๐ŸŽ„

CertoMetrics - 9% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

Microsoft Identity and Access Administrator (SC-300)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

Microsoft

Certification

Security

Content

391 Qs

Status

Verified

Updated

6 hours ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$83 $49

Save $34 Instantly

  • โœ“
    Full PDF + Interactive Engine Everything you need to pass
  • โœ“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • โœ“
    Priority 24/7 Expert Support Direct line to certification leads
  • โœ“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$44

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$39

Digital Access

  • โœ“ Exam Questions (PDF)
  • โœ“ Mobile Friendly
  • โœ“ 60 Days Updates
Download Free Sample PDF

Verified 79-Question Preview (SC-300)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified Microsoft certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated SC-300 prep kit.

Exam Overview

The Microsoft Identity and Access Administrator (SC-300) certification is a vital credential for professionals tasked with securing an organization's digital assets through robust identity and access management solutions. This exam validates your expertise in designing, implementing, and monitoring identity and access within Microsoft Azure Active Directory (Azure AD), a critical component of modern cloud security. Achieving this certification demonstrates your ability to manage users, groups, external identities, implement secure authentication, enforce access policies, and govern identity lifecycles. It signifies your proficiency in protecting data, ensuring compliance, and mitigating security risks, making you an indispensable asset in any organization navigating the complexities of cloud identity.

Questions

40-60

Passing Score

700/1000

Duration

120 Minutes

Difficulty

Expert

Level

Associate

Skills Measured

Implement an Identity Management Solution (Azure AD, users, groups, external identities, custom roles, administrative units).
Implement an Authentication Solution (MFA, passwordless authentication, SSPR, authentication methods, tenant-wide settings).
Implement an Access Management Solution (Conditional Access policies, enterprise applications, application access, device management integration).
Implement Access Governance (Azure AD Entitlement Management, access reviews for groups/applications, Privileged Identity Management for Azure resources).
Implement Identity Governance (Lifecycle workflows, access reviews for Azure AD roles, Privileged Identity Management for Azure AD roles, Azure AD Identity Protection).

Career Path

Target Roles

Identity and Access Administrator Security Engineer Cloud Security Administrator

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest Microsoft standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the SC-300 exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated SC-300 bank (79 Questions).

QUESTION 1

You need to configure the MFA settings for users who connect from the Boston office. The solution must meet the authentication requirements and the access requirements.

What should you include in the configuration?

A
named locations that have a private IP address range
B
named locations that have a public IP address range
C
trusted IPs that have a public IP address range
D
trusted IPs that have a private IP address range

Correct Option: B

โœ…

Reasoning: To exempt users from MFA when connecting from a specific office, Conditional Access policies utilize "Named locations." These locations must be configured with the public IP address range of the Boston office, allowing Azure AD to identify and apply policy exemptions for connections originating from that trusted network. โŒ Why the other choices are incorrect:

  • Option A is incorrect: Private IP address ranges are internal and cannot be used by Azure AD Conditional Access to identify external connections originating from a specific office.
  • Option C is incorrect: "Trusted IPs" are primarily associated with legacy per-user MFA settings and not the modern "Named locations" construct used within Conditional Access policies for network-based exemptions.
  • Option D is incorrect: Private IP ranges are unsuitable for external identification, and "Trusted IPs" is not the current or recommended Conditional Access mechanism for this scenario.


QUESTION 2

You have a Microsoft Entra tenant.

You need to create a Conditional Access policy to manage administrative access to the tenant. The solution must ensure that administrators are authenticated by using a phishing-resistant multi-factor authentication (MFA) method.

Which three authentication methods should you include in the solution? Each correct answer presents a complete solution.

A
Windows Hello for Business
B
an FIDO2 security key
C
certificate-based authentication (multi-factor)
D
voice call
E
SMS
F
email OTP
G
certificate-based authentication (single-factor)
H
Microsoft Authenticator

Correct Option: A,B,C

โœ… **Windows Hello for Business **

Reasoning: Windows Hello for Business uses strong, device-bound cryptographic keys secured by a TPM. This design inherently resists phishing by tying authentication to the specific device and user, making it a recognized phishing-resistant MFA method.


โœ… **an FIDO2 security key **

Reasoning: FIDO2 security keys employ public-key cryptography (WebAuthn) and are device-bound. They are specifically designed to be phishing-resistant, as the authentication challenge-response mechanism prevents credential harvesting by malicious sites.


โœ… **certificate-based authentication (multi-factor) **

Reasoning: Multi-factor certificate-based authentication (e.g., smart card with PIN) uses device-bound certificates and cryptographic proof. The requirement for a second factor (like a PIN) makes it highly resistant to phishing attacks by ensuring both possession of the certificate and knowledge of the PIN. โŒ Why the other choices are incorrect:

  • Option D: voice call is incorrect: Voice calls are highly susceptible to vishing and MFA fatigue attacks, making them not phishing-resistant.
  • Option E: SMS is incorrect: SMS is vulnerable to smishing, SIM-swapping, and interception, rendering it not phishing-resistant.
  • Option F: email OTP is incorrect: Email OTPs are easily compromised through email phishing, account takeover, or malware, providing no phishing resistance.
  • Option G: certificate-based authentication (single-factor) is incorrect: While strong, single-factor CBA lacks the crucial second factor (e.g., PIN) that makes multi-factor CBA robustly phishing-resistant against various attack vectors.
  • Option H: Microsoft Authenticator is incorrect: While a strong MFA method, standard Microsoft Authenticator push notifications can be vulnerable to MFA fatigue attacks and are not classified as inherently phishing-resistant in the same tier as FIDO2 or Windows Hello for Business without specific advanced configurations.


QUESTION 3

You have a Microsoft 365 E5 subscription.

You need to perform the following tasks:

โ€ข Identify the locations and IP addresses used by Azure AD users to sign in.
โ€ข Review the Azure AD security settings and identify improvement recommendations.
โ€ข Identify changes to Azure AD users or service principals.

What should you use for each task? To answer, drag the appropriate resources to the correct requirements. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Answer Canvas

Correct Mappings:

โœ… Step 1: Sign-in logs matches with -> Identify the locations and IP addresses used by Azure AD users to sign in:
Reasoning: The Azure AD Sign-in logs capture detailed information about every user sign-in attempt. This data explicitly includes the source IP address and the associated geographical location, making it the designated tool for this task.

โœ… Step 2: Audit logs matches with -> Identify changes to Azure AD users or service principals:
Reasoning: The Azure AD Audit logs record all administrative actions and configuration changes within the tenant. This includes events like user creation, password resets, application consent, and modifications to service principals, providing a complete change history.

โœ… Step 3: Identity secure score matches with -> Review the Azure AD security settings and identify improvement recommendations:
Reasoning: Azure AD Identity Secure Score is a security analytics feature that assesses your identity security configuration against Microsoft's best practices. It provides a numerical score and actionable recommendations to improve your security posture.



Reference: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/overview-monitoring
QUESTION 4

You have an Azure Active Directory (Azure AD) tenant that has Security defaults disabled. You are creating a conditional access policy as shown in the following exhibit.

 

 

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Answer Canvas

โœ… Grant settings

Reasoning: To enforce multi-factor authentication (MFA) within a Conditional Access policy, the "Grant" controls are used. This section dictates what controls are required (e.g., MFA, compliant device) for access to be granted.


โœ… Sessions settings

Reasoning: To control how often a user is prompted for authentication (e.g., every eight hours), the "Session" controls are configured. This setting specifically manages sign-in frequency or persistent browser sessions.

QUESTION 5

You have a Microsoft 365 subscription.

You have an Azure subscription that contains an Azure App Service web app named App1.

You have multiple devices that run Windows and are enrolled in Microsoft Intune.

You deploy the Global Secure Access client to the devices by using Intune.

You need to configure private access to App1.

What should you do next?

A
Create a remote network.
B
Configure a traffic forwarding profile.
C
Deploy a private network connector.
D
Create an application security group.

Correct Option: B

โœ…

Reasoning: After deploying the Global Secure Access client, the next critical step to enable private access is to configure a traffic forwarding profile (specifically, the private access profile). This profile instructs the client on which traffic to intercept and steer through the Global Secure Access service for private resources like App1. โŒ Why the other choices are incorrect:

  • Option A is incorrect: Remote networks are typically used for connecting entire branch offices or networks via site-to-site VPNs, not primarily for configuring access to a single Azure App Service web app via a client.
  • Option C is incorrect: While a private network connector is essential to establish connectivity from Global Secure Access to App1, configuring the traffic forwarding profile is the immediate next step for the client to know it should use private access. The profile enables the client's private access functionality.
  • Option D is incorrect: Application security groups (ASGs) are Azure networking features used with Network Security Groups to define network policies within Azure. They are not part of configuring Global Secure Access private access functionality for client devices.


QUESTION 6

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the identities shown in the following table.

You have an attribute set named Custom 1 that contains the custom security attributes shown in the following table.

For each of the following statements. select Yes if the statement is true. Otherwise. select No.

Technical Scenario Diagram
Answer Canvas

Statement 1: Admin1 can assign Attribute1 to User1. (No)

By default, the Global Administrator role does not have permissions to assign custom security attributes. To perform this action, Admin1 would need to be explicitly assigned the Attribute Assignment Administrator role.

Statement 2: Admin2 can modify Attribute1. (No)

Admin2 has the Attribute Assignment Administrator role, which only grants permissions to assign attribute values to objects. Modifying the attribute definition itself (like its name or type) requires the Attribute Definition Administrator role.

Statement 3: Admin2 can assign Attribute2 to Group1. (No)

Custom security attributes can only be assigned to specific object types: users, enterprise applications (service principals), and managed identities. They are not supported for group objects. Therefore, Admin2 cannot assign an attribute to Group1.



Reference: https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview
QUESTION 7

You have an Azure Active Directory (Azure AD) tenant that contains a user named SecAdmin1. SecAdmin1 is assigned the Security administrator role. SecAdmin1 reports that she cannot reset passwords from the Azure AD Identity Protection portal.

You need to ensure that SecAdmin1 can manage passwords and invalidate sessions on behalf of non-administrative users. The solution must use the principle of least privilege.

Which role should you assign to SecAdmin1?

A
Authentication administrator
B
Helpdesk administrator
C
Privileged authentication administrator
D
Security operator

Correct Option: A

โœ… **Authentication administrator **

Reasoning: The Authentication administrator role enables SecAdmin1 to reset passwords for any user and invalidate all user refresh tokens and MFA sessions. This role provides the necessary comprehensive authentication management, including capabilities often performed from Azure AD Identity Protection, while adhering to least privilege compared to higher-level admin roles. โŒ Why the other choices are incorrect:

  • Option B is incorrect: The Helpdesk administrator can reset passwords and invalidate refresh tokens for non-administrative users, but it cannot revoke MFA sessions, which is a critical part of comprehensive session invalidation.
  • Option C is incorrect: Privileged authentication administrator grants excessive privileges, including managing global administrator credentials, which violates the principle of least privilege for managing non-administrative users.
  • Option D is incorrect: The Security operator role is for monitoring and managing security posture and does not include permissions to reset passwords or invalidate user sessions.


QUESTION 8

You have an Azure subscription named Sub1.

You plan to use Microsoft Entra Permissions Management to manage Sub1.

You need to ensure that Permissions Management can perform the following tasks:

 

โ€ข Identify unused permissions assigned to applications and managed identities.

โ€ข Provide users with recommendations about which permissions to remove.

โ€ข Remove unused permissions.

 

The solution must follow the principle of least privilege.

Which role should you assign to the service principal of Permissions Management, and what should you use to provide recommendations and remove unused permissions? To answer, select the appropriate options in the answer area.

 

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Answer Canvas

โœ… User Access Administrator

Reasoning: To allow Microsoft Entra Permissions Management to remove unused permissions, its service principal requires a role capable of modifying access assignments. The User Access Administrator role grants the necessary permissions to manage user access to Azure resources, including role assignments, adhering to the principle of least privilege for remediation.


โœ… An Autopilot rule

Reasoning: Microsoft Entra Permissions Management identifies unused permissions, provides recommendations, and enables their removal through automated, rule-based policies. An "Autopilot rule" represents such a proactive, automated mechanism within the service for managing permissions based on defined criteria and usage patterns.

QUESTION 9

You have a Microsoft Entra tenant that contains 1.000 users. The users are assigned Microsoft Entra Suite licenses.

Vou perform the following actions:

โ€ข Deploy Global Secure Access.

โ€ข create a Global secure Access security profile named Profilel.

โ€ข Create the following Conditional Access policies:

o Name: CApoIicy1

o Target resources: All internet resources with Global Secure Access

o Name: CApoIicy2

โ€ข use Global secure Access security profile: profile 1

To which Global secure Access traffic forwarding profiles is CAPoIicy1 linked, and to which profile does profilel apply? TO answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains 1,000 users. The users are assigned Microsoft Entra Suite licenses.

Technical Scenario Diagram
Answer Canvas

Box 1: CAPolicy1 is linked to:

โœ… Microsoft traffic profile and Internet access profile

Reasoning: When Global Secure Access is deployed, by default, it forwards traffic for both the Microsoft 365 services (Microsoft traffic profile) and general web traffic (Internet access profile). A Conditional Access policy applied to Global Secure Access is linked to all active forwarding profiles. The question doesn't state any profiles are disabled, so CAPolicy1 is linked to both.


Box 2: Profile1 applies to:

โœ… Internet access profile

Reasoning: A Global Secure Access security profile is a container for Conditional Access policies that is then linked to a specific traffic forwarding profile. Since CAPolicy1 targets "All internet resources," which aligns with the purpose of the Internet access profile, it indicates that the administrator has linked Profile1 to the "Internet access profile" to manage non-Microsoft 365 internet traffic.



Reference: https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-apply-conditional-access-policies
QUESTION 10

You configure Azure Active Directory (Azure AD) Password Protection as shown in the exhibit. (Click the Exhibit tab.)

You are evaluating the following passwords:

Pr0jectlitw@re T@ilw1nd C0nt0s0

Which passwords will be blocked?

A
Pr0jectlitw@re and T@ilw1nd only
B
C0nt0s0 only
C
C0nt0s0, Pr0jectlitw@re, and T@ilw1nd
D
C0nt0s0 and T@ilw1nd only
E
C0nt0s0 and Pr0jectlitw@re only

Correct Option: C

โœ…

Reasoning: Azure AD Password Protection with custom banned lists applies fuzzy matching, including common character substitutions (e.g., '0' for 'o', '@' for 'a', '1' for 'l') and case insensitivity. All three passwords (C0nt0s0, Pr0jectlitw@re, T@ilw1nd) contain terms from the custom banned list ('Contoso', 'project', 'Litware', 'Tailwind') with these substitutions, so they will all be blocked. โŒ Why the other choices are incorrect:

  • Option A is incorrect: C0nt0s0 is also blocked because 'C0nt0s0' is a common substitution for 'Contoso', which is on the banned list.
  • Option B is incorrect: Pr0jectlitw@re and T@ilw1nd are also blocked due to containing banned terms with common character substitutions.
  • Option D is incorrect: Pr0jectlitw@re is also blocked as it contains 'project' and 'Litware' from the banned list via character substitutions.
  • Option E is incorrect: T@ilw1nd is also blocked because 'T@ilw1nd' is a common substitution for 'Tailwind', which is on the banned list.
QUESTION 11

You have multiple on-premises devices that run either Windows or Linux.

You have a Microsoft 365 E5 subscription.

You configure Microsoft Entra Internet Access.

You need to ensure that all the on-premises devices access the internet by using Global Secure Access.

What should you do in the Microsoft Entra admin center?

A
Create a remote network.
B
Create a named location.
C
Create an access package.
D
Deploy the Global Secure Access client.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 12

You have a Microsoft 365 subscription.

You need to create a Conditional Access policy that will use a Global Secure Access security profile. The solution must ensure that users are prevented from accessing websites that include the word gambling in

the URL.

What should you do first?

A
Create a web content filtering policy.
B
Create a named location.
C
Configure the Adaptive Access settings.
D
Create a network security group (NSG).

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 13

You have a Microsoft 365 tenant.

All users have mobile phones and laptops.

The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access.

You plan to implement multi-factor authentication (MFA).

Which MFA authentication method can the users use from the remote location?

A
a verification code from the Microsoft Authenticator app
B
security questions
C
voice
D
SMS

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 14

Use the following login credentials as needed:

To enter your username, place your cursor in the Sign in box and click on the username below.

To enter your password, place your cursor in the Enter password box and click on the password below.

Microsoft 365 Username:admin@XXYyz112233.onmicrosoft.com

Microsoft 365 Password: =1122334455667788

If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.

The following information is for technical support purposes only:

Lab Instance: 99999999

 

You need to create a group named Audit. The solution must ensure that the members of Audit can activate the Security Reader role.

To complete this task, sign in to the appropriate admin center.

 

Technical Scenario Diagram
Solution Locked
A
B
C
D

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 15

You have a Microsoft Entra tenant.

You need to implement smart lockout with a lockout threshold of 10 failed sign-ins.

What should you configure in the Microsoft Entra admin center?

A
Authentication strengths
B
User risk policy
C
Sign-in risk policy
D
Password protection

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 16

You configure a new Microsoft 365 tenant to use a default domain name of contoso.com.

You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies. What should you do first?

A
Disable the User consent settings.
B
Disable Security defaults.
C
Configure a multi-factor authentication (MFA) registration policy.
D
Configure password protection for Windows Server Active Directory.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 17

You have a Microsoft 365 subscription that is onboarded to Microsoft Entra Permissions Management.

You need to identify managed identities that are assigned permissions and remove any permissions that have been unused for 90 days. The solution must minimize administrative effort.

What should you do in the Entra Permissions Management portal?

A
Configure an Autopilot rule.
B
Schedule a Permissions analytics report.
C
From Microsoft Entra Insights, review Service principals with privileged role assignments.
D
Run an audit query.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 18

You have a Microsoft Entra tenant that has a Microsoft Entra ID P2 license.

You create a Log Analytics workspace.

You need to ensure that you can view Microsoft Entra ID audit log information by using Azure Monitor.

What should you do first?

A
Modify the Diagnostics settings for Microsoft Entra ID.
B
Run the Update-MgDomain cmdlet.
C
Run the Update-MgOrganization cmdlet.
D
Create a Data Collection Rule.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 19

Your company has a Microsoft 365 tenant.

The company has a call center that contains 300 users. In the call center, the users share desktop computers and might use a different computer every day. The call center computers are NOT configured for biometric identification.

The users are prohibited from having a mobile phone in the call center.

You need to require multi-factor authentication (MFA) for the call center users when they access Microsoft 365 services. What should you include in the solution?

A
a named network location
B
the Microsoft Authenticator app
C
Windows Hello for Business authentication
D
FIDO2 tokens

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 20

You have an Azure subscription named Sub1.

You plan to deploy Microsoft Entra Permissions Management.

You need to ensure that Permission Management can onboard Sub1. The solution must follow the principle of least privilege.

How should you complete the PowerShell command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 21

You have a Microsoft Entra tenant.

You discover that a large number of new apps were added to the tenant.

You need to implement an approval process for new enterprise applications.

What should you do?

A
From the Microsoft Entra admin center, configure the Admin consent settings.
B
From the Microsoft Entra admin center, configure an access review.
C
From the Microsoft Defender portal, configure an app connector.
D
From the Microsoft Defender portal, create an app detection policy.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 22

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

All users who run applications registered in Azure AD are subject to conditional access policies. You need to prevent the users from using legacy authentication.

What should you include in the conditional access policies to filter out legacy authentication attempts?

A
a cloud apps or actions condition
B
a user risk condition
C
a client apps condition
D
a sign-in risk condition

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 23

You have an Microsoft Entra tenant that contains the users shown in the following table.

 

 

The tenant contains the identities shown in the following table.

 

 

Which users can create custom security attributes, and to which identities can the attributes be assigned? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 24

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Sitel.

You need to be notified if a user downloads more than 50 files in one minute from Sitel.

Which type of policy should you create in Microsoft Defender for Cloud Apps?

A
file policy
B
activity policy
C
app discovery policy
D
session policy

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 25

You have an Azure Active Directory (Azure AD) tenant. You open the risk detections report.

Which risk detection type is classified as a user risk?

A
impossible travel
B
anonymous IP address
C
atypical travel
D
leaked credentials

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 26

Your company has a Microsoft Entra tenant that contains a user named User1.
The company has two departments named marketing and finance.
You need to grant permissions to User1 to manage only the users in the marketing department.

What should you create first?

A
a Microsoft 365 group
B
an administrative unit
C
a management group
D
a resource group

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 27

You have an Azure subscription that contains two virtual machines named VMI and VM2 and an Azure SQL managed instance named SQL1.

You need to ensure that VMI and VM2 can retrieve data from SQLI.

The solution must minimize administrative effort.

What should you create first?

A
a Microsoft Entra user account
B
a managed identity
C
a certificate
D
a shared access signature (SAS) token

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 28

You have a Microsoft 365 tenant.

All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user- owned and are only registered in Azure AD.

You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer from downloading or syncing files. Other users must NOT

be restricted.

Which policy type should you create?

A
a Microsoft Cloud App Security activity policy that has Microsoft Office 365 governance actions configured
B
an Azure AD conditional access policy that has session controls configured
C
an Azure AD conditional access policy that has client apps conditions configured
D
a Microsoft Cloud App Security app discovery policy that has governance actions configured

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 29

You have a Microsoft Entra tenant.

You need to implement protected actions.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 30

You have a Microsoft Entra tenant named contoso.com that contains a group named Groupl. Groupl contains 50 users in your

company's IT department and 50 users in your company's accounts department.

You have a partner company that has a Microsoft Entra tenant named fabrikam.com.

You configure cross-tenant synchronization between contoso.com and fabrikam.com.

You need to sync the members of Groupl to fabrikam.com. The solution must meet the following requirements:

  • Ensure that only the IT department users sync with fabrikam.com
  • Minimize administrative effort.

What should you do in the Cross-tenant synchronization settings? To answer, select the appropriate options in the answer area.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 31

You have an Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant.

The on-premises network contains a VPN server that authenticates to the on-premises Active Directory domain. The VPN server does NOT support Azure Multi- Factor Authentication (MFA).

You need to recommend a solution to provide Azure MFA for VPN connections. What should you include in the recommendation?

A
Azure AD Application Proxy
B
an Azure AD Password Protection proxy
C
Network Policy Server (NPS)
D
a pass-through authentication proxy.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 32

You have an Azure subscription that contains a virtual machine named VM1 and an Azure key vault named Vault1. VM1 has a system-assigned managed identity.

You need to ensure that VM1 can retrieve the values of secrets stored in Vault1. The solution must minimize administrative effort.

What should you do first?

A
Configure the Resource access settings for Vault1.
B
Configure the permissions model for Vault1.
C
Add a user-assigned managed identity to VM1.
D
Assign an Azure role to VM1.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 33

You have a Microsoft 365 subscription.

You need to ensure that when users access the Microsoft 365 portal from Microsoft Edge and have their browser language set to Spanish, they are presented with a Spanish sign-in form.

What should you do in the Microsoft Entra admin center?

A
Configure the Company branding settings.
B
Create a Conditional Access policy.
C
From Global Secure Access, configure the Session management settings.
D
From Settings for the users, configure the Usage location setting.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 34

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant is configured to sync with an on-premises Active Directory domain. The domain contains the servers shown in the following table.

The domain controllers are prevented from communicating to the internet. You implement Azure AD Password Protection on Server1 and Server2. You deploy a new server named Server4 that runs Windows Server 2019.

You need to ensure that Azure AD Password Protection will continue to work if a single server fails. What should you implement on Server4?

A
Azure AD Connect
B
Azure AD Application Proxy
C
Password Change Notification Service (PCNS)
D
the Azure AD Password Protection proxy service

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 35

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant has the authentication methods shown in the following table.

Which users will sign in to cloud apps by using number matching?

A
User1 only
B
User2 only
C
User3 only
D
User1 and User2 only
E
User2 and User3 only

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 36

Your on-premises network contains an Active Directory domain that uses Microsoft Entra Connect sync to sync with a Microsoft Entra tenant.

You need to configure Microsoft Entra Connect sync to meet the following requirements:

โ€ข Microsoft Entra sign-ins must be authenticated by an Active Directory domain controller.
โ€ข Active Directory domain users must be able to use Microsoft Entra self-service password reset (SSPR).
โ€ข Minimize administrative effort.

What should you use for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 37

You have a Microsoft 365 E5 tenant. You purchase a cloud app named App1.

You need to enable real-time session-level monitoring of App1 by using Microsoft Cloud App Security.

In which order should you perform the actions? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 38

You have an Azure subscription that contains the resources shown in the following table.

You need to grant permissions to the resources by using attribute-based access control (ABAC).

To which resource can you grant permissions?

A
Vault1
B
VM1
C
App1
D
Storage1

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 39

Your network contains an on-premises an Active Directory Domain Services (AD DS) domain. The domain syncs with a Microsoft 365 subscription by using Microsoft Entra Connect Sync.

You plan to create 300 new users. The details of the user accounts are saved in a Microsoft Excel spreadsheet.

You need to automate the creation of the users. The solution must meet the following requirements:

  • The users must be able to access the resources in the Microsoft 365 subscription.
  • The users must be able to access the resources on the on-premises network.
  • Administrative effort must be minimized.

Which PowerShell cmdlets should you include in the solution?

A
New-ADUser and Import-CSV
B
Set-MgUser and Import-CSV
C
Set-ADUser and Get-Content
D
New-MgUser and Get-Content

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 40

You have a Microsoft 365 tenant.

All users have mobile phones and laptops.

The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access.

You plan to implement multi-factor authentication (MFA).

Which MFA authentication method can the users use from the remote location?

A
a notification through the Microsoft Authenticator app
B
an app password
C
Windows Hello for Business

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 41

You have a Microsoft Entra tenant that contains the users shown in the following table.

You add an enterprise application named App1 and configure the following Self-service settings:

โ€ข Allow users to request access to this application: Yes

โ€ข To which group should assigned users be added: Group1

โ€ข Require approval before granting access to this application: Yes

โ€ข Who is allowed to approve access to this application: User2

Which users can request access to App1?

A
User3 only
B
User2 and User3 only
C
User1 and User3 only
D
User1, User2, and User3

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 42

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

You discover that users connect to unsanctioned third-party apps.

You need to automatically identify and block the use of unsanctioned apps that have a risk score of 5 or higher and generate more than 200 GB of daily traffic. The solution must minimize administrative effort.

What should you do?

A
From the Microsoft Defender portal, create an app governance policy.
B
From the Microsoft Entra admin center, create a Conditional Access policy.
C
Create an app discovery policy by using the New popular app template.
D
Create an app discovery policy by using the New risky app template.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 43

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services. Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.

You need to block the users automatically when they report an MFA request that they did not initiate. Solution: From the Azure portal, you configure the Notifications settings for multi-factor authentication (MFA). Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 44

You work for a company named Contoso, Ltd. that has a Microsoft Entra tenant named contoso.com.

Contoso is working on a project with the following two partner companies:

โ€ข A company named

A
Guest invite settings
B
Verifiable credentials
C
Named locations
D
Collaboration restrictions

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 45

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services. Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.

You need to block the users automatically when they report an MFA request that they did not initiate.

Solution: From the Azure portal, you configure the Account lockout settings for multi-factor authentication (MFA). Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 46

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

 

 

You plan to manage the lifecycles of the groups.

Which groups can be set to expire, and what is the shortest group lifetime you can set? To answer, select the appropriate options in the answer area.

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 47

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services. Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.

You need to block the users automatically when they report an MFA request that they did not initiate.

Solution: From the Azure portal, you configure the Block/unblock users settings for multi-factor authentication (MFA). Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 48

You have a Microsoft Entra tenant that contains two remote networks named RemoteNetwork1 and RemoteNetwork2 and the users shown in the following table.

You have the devices shown in the following table.

You have a Conditional Access policy that has the following settings:
o Name: CAPolicy1
o Assignments
- Users: Group1, Group2
- Target resources: All internet resources with Global Secure Access
o Access controls
- Grant: Require multifactor authentication
o Enable policy: On

Global Secure Access traffic forwarding is configured as shown in the following exhibit.

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 49

You have a Microsoft 365 tenant.

You need to identify users who have leaked credentials. The solution must meet the following requirements:

 

 

Identify sign-ins by users who are suspected of having leaked credentials. Flag the sign-ins as a high-risk event.

 

Immediately enforce a control to mitigate the risk, while still allowing the user to access applications.

 

What should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 50

You have a Microsoft Entra tenant named contoso.com that contains a user named User1.

User1 has the devices shown in the following table:
 

On November 5, 2025, you create and enforce terms of use in contoso.com that has the following settings:

โ€ข Name: Terms1
โ€ข Display name: Contoso terms of use
โ€ข Require users to expand the terms of use: On
โ€ข Require users to consent on every device: On
โ€ข Expire consents: On
โ€ข Expire starting on: December 10, 2025
โ€ข Frequency: Monthly

On November 15, 2025, User1 accepts Terms1 on Device3.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 51

You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

 

 

You plan to implement Azure AD Identity Protection.

Which users can configure the user risk policy, and which users can view the risky users report? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 52

You have a Microsoft Entra tenant that contains the users shown in the following table.
 


Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for Azure management template.

Which users will be required to use multi-factor authentication (MFA) the next time they sign in?

 

A
Admin2 and Admin3 only
B
Admin1 and Admin4 only
C
Admin1, Admin2, and Admin3 only
D
Admin1, Admin2, Admin3, and Admin4

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 53

You have an Azure Active Directory (Azure AD) tenant that contains an administrative unit named Department1. Department1 has the users shown in the Users exhibit. (Click the Users tab.)

 

 

Department1 has the groups shown in the Groups exhibit. (Click the Groups tab.)

 

 

Department1 has the user administrator assignments shown in the Assignments exhibit. (Click the Assignments tab.)

 

 

The members of Group2 are shown in the Group2 exhibit. (Click the Group2 tab.)

 

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 54

You have a Microsoft Entra tenant.

You need to use Microsoft Entra workbooks to monitor identity activity.

To what should you set Destination details in the Diagnostic settings?

A
Archive to a storage account
B
Send to partner solution
C
Stream to an event hub
D
Send to Log Analytics workspace

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 55

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services. Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.

You need to block the users automatically when they report an MFA request that they did not initiate. Solution: From the Azure portal, you configure the Fraud alert settings for multi-factor authentication (MFA). Does this meet the goal?

A
Yes
B
No

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 56

You have a Microsoft Entra tenant that contains the users shown in the following table.

 



The tenant contains the Microsoft 365 groups shown in the following table.

 



You create an access review named Access1 that has the following settings:

โ€ข Select what to review: Teams + Groups
โ€ข Review scope: All Microsoft groups with guest users
โ€ข Scope: Guest users only
โ€ข Select reviewers: Users review their own access

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 57

You need to meet the planned changes and technical requirements for App1. What should you implement?

A
a policy set in Microsoft Endpoint Manager
B
an app configuration policy in Microsoft Endpoint Manager
C
an app registration in Azure AD
D
Azure AD Application Proxy

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 58

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant. The tenant contains the users shown in the following table.

 



Sub1 contains a resource group named RG1.

The tenant contains the groups shown in the following table.

 



You deploy a virtual machine named VM1 to RG1. VM1 runs Windows Server and has Microsoft Entra login enabled.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 59

You need to implement on-premises application and SharePoint Online restrictions to meet the authentication requirements and the access requirements. What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 60

You have a Microsoft Entra tenant.

You need to ensure that users are prevented from consenting to high-privilege permission requests for enterprise applications. The solution must ensure that the users can consent to low-risk permission requests.

What should you modify first?

A
Admin consent settings
B
Permission classifications
C
User consent settings
D
App registrations

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 61

You need to configure app registration in Azure AD to meet the delegation requirements. What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 62

You have a Microsoft Entra tenant that contains the identities shown in the following table.

 

 

You register an app named App1 in the tenant.

To which identities can you assign the Owner role for App1?

A
User1 only
B
User1 and Group1 only
C
User1 and SP1 only
D
User1, Group1, and Group2 only
E
User1, Group1, and SP1 only
F
User1, Groupl, Group2, and SP1

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 63

You have a Microsoft 365 tenant and an Active Directory domain named adatum.com. You deploy Azure AD Connect by using the Express Settings.

You need to configure self-service password reset (SSPR) to meet the following requirements:

 

When users reset their password, they must be prompted to respond to a mobile app notification or answer three predefined security questions. Passwords must be synced between the tenant and the domain regardless of where the password was reset.

 

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 64

You have an on-premises server named Server1 that runs Windows Server.

You have a Microsoft Entra tenant that contains an app registration named App1. App1 has Microsoft Graph application permissions.

You need to configure the environment to support App1. The solution must meet the following requirements:

โ€ข App1 must be accessible only from the corporate network.
โ€ข The credentials for App1 must NOT be stored as plain text.
โ€ข Non-interactive scheduled tasks on Server1 must be able to authenticate to App1.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 65

You have a Microsoft 365 tenant.

Sometimes, users use external, third-party applications that require limited access to the Microsoft 365 data of the respective user. The users register the applications in Azure Active Directory (Azure AD).

You need to receive an alert if a registered application gains read and write access to the usersโ€™ email. What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 66

You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server.

You enable Microsoft Entra login for the virtual machines.

Users report that they cannot sign in to the virtual machines by using their Microsoft Entra credentials.

You need to ensure that the users can sign in to the virtual machines.

What should you do first?

A
From the Microsoft Entra admin center, delete the device registrations of the virtual machines.
B
Revoke the primary refresh token.
C
Enable SSH client support for OpenSSH.
D
Ensure that the virtual machines can access <a href="https://enterpriseregistration.windows.net">https://enterpriseregistration.windows.net</a>.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 67

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain.

Users connect to the internet by using a hardware firewall at your company. The users authenticate to the firewall by using their Active Directory credentials. You plan to manage access to external applications by using Azure AD.

You need to use the firewall logs to create a list of unmanaged external applications and the users who access them. What should you use to gather the information?

A
Application Insights in Azure Monitor
B
access reviews in Azure AD
C
Cloud App Discovery in Microsoft Cloud App Security
D
enterprise applications in Azure AD

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 68

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains a registered app named App1.

You have a partner organization that has a Microsoft Entra tenant. The tenant contains a registered app named App2.

You need to ensure that App1 can access App2.

Which two types of credentials can App1 use? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A
certificate
B
managed identity
C
secret
D
user account
E
one-time password

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 69

You have an on-premises datacenter that contains the hosts shown in the following table.

 

 

You have an Azure Active Directory (Azure AD) tenant that syncs to the Active Directory forest. Multi-factor authentication (MFA) is enforced for Azure AD. You need to ensure that you can publish App1 to Azure AD users.

What should you configure on Server and Firewall1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 70

You have 2,500 users who are assigned Microsoft 365 E3 licenses. The licenses are assigned to individual users.

You assign Microsoft 365 E5 licenses to a group that includes all users.

You need to remove the Microsoft 365 E3 licenses from the users by using the least amount of administrative effort.

What should you use?

A
the Update-MgGroup cmdlet
B
the Set-WindowsProductKey cmdlet
C
the Set-MgUserLicense cmdlet
D
the Licenses blade in the Microsoft Entra admin center

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 71

You have an Azure Active Directory (Azure AD) tenant that has the default App registrations settings. The tenant contains the users shown in the following table.

 

 

You purchase two cloud apps named App1 and App2. The global administrator registers App1 in Azure AD. You need to identify who can assign users to App1, and who can register App2 in Azure AD.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 72

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the groups shown in the following table.

Which groups can you manage by using Privileged Identity Management (PIM)?

A
Group2 only
B
Group1 and Group2 only
C
Group2 and Group4 only
D
Group1, Group2, and Group3 only
E
Group1, Group2, Group3, and Group4

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 73

You have a custom cloud app named App1 that is registered in Azure Active Directory (Azure AD). App1 is configured as shown in the following exhibit.

 

 

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Hot Area:

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 74

You have a Microsoft Entra tenant that contains 1,000 users. The users are assigned Microsoft Entra Suite licenses.

You are deploying Global Secure Access.

You need to ensure that connections to www.microsoft.com are bypassed by Global Secure Access.

Which profiles should you update?

A
Intemet access profile only
B
Microsoft traffic profile only
C
Microsoft traffic profile and Internet access profile only
D
Microsoft traffic profile, Private access profile, and Internet access profile

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 75

You have an Azure Active Directory (Azure AD) tenant.

You create an enterprise application collection named HR Apps that has the following settings:

 

  • Applications: App1, App2, App3 
  • Owners: Admin1
  • Users and groups: HRUsers

 

All three apps have the following Properties settings:

 

  • Enabled for users to sign in: Yes 
  • User assignment required: Yes Visible to users: Yes

 

Users report that when they go to the My Apps portal, they only see App1 and App2. You need to ensure that the users can also see App3.

What should you do from App3?

Technical Scenario Diagram
Solution Locked
A
From Users and groups, add HRUsers.
B
From Single sign-on, configure a sign-on method.
C
From Properties, change User assignment required to No.
D
From Permissions, review the User consent permissions.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 76

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains three users named User1, User2 and User3.

You have the devices shown in the following table.

 



You deploy a virtual machine that has the following configurations:

โ€ข Name: VM1
โ€ข Resource group: RG1
โ€ข Operating system: Windows Server
โ€ข Login with Microsoft Entra ID: Enabled

You have the Azure role assignments shown in the following table.

 



For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 77

You have an Azure Active Directory (Azure AD) tenant. For the tenant, Users can register applications is set to No.

A user named Admin1 must deploy a new cloud app named App1.

You need to ensure that Admin1 can register App1 in Azure AD. The solution must use the principle of least privilege. Which role should you assign to Admin1?

A
Managed Application Contributor for Subscription1.
B
Application developer in Azure AD.
C
Cloud application administrator in Azure AD.
D
App Configuration Data Owner for Subscription1.

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 78

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the administrative units shown in the following table.

The tenant contains the groups shown in the following table.

You perform the following actions:

โ€ข Assign User1 the User Administrator role for AU2.
โ€ข Assign User3 the Groups Administrator role for AU1.
โ€ข Assign User5 the Authentication Administrator role for AU3.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

QUESTION 79

You have a Microsoft 365 tenant that contains a group named Group1 as shown in the Group1 exhibit. (Click the Group1 tab.)

 

 

You create an enterprise application named App1 as shown in the App1 Properties exhibit. (Click the App1 Properties tab.)

 

 

You configure self-service for App1 as shown in the App1 Self-service exhibit. (Click the App1 Self-service tab.)

 

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

 

Technical Scenario Diagram
Interactive Canvas Locked

Premium Solution Locked

Unlock all 391 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 391 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

> Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

> Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat โ— Active Now

๐Ÿ‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting