk condition.

330
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID Governance?

Select 2 answers
A.Privileged Identity Management
B.Access Reviews
C.Entitlement Management
D.Conditional Access
E.Identity Protection
AnswersB, C

Access Reviews are a core ID Governance feature.

Why this answer

Access Reviews (B) is a core Microsoft Entra ID Governance capability that lets organizations automate periodic reviews of group memberships, application access, and role assignments to ensure users retain only the access they need. Entitlement Management (C) is also part of Entra ID Governance, providing access packages, catalogs, and policies to automate the request, approval, assignment, and expiration of access for internal and external users. These two features directly address governance concerns such as access lifecycle management, least privilege, and compliance attestation.

Privileged Identity Management (A) is a separate Microsoft Entra ID service focused on just-in-time privileged role activation, while Conditional Access (D) is an access-control policy engine and Identity Protection (E) is a risk-detection and remediation service; neither is categorized as an Entra ID Governance capability.

Exam trap

The exam trap incorrectly suggests PIM is not a core governance capability. Microsoft's documentation explicitly lists Privileged Identity Management as a capability of Microsoft Entra ID Governance.

331
MCQmedium

A company uses Microsoft Entra ID. The security team wants to enforce a policy that prevents users from choosing commonly used weak passwords like 'Winter2024!' or 'Password@123', and also blocks customized variants based on organizational context (e.g., company name). Users must create passwords that meet standard complexity requirements. Which Microsoft Entra ID feature should they enable?

A.Password hash synchronization
B.Microsoft Entra ID Password Protection
C.Self-Service Password Reset
D.Conditional Access
AnswerB

Microsoft Entra ID Password Protection applies both a global banned-password list and a custom banned list, blocking weak terms such as company names and their variants. It enforces this during password set or reset, satisfying the requirement to reject common and organisation-specific passwords.

Why this answer

Microsoft Entra ID Password Protection (B) is the correct feature because it specifically enforces custom banned password lists that block weak passwords like 'Winter2024!' and organizational variants such as the company name. It works alongside standard password complexity requirements to prevent users from choosing passwords that appear on a global banned list or a tenant-specific custom list. This directly addresses the security team's need to block commonly used weak passwords and context-based variants.

Exam trap

The trap here is that candidates often confuse Self-Service Password Reset (SSPR) with password policy enforcement, but SSPR only facilitates password changes and does not block weak passwords; the actual blocking is done by Password Protection, which is a separate feature.

Why the other options are wrong

A

Password hash synchronization is a feature for syncing password hashes from on-premises AD to Entra ID for authentication, not for enforcing password policies like blocking weak or context-specific passwords.

C

Self-Service Password Reset (SSPR) allows users to reset their own passwords but does not enforce password policies that block weak or context-specific passwords. The question asks for a feature to prevent weak passwords, which is handled by Password Protection, not SSPR.

D

Conditional Access is used to enforce access controls based on signals like user location or device state, not to enforce password complexity or block weak passwords.

332
MCQmedium

An organization uses Microsoft Entra ID for identity management and wants to allow external partners to access their resources using their own corporate credentials. Which feature should they enable?

A.Entra External ID
B.Identity Protection
C.Conditional Access
D.Privileged Identity Management
AnswerA

Microsoft Entra External ID is the comprehensive solution designed for managing all external identities, including partners, customers, and other collaborators. It facilitates secure business-to-business (B2B) collaboration by allowing organizations to invite guest users from other Microsoft Entra tenants, social identity providers, or via email one-time passcodes. This enables external users to access internal applications and resources while maintaining their original identity provider.

Why this answer

Entra External ID (formerly Azure AD B2B) enables organizations to invite external partners to access resources using their own corporate credentials. This feature leverages federation protocols such as SAML, WS-Fed, or OpenID Connect to authenticate the partner's identity in their home tenant, eliminating the need for separate local accounts.

Exam trap

The trap here is that candidates often confuse Conditional Access (a policy engine) with the ability to invite external identities, mistakenly thinking policies alone can grant external access without a federation mechanism.

How to eliminate wrong answers

Option B is wrong because Identity Protection is a risk-detection service that monitors sign-in anomalies and user risk, not a feature for inviting external users with their own credentials. Option C is wrong because Conditional Access enforces policy-based access controls (e.g., MFA, location) after authentication, but does not itself enable external identity federation. Option D is wrong because Privileged Identity Management manages just-in-time privileged role activation and access reviews for internal users, not external partner authentication.

333
MCQmedium

A company uses Microsoft Entra ID. The security team wants to enforce multifactor authentication (MFA) only when users sign in from devices that are not compliant with company security policies. They also want to block sign-ins from unknown geographic locations. Which Microsoft Entra feature should they configure?

A.Identity Protection
B.Privileged Identity Management (PIM)
C.Conditional Access
D.Self-Service Password Reset (SSPR)
AnswerC

Microsoft Entra Conditional Access is a policy engine that evaluates various signals, including user identity, device state, sign-in location, and application, to make real-time access decisions. It directly enables the creation of granular policies to enforce requirements like multi-factor authentication (MFA) or compliant devices, or to block access entirely, based on specific conditions such as device compliance or trusted network locations, precisely meeting the stated requirements.

Why this answer

Conditional Access is the correct feature because it allows administrators to create policies that evaluate signals such as device compliance and geographic location before granting access. By configuring a policy that requires MFA for non-compliant devices and blocks sign-ins from unknown locations, the security team can enforce these specific conditions. This granular control is unique to Conditional Access, which integrates with Microsoft Entra ID to enforce access decisions based on real-time risk and context.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access with the broader Conditional Access feature, not realizing that Identity Protection only provides risk signals and requires Conditional Access to enforce the actual MFA or block action.

How to eliminate wrong answers

Option A is wrong because Identity Protection focuses on detecting and responding to identity-based risks (e.g., leaked credentials, anonymous IP addresses) but does not natively enforce MFA based on device compliance or block sign-ins from unknown geographic locations; it can trigger Conditional Access policies but is not the feature to configure the rules themselves. Option B is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and access reviews, not for enforcing MFA or location-based blocking for regular user sign-ins. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords and does not provide any mechanism to enforce MFA or block sign-ins based on device compliance or geographic location.

334
Multi-Selectmedium

Which two capabilities are provided by Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Mobile device management (MDM)
B.Conditional Access policies
C.Identity protection with risk-based conditional access
D.Data loss prevention (DLP) for sensitive information
E.Cloud access security broker (CASB)
AnswersB, C

Conditional Access policies are a core security feature within Microsoft Entra ID, allowing organizations to enforce specific access controls based on various signals. These policies evaluate conditions such as user identity, device state, location, and application to determine whether to grant access, block access, or require additional authentication methods like multi-factor authentication. This capability is fundamental for implementing Zero Trust principles in Entra ID by ensuring only authorized users on compliant devices can access resources.

Why this answer

Conditional Access policies (B) are a core capability of Microsoft Entra ID, enabling administrators to enforce access controls based on signals like user location, device state, and application sensitivity. Identity Protection with risk-based conditional access (C) leverages machine learning to detect sign-in and user risks, automatically applying policies to block or require multi-factor authentication. Both are native to Microsoft Entra ID and integral to its identity and access management (IAM) framework.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID's identity-focused capabilities (Conditional Access, Identity Protection) with adjacent security services like Intune (MDM), Microsoft Purview (DLP), and Defender for Cloud Apps (CASB), which are separate products in the Microsoft security stack.

335
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their existing Facebook accounts without creating a separate Microsoft Entra ID account. What should you configure?

A.Configure Microsoft Entra ID Protection
B.Create a Microsoft Entra External ID tenant and add Facebook as an identity provider
C.Enable Microsoft Entra ID Domain Services
D.Configure Microsoft Entra ID Governance
AnswerB

Microsoft Entra External ID (formerly Azure AD B2C) is a customer identity and access management (CIAM) solution specifically designed for managing consumer identities for customer-facing applications. By creating an External ID tenant, organizations can integrate various social identity providers, including Facebook, Google, and Microsoft accounts, allowing users to sign up and sign in using their existing social credentials. This capability directly addresses the requirement for enabling social login functionality for external users.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2C) is designed to allow external identities, such as social identity providers like Facebook, to authenticate users without requiring a separate Microsoft Entra ID account. By creating an External ID tenant and adding Facebook as an identity provider, you enable users to sign in using their existing Facebook credentials via OAuth 2.0 or OpenID Connect protocols.

Exam trap

The trap here is that candidates often confuse Microsoft Entra External ID (B2C) with Microsoft Entra ID (Azure AD) itself, assuming social identity providers can be added directly to a standard tenant, but only an External ID tenant supports social identity federation without requiring a separate Microsoft Entra ID account.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection is a security feature that detects and responds to identity risks (e.g., leaked credentials, sign-ins from anonymous IPs), not a mechanism for adding external identity providers like Facebook. Option C is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for legacy on-premises applications, not social identity federation. Option D is wrong because Microsoft Entra ID Governance focuses on managing identity lifecycle, access reviews, and entitlement management, not on configuring external authentication sources.

336
MCQmedium

A company uses Microsoft Entra ID. The security team wants to grant temporary, time-bound administrative access to the Microsoft 365 user management role for IT support staff. The access should require an approval from a senior administrator, and all actions should be audited. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Identity Governance
AnswerC

Microsoft Entra Privileged Identity Management (PIM) is the specific service designed to manage, control, and monitor access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It provides just-in-time (JIT) privileged access, allowing users to activate roles for a limited duration, often requiring multi-factor authentication and an approval workflow. This capability directly addresses the need for time-bound privilege elevation with comprehensive auditing and accountability, significantly reducing the attack surface.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access with time-bound role activation, approval workflows, and full auditing. This directly matches the requirement for temporary, approved administrative access to the Microsoft 365 user management role with audit trails.

Exam trap

The trap here is confusing Identity Governance (which handles access reviews and entitlement management for regular users) with Privileged Identity Management (which specifically handles just-in-time privileged role activation and approval).

Why the other options are wrong

A

Conditional Access controls access based on conditions like location or device state, but it does not provide time-bound, approval-based role activation or auditing for administrative roles.

B

Identity Protection is designed to detect and respond to identity-based risks, such as compromised credentials or suspicious sign-ins, not to manage temporary, time-bound administrative access with approval workflows.

D

Identity Governance focuses on managing user identity lifecycles, access certifications, and entitlement management, but does not provide time-bound, approval-based privileged role activation with auditing. PIM is required for just-in-time administrative access.

337
MCQeasy

Refer to the exhibit. The JSON shows a Conditional Access policy. What is the primary purpose of this policy?

A.Block legacy authentication protocols
B.Require MFA for all applications
C.Disable the policy for emergency access
D.Allow only iOS devices
AnswerA

The policy's "Client apps" condition is configured to target "Other clients," which is the category encompassing applications that utilize legacy authentication protocols such as POP, IMAP, SMTP, and older versions of Office clients that do not support modern authentication. By combining this specific client app condition with a "Block access" grant control, the policy effectively prevents users from authenticating via these less secure, legacy protocols. This significantly enhances security by forcing the use of modern authentication methods.

Why this answer

The policy targets 'Block legacy authentication' by applying a condition that blocks authentication attempts using legacy protocols (e.g., POP3, IMAP4, SMTP, ActiveSync) which do not support modern authentication methods like MFA. This is a common security measure to prevent credential-stuffing and password-spray attacks that exploit the lack of MFA enforcement in legacy protocols.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' with 'requiring MFA' — the policy blocks the protocol entirely rather than prompting for an additional factor, which is a distinct control in Conditional Access.

How to eliminate wrong answers

Option B is wrong because the policy does not require MFA; it explicitly blocks authentication entirely, not just requiring an additional factor. Option C is wrong because the policy does not include any exclusion for emergency access accounts (e.g., break-glass accounts) — it applies to all users unless a separate exclusion is configured. Option D is wrong because the policy does not filter by device platform (iOS) — it targets authentication protocol, not device type.

338
MCQmedium

Your company is implementing a hybrid identity solution with Microsoft Entra ID. Users report that they can sign in to Microsoft 365 but cannot access on-premises applications that are configured for integrated Windows authentication. You need to ensure seamless single sign-on (SSO) for both cloud and on-premises resources. What should you implement?

A.Implement Passthrough Authentication.
B.Deploy Active Directory Federation Services (AD FS).
C.Enable Microsoft Entra seamless SSO.
D.Configure password hash synchronization.
AnswerC

Enabling Microsoft Entra seamless SSO is the correct solution as it provides automatic sign-in for users on corporate domain-joined devices connected to the corporate network. It achieves this by leveraging Kerberos, allowing users to silently authenticate to both cloud-based Microsoft Entra ID applications and on-premises applications configured for Integrated Windows Authentication (IWA) without re-entering their credentials. This mechanism ensures a true single sign-on experience across the hybrid environment.

Why this answer

Microsoft Entra seamless SSO (Seamless SSO) is the correct choice because it automatically signs users in when they are on corporate devices connected to the corporate network, using Kerberos delegation to provide single sign-on for both cloud resources (like Microsoft 365) and on-premises applications configured for Integrated Windows Authentication (IWA). This eliminates the need for users to re-enter credentials when accessing on-premises apps after authenticating to the cloud.

Exam trap

The trap here is that candidates often confuse Passthrough Authentication or password hash synchronization with providing SSO for on-premises applications, but neither includes the Kerberos delegation required for Integrated Windows Authentication, which is the specific need in this scenario.

How to eliminate wrong answers

Option A is wrong because Passthrough Authentication validates passwords against on-premises Active Directory but does not provide the Kerberos-based SSO needed for Integrated Windows Authentication to on-premises applications; it only handles cloud authentication. Option B is wrong because Active Directory Federation Services (AD FS) is a more complex, on-premises federation solution that can provide SSO, but it is overkill for this scenario and not the simplest or recommended approach when Seamless SSO can achieve the same goal with less infrastructure. Option D is wrong because password hash synchronization only synchronizes password hashes to the cloud for cloud authentication and does not enable Kerberos-based SSO for on-premises IWA applications.

← PreviousPage 5 of 5 · 338 questions total

Ready to test yourself?

Try a timed practice session using only Entra Capabilities questions.