Microsoft Certified: Identity and Access Administrator Associate practice questions
207 free questions with answers and explanations.
- 1.A security administrator is reviewing sign-in logs in Azure AD and notices a significant number of failed sign-in attempts originating from unusual geographic locations for several user accounts. Some of these accounts also show signs of suspicious activity, such as sign-ins from infected devices. The administrator wants to automatically detect and respond to these types of risks. Which Azure AD feature should be configured?Implement an authentication and access management solution
- 2.A company uses Azure AD and has several line-of-business (LOB) applications. One critical application requires that users accessing it must be registered with Microsoft Entra ID and have a specific 'Partner' attribute set to 'True'. The company wants to enforce this condition before users are granted access to the application, without modifying the application code. Which Azure AD feature should be used to achieve this?Implement an authentication and access management solution
- 3.A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity model using Azure AD Connect. They have a strict security requirement that user password hashes must NEVER be synchronized to Azure AD. However, users must still be able to sign in to both on-premises and cloud applications using the same credentials. Which authentication method should the client configure in Azure AD Connect?Implement an authentication and access management solution
- 4.A global organization uses Azure AD Connect to synchronize user accounts from its on-premises Active Directory to Azure AD. The organization has users located in different geographical regions, and each region has its own set of domain controllers. To ensure high availability and disaster recovery for the synchronization service, what is the recommended deployment strategy for Azure AD Connect?Implement an authentication and access management solution
- 5.A security architect is designing an authentication solution for a new internal web application. The application will be accessed by employees only, and all employees are managed in Azure AD. The architect wants to implement a solution where users are automatically signed in when they access the application from a corporate-joined device within the corporate network, without explicitly entering credentials. If they access from outside the corporate network or from a non-corporate device, they should be prompted for MFA. Which combination of Azure AD features should the architect recommend?Implement an authentication and access management solution
- 6.A company uses Azure Active Directory (Azure AD) and has implemented Conditional Access policies. A new policy is being designed to require multifactor authentication (MFA) for all users accessing sensitive applications, but only when they are outside a trusted network location. How should this Conditional Access policy be configured?Implement an authentication and access management solution
- 7.A global company uses Azure AD and has deployed a new application that uses the OpenID Connect protocol for authentication. The application requires specific custom attributes from the user's profile, such as 'DepartmentID' and 'CostCenter', to be included in the ID token. How can these attributes be added to the ID token?Implement an authentication and access management solution
- 8.A company is implementing a new application that will be hosted on Azure App Service. This application needs to securely access data stored in Azure Key Vault without storing credentials in its code or configuration files. The company wants to use a managed identity for this purpose. Which type of managed identity should be assigned to the Azure App Service instance to meet this requirement?Implement an authentication and access management solution
- 9.A global company is integrating a critical line-of-business application with Azure AD. The application requires highly granular authorization based on custom user attributes that are specific to the company's business processes (e.g., 'ProjectRole', 'SecurityClearanceLevel'). These attributes are not standard Azure AD properties. The company wants to use Conditional Access policies to enforce access based on these custom attributes. How can these custom attributes be integrated with Azure AD Conditional Access?Implement an authentication and access management solution
- 10.A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without storing any credentials in the application code or configuration files. Which type of managed identity should the developer configure for the Azure VM?Implement an authentication and access management solution
- 11.A company is planning to implement Azure AD Connect to synchronize identities from its on-premises Active Directory to Azure AD. Due to strict security policies, the company requires that no password hashes are synchronized to Azure AD. However, users must still be able to use their on-premises credentials for single sign-on to cloud applications. Which authentication method should the company choose for Azure AD Connect to satisfy these requirements?Implement an authentication and access management solution
- 12.A security administrator is reviewing user sign-in logs in Azure AD and notices several failed sign-in attempts for a specific user account originating from unusual geographic locations. The administrator suspects a potential brute-force attack or credential compromise. Which Azure AD feature provides automated protection against such threats by analyzing sign-in behavior and applying remediation actions?Implement an authentication and access management solution
- 13.A company is integrating a custom-developed web application with Azure AD for single sign-on (SSO) using OpenID Connect. The application requires two specific custom attributes, 'EmployeeID' and 'ProjectRole', to be present in the user's ID token upon successful authentication. These attributes are stored as extension attributes in Azure AD. How should the administrator configure Azure AD to include these attributes in the ID token?Implement an authentication and access management solution
- 14.A large enterprise with multiple subsidiary companies, each with its own Azure AD tenant, needs to collaborate efficiently. Users from one subsidiary must be able to seamlessly access applications hosted in another subsidiary's tenant, and administrators need a simplified way to manage cross-tenant access without individual B2B invitations. Which Azure AD feature is designed to address this scenario?Implement an authentication and access management solution
- 15.A company is configuring an Azure AD Conditional Access policy to enforce multi-factor authentication (MFA) for all users accessing a specific sensitive application. The company wants to ensure that users who are already MFA-compliant from their trusted corporate network are not prompted again. Which condition should be configured in the Conditional Access policy to achieve this goal?Implement an authentication and access management solution
- 16.A developer is creating an application that needs to retrieve a list of all users in an Azure AD tenant. The application will run as a background service without a signed-in user. To follow the principle of least privilege, the developer wants to grant the minimum necessary permissions. Which Microsoft Graph permission should be assigned to the application's service principal for this task?Implement an authentication and access management solution
- 17.A company is implementing a new application that uses the OAuth 2.0 authorization code flow to obtain access tokens for accessing a protected API. The application is registered in Azure AD. Which of the following is a critical security best practice for handling the client secret in this flow?Implement an authentication and access management solution
- 18.A developer is building a multi-tenant SaaS application that needs to access Microsoft Graph API on behalf of signed-in users. The application requires permissions to read user profiles and send emails. To ensure the principle of least privilege, the developer wants to request only the necessary permissions. Which type of permission should the developer request for this scenario?Implement an authentication and access management solution
- 19.A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity solution with Azure Active Directory (Azure AD). They want to ensure that users continue to authenticate using their existing on-premises credentials for applications integrated with Azure AD, without storing password hashes in Azure AD. Which authentication method should be implemented?Implement an authentication and access management solution
- 20.A company is using Azure AD and wants to standardize user access to all corporate resources based on job function. They plan to use Azure AD groups to manage permissions. What type of Azure AD group should be used to assign licenses and access to Microsoft 365 applications, as well as access to non-Microsoft SaaS applications integrated with Azure AD for SSO?Implement an authentication and access management solution
- 21.A pilot project team is developing a new line-of-business application that will be hosted on Azure App Service. This application needs to securely access data from an Azure SQL Database and secrets from Azure Key Vault. The developers want to avoid embedding credentials in the application code or configuration files. Which Azure AD feature provides the most secure and manageable solution for this scenario?Implement an authentication and access management solution
- 22.A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without requiring hardcoded credentials or managing service principal secrets. Which identity solution should the developer implement for the VM?Implement an authentication and access management solution
- 23.A company uses Azure AD and has implemented Azure AD Privileged Identity Management (PIM) for its critical administrative roles. The security team wants to ensure that all activations of the 'Global Administrator' role require approval from a designated security group, and that the activation period is limited to a maximum of four hours. Which PIM setting should the administrator configure to meet these requirements?Implement an authentication and access management solution
- 24.A company is migrating its infrastructure to Azure and wants to ensure that Virtual Machines (VMs) can securely access Azure Key Vault to retrieve secrets without requiring hard-coded credentials. The solution must follow the principle of least privilege. What is the most appropriate method to achieve this?Implement an authentication and access management solution
- 25.A company wants to allow its employees to sign in to Azure AD-integrated applications using their personal Microsoft accounts (e.g., @outlook.com, @hotmail.com). This is for a specific set of applications used by a department that frequently collaborates with external consultants who use these accounts. What Azure AD feature should be configured to enable this authentication?Implement an authentication and access management solution
- 26.A global organization uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company uses an on-premises Active Directory Domain Services (AD DS) environment. The organization wants to integrate the acquired company's users into its existing Azure AD tenant for single sign-on (SSO) to Microsoft 365 and other cloud applications, while ensuring that password hashes are synchronized to Azure AD. Which Azure AD Connect synchronization option should be implemented?Implement an authentication and access management solution
- 27.A company is implementing Azure AD Connect to synchronize identities from its on-premises Active Directory to Azure Active Directory. The security team requires that password hashes are synchronized but also that users can sign in using their on-premises credentials when connected to the corporate network. What authentication method should be configured in Azure AD Connect to meet these requirements?Implement an authentication and access management solution
- 28.A company policy dictates that all users must have their user principal name (UPN) match their primary email address. The company uses Azure AD Connect to synchronize identities from an on-premises Active Directory Domain Services (AD DS) forest. Some users currently have a UPN suffix that does not match their email domain, and these users are experiencing issues signing in to Azure AD applications. What is the most effective solution to resolve this issue and align with company policy?Implement an authentication and access management solution
- 29.A company policy requires that all users accessing the 'Finance App' from unmanaged devices must use a compliant device. The company uses Intune to manage corporate devices and mark them as compliant. Which Azure AD feature, in conjunction with Intune, is used to enforce this access requirement?Implement an authentication and access management solution
- 30.A company uses Azure AD and has deployed a new application that uses the OpenID Connect protocol for authentication. The application requires specific user attributes, such as employee ID and department, to be included in the ID token for authorization purposes. Which feature in Azure AD should be configured to ensure these attributes are sent in the ID token?Implement an authentication and access management solution
- 31.A company is integrating a custom-developed web application with Azure AD for single sign-on (SSO). The application uses the OpenID Connect protocol. After a user successfully authenticates with Azure AD, the application needs to retrieve additional user profile information, such as the user's department and employee ID, which are not included in the default ID token. Which manifest property of the application registration in Azure AD should be modified to include these claims in the ID token?Implement an authentication and access management solution
- 32.A large enterprise with multiple subsidiary companies, each with its own Azure AD tenant, wants to implement a centralized application portal. Users from any subsidiary tenant should be able to access applications hosted in the central tenant's application portal using their own tenant's credentials. The enterprise wants to minimize administrative overhead for managing user accounts and ensure a seamless single sign-on experience. What is the most appropriate solution to achieve this cross-tenant access?Implement an authentication and access management solution
- 33.A security administrator is reviewing sign-in logs in Azure AD and notices a significant number of failed sign-in attempts from unusual locations for several user accounts. These accounts do not have any Conditional Access policies applied. The administrator wants to automatically detect and respond to these risky sign-in attempts by requiring MFA or blocking access when high risk is detected. Which Azure AD feature should the administrator configure?Implement an authentication and access management solution
- 34.A global company with multiple subsidiaries, each operating as a separate Azure AD tenant, wants to simplify resource sharing and collaboration. They need a solution that allows users from one subsidiary to seamlessly access applications and resources in another subsidiary's tenant without requiring separate guest invitations or re-authentication. All tenants are part of the same parent organization. Which Azure AD feature is designed for this specific scenario?Implement an authentication and access management solution
- 35.A company is developing a new multi-tenant SaaS application that will be used by customers from various Azure AD tenants. The application needs to securely access Microsoft Graph API on behalf of the signed-in user to read their profile information. What permission type should the application request from Azure AD?Implement an authentication and access management solution
- 36.A company uses Azure Active Directory (Azure AD) and has implemented several Conditional Access policies. One specific policy is configured to require multi-factor authentication (MFA) for all users accessing cloud apps, but it excludes users from a trusted IP range. Another policy requires compliant devices for users accessing a specific finance application. A user attempts to access the finance application from a non-compliant device, but they are within the trusted IP range. Which action will Azure AD take?Implement an authentication and access management solution
- 37.A security architect is designing an access management solution for a new internal web application. The application will be accessed by employees using various devices, including corporate-managed laptops and personal mobile phones. The architect needs to ensure that access to the application from corporate-managed devices requires only a single sign-on (SSO) experience, while access from personal mobile phones requires MFA and is restricted to specific trusted network locations. Which combination of Azure AD features should the architect implement?Implement an authentication and access management solution
- 38.A global company is deploying a new web application that needs to authenticate users from multiple Azure Active Directory (Azure AD) tenants, including external partners. The application is registered in the company's home tenant. What type of user account should be used to allow users from external Azure AD tenants to access this application?Implement an authentication and access management solution
- 39.A company employs a large number of contractors who require access to various applications and resources for limited durations. The company uses Microsoft Entra ID for identity management and has implemented entitlement management. They aim to streamline the onboarding and offboarding process for these contractors. Which type of connected organization should be configured in entitlement management to simplify the process of granting access to contractors who use Microsoft accounts (e.g., Outlook.com, Hotmail.com) and do not belong to another Microsoft Entra organization?Implement access governance
- 40.A large pharmaceutical company uses Microsoft Entra ID and has delegated the management of several Microsoft 365 groups to department heads. These groups grant access to sensitive project files. The security team wants to implement access reviews for these groups, but they want the department heads to be responsible for reviewing their own group members' access, not a central IT team. Additionally, if the department head fails to review a member's access, that member's access should automatically be removed. Which access review settings should be configured?Implement access governance
- 41.A company uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They want to ensure that all 'User Administrator' role assignments are subject to a regular review process to confirm that assigned users still require the role. The review should occur every 90 days. Which PIM setting for the 'User Administrator' role needs to be configured to meet this requirement?Implement access governance
- 42.A consulting firm uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They have a policy that consultants should have eligible assignments to highly privileged roles like 'User Access Administrator' for a maximum of 6 months. After this period, their eligibility should automatically expire. Which PIM setting should be configured to enforce this policy?Implement access governance
- 43.A company uses Microsoft Entra ID to manage its identities. They have a critical group called 'Global Admins' that includes several highly privileged accounts. The security team wants to ensure that these accounts are only used when absolutely necessary and that their usage is audited. They need a solution that can automatically remove permanent administrator assignments and require users to activate their roles with multi-factor authentication (MFA) before use. Which Microsoft Entra ID feature should the company implement to achieve this goal?Implement access governance
- 44.A global company uses Microsoft Entra ID and has several business units, each operating as a distinct legal entity with its own Microsoft Entra tenant. They want to enable seamless collaboration by allowing users from one business unit to request access to applications and resources owned by another business unit's tenant, all managed through entitlement management. The solution must support self-service access requests and automatic de-provisioning. Which type of connected organization should the company configure in each tenant to enable this cross-tenant collaboration?Implement access governance
- 45.A consulting firm provides services to multiple clients and needs to grant their consultants temporary access to client-specific applications in Microsoft Entra ID. The firm wants to ensure that when a consultant is assigned an eligible role in PIM for a client's tenant, this assignment automatically expires after a maximum of 90 days, and the consultant must re-request eligibility if they still need it. Which PIM setting for the role should be configured?Implement access governance
- 46.A software development company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure resources. They have a policy that developers should only be able to activate certain highly sensitive roles, such as 'User Access Administrator' for a maximum of 4 hours at a time. After this period, the role should automatically deactivate. Which PIM setting should be configured for these roles?Implement access governance
- 47.A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management. They need to ensure that when a user requests access to an access package, the request is automatically approved if the user's manager also approves it. The manager's approval should be the only required approval step. Which setting within the entitlement management access package policy should be configured to achieve this?Implement access governance
- 48.A global consulting firm uses Microsoft Entra ID and has a policy that all highly privileged roles, such as 'User Administrator' and 'Application Administrator', must be assigned as 'eligible' in PIM. However, they also need to ensure that a backup break-glass account for each of these roles is always 'permanently active' to handle emergencies, even if the PIM service is temporarily unavailable. Which assignment type in PIM should be used for these specific break-glass accounts?Implement access governance
- 49.A consulting firm uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a critical 'Global Administrator' role that requires a multi-stage approval process before activation. The first stage of approval must be by a Security Administrator, and the second stage must be by a designated senior manager. How would you configure this multi-stage approval in PIM?Implement access governance
- 50.A defense contractor uses Microsoft Entra ID and has mandated that all 'Security Administrator' role activations must be approved by two separate individuals: first by the user's direct manager, and then by a member of the 'Security Operations' group. Both approvals are mandatory. Which PIM setting should be configured to achieve this multi-stage approval workflow?Implement access governance