Microsoft Certified: Identity and Access Administrator Associate practice questions

207 free questions with answers and explanations.

Practice test
  1. 51.A research institution uses Microsoft Entra ID and has implemented entitlement management. They have a highly sensitive research project that requires access to be granted based on a user's department and job title, and only if they are a full-time employee. Access requests should be automatically approved if these conditions are met, otherwise, they should go through an approval process. Which type of policy configuration should be used to enforce these granular conditions for automatic approval?Implement access governance
  2. 52.A multinational corporation uses Microsoft Entra ID and has delegated the management of specific access packages to departmental managers. These managers need the ability to create new access packages, assign resources, and configure policies for their respective departments, but they should not be able to manage access packages that belong to other departments or modify global entitlement management settings. Which Microsoft Entra role should be assigned to these departmental managers?Implement access governance
  3. 53.A consulting company uses Microsoft Entra ID and has implemented access reviews for several Microsoft 365 groups. These groups are used to grant access to sensitive client data. The company has a strict policy that any access granted through these groups must be re-evaluated every 30 days. Furthermore, they need to ensure that if a group member's manager does not explicitly approve or deny their access during the review period, that member's access is automatically removed. Which two settings must be configured in the access review policy to enforce these requirements?Implement access governance
  4. 54.A healthcare provider uses Microsoft Entra ID and has just completed a major acquisition. They need to integrate the new company's users into their existing access governance framework using entitlement management. The acquired company uses its own separate Microsoft Entra tenant, and its users frequently need access to applications managed by the parent company's entitlement packages. The parent company wants to streamline the process of allowing these external users to request access without manually inviting each user and without requiring the acquired company to switch to the parent company's tenant. Which entitlement management feature should be configured to enable this seamless collaboration?Implement access governance
  5. 55.A global enterprise is implementing a new access governance strategy. They need to ensure that the management of access packages is decentralized to departmental IT teams, but with a global oversight. Each departmental IT team should be able to create and manage their own access packages and policies, but not modify those of other departments. Which entitlement management role should be assigned to the departmental IT leads to grant them these specific permissions?Implement access governance
  6. 56.A company uses Microsoft Entra ID and has implemented access reviews for various groups and applications. The security team wants to ensure that all access reviews are completed on time. They need a mechanism to automatically notify reviewers when a review is due and remind them periodically until the review is completed. Additionally, they want to receive a summary of the review's status. Which access review setting should be configured to meet these notification and reminder requirements?Implement access governance
  7. 57.A global company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They want to ensure that 'Global Administrator' role assignments are always 'eligible' and that these assignments are permanent, meaning they do not expire unless explicitly removed or an access review revokes them. Which PIM setting should be configured for the assignment duration of the Global Administrator role?Implement access governance
  8. 58.A company uses Microsoft Entra ID and has configured Privileged Identity Management (PIM) for its critical Azure resource roles. They want to ensure that if an eligible administrator's account is compromised, the attacker cannot immediately activate a privileged role. The security team needs to enforce that all role activations require an additional layer of verification beyond the usual sign-in credentials. Which PIM setting should be configured for these Azure resource roles to meet this requirement?Implement access governance
  9. 59.A company is implementing a new access governance strategy using Microsoft Entra ID. They have identified several critical applications that require strict control over who can request access. They want to delegate the creation and management of access packages for these applications to specific department heads, ensuring that these department heads can only manage access packages for their own departments' resources and not other departments'. Which Microsoft Entra ID role should be assigned to the department heads to achieve this granular delegation?Implement access governance
  10. 60.A research institution uses Microsoft Entra ID and has implemented entitlement management. They have an access package for research data that contains highly confidential intellectual property. The institution needs to ensure that only full-time employees from the 'Research' department, who also possess a 'Security Clearance: Top Secret' attribute, are eligible to request this access package. Users outside this department or without the specific security clearance should not even see the option to request the package. Which combination of settings in the access package policy will achieve this visibility and eligibility control?Implement access governance
  11. 61.A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management to control access to various resources. They have a critical application that requires highly sensitive data. You need to ensure that specific users can request access to this application, and their requests are automatically approved if they meet certain criteria, without requiring manual intervention from a manager or resource owner. Which entitlement management setting should you configure for the access package policy?Implement access governance
  12. 62.A financial services organization uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. Due to stringent regulatory requirements, all activations of highly privileged roles, such as 'Global Administrator' or 'Privileged Role Administrator', must be digitally signed by the requesting administrator using a certificate-based credential. Which PIM setting, in conjunction with other Microsoft Entra features, would allow this secure activation method?Implement access governance
  13. 63.A large pharmaceutical company uses Microsoft Entra ID and has delegated the management of several Microsoft 365 groups to department heads. These groups grant access to sensitive project files. The security team wants to implement access reviews for these groups, but they want the department heads to be responsible for reviewing their own group members' access, not a central IT team. Additionally, if the department head fails to review a member's access, that member's access should automatically be removed. Which access review settings should be configured?Implement access governance
  14. 64.A software development company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure resources. They have a policy that developers should only be able to activate certain highly sensitive roles, such as 'User Access Administrator' for a maximum of 4 hours at a time. After this period, the role should automatically deactivate. Which PIM setting should be configured for these roles?Implement access governance
  15. 65.A large multinational corporation uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for several Azure AD roles. The security team wants to ensure that all activations of the 'Global Administrator' role are accompanied by a multi-factor authentication (MFA) challenge, even if the user has already satisfied MFA during their initial sign-in to Microsoft Entra ID. This is to provide an additional layer of security for highly privileged actions. Which PIM setting for the 'Global Administrator' role is required to enforce this behavior?Implement access governance
  16. 66.A company uses Microsoft Entra ID to manage its identities. They have a critical group called 'Global Admins' that includes several highly privileged accounts. The security team wants to ensure that these accounts are only used when absolutely necessary and that their usage is audited. They need a solution that can automatically remove permanent administrator assignments and require users to activate their roles with multi-factor authentication (MFA) before use. Which Microsoft Entra ID feature should the company implement to achieve this goal?Implement access governance
  17. 67.A consulting firm provides services to multiple clients and needs to grant their consultants temporary access to client-specific applications in Microsoft Entra ID. The firm wants to ensure that when a consultant is assigned an eligible role in PIM for a client's tenant, this assignment automatically expires after a maximum of 90 days, and the consultant must re-request eligibility if they still need it. Which PIM setting for the role should be configured?Implement access governance
  18. 68.A defense contractor uses Microsoft Entra ID and has mandated that all 'Security Administrator' roles must be assigned as eligible, just-in-time (JIT) roles through PIM. Due to the highly sensitive nature of the data involved, every activation of this role must be approved by at least two separate senior security officers. This approval process must be multi-stage, where one officer approves, and then a second, different officer provides a final approval before the role is activated. Which PIM setting should be configured to achieve this multi-stage approval for 'Security Administrator' role activations?Implement access governance
  19. 69.A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management. They have a business-critical application that requires highly sensitive data access. The security team wants to ensure that access to this application is reviewed by at least two separate managers before it is granted, to minimize the risk of unauthorized access. Which feature in an entitlement management access package policy should be configured to meet this requirement?Implement access governance
  20. 70.A company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management. They need to ensure that when a user requests access to an access package, the request is automatically approved if the user's manager also approves it. The manager's approval should be the only required approval step. Which setting within the entitlement management access package policy should be configured to achieve this?Implement access governance
  21. 71.A global consulting firm uses Microsoft Entra ID and has a policy that all highly privileged roles, such as 'User Administrator' and 'Application Administrator', must be assigned as 'eligible' in PIM. However, they also need to ensure that a backup break-glass account for each of these roles is always 'permanently active' to handle emergencies, even if the PIM service is temporarily unavailable. Which assignment type in PIM should be used for these specific break-glass accounts?Implement access governance
  22. 72.A global company uses Microsoft Entra ID and has several business units, each operating as a distinct legal entity with its own Microsoft Entra tenant. They want to enable seamless collaboration by allowing users from one business unit to request access to applications and resources owned by another business unit's tenant, all managed through entitlement management. The solution must support self-service access requests and automatic de-provisioning. Which type of connected organization should the company configure in each tenant to enable this cross-tenant collaboration?Implement access governance
  23. 73.A consulting firm uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a critical 'Global Administrator' role that requires a multi-stage approval process before activation. The first stage of approval must be by a Security Administrator, and the second stage must be by a designated senior manager. How would you configure this multi-stage approval in PIM?Implement access governance
  24. 74.A consulting firm uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They have a policy that consultants should have eligible assignments to highly privileged roles like 'User Access Administrator' for a maximum of 6 months. After this period, their eligibility should automatically expire. Which PIM setting should be configured to enforce this policy?Implement access governance
  25. 75.A defense contractor uses Microsoft Entra ID and has mandated that all 'Security Administrator' role activations must be approved by two separate individuals: first by the user's direct manager, and then by a member of the 'Security Operations' group. Both approvals are mandatory. Which PIM setting should be configured to achieve this multi-stage approval workflow?Implement access governance
  26. 76.A company uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They want to ensure that all 'User Administrator' role assignments are subject to a regular review process to confirm that assigned users still require the role. The review should occur every 90 days. Which PIM setting for the 'User Administrator' role needs to be configured to meet this requirement?Implement access governance
  27. 77.A software development company uses Microsoft Entra ID and has implemented PIM for its Azure AD roles. The security team observes that 'Global Administrator' role activations frequently exceed the intended duration, leading to prolonged elevated privileges. They want to ensure that once a 'Global Administrator' role is activated, it is automatically deactivated after a strict maximum period of 4 hours, regardless of whether the user remembers to deactivate it manually. Which PIM setting for the 'Global Administrator' role should be configured to enforce this policy?Implement access governance
  28. 78.A company employs a large number of contractors who require access to various applications and resources for limited durations. The company uses Microsoft Entra ID for identity management and has implemented entitlement management. They aim to streamline the onboarding and offboarding process for these contractors. Which type of connected organization should be configured in entitlement management to simplify the process of granting access to contractors who use Microsoft accounts (e.g., Outlook.com, Hotmail.com) and do not belong to another Microsoft Entra organization?Implement access governance
  29. 79.A global company uses Microsoft Entra ID and has implemented entitlement management. They frequently collaborate with external partners who require temporary access to specific applications. These partners manage their own identities in their respective Microsoft Entra tenants. The company wants to streamline the process of granting and revoking access for these external partners. Which feature in entitlement management allows the company to establish trust with partner organizations to automate access for their users?Implement access governance
  30. 80.A software development company uses Microsoft Entra ID and has implemented entitlement management. They have an access package for their 'Developer Tools' which grants access to several critical applications and groups. The company needs to ensure that access to 'Developer Tools' is automatically revoked for users if they lose their 'Developer' attribute in Microsoft Entra ID. Which type of policy setting should be configured within the access package to achieve this?Implement access governance
  31. 81.A company with a hybrid identity environment uses Azure AD Connect for synchronizing user accounts. They recently acquired another company that also has an on-premises Active Directory forest. Both forests need to synchronize users to the same Azure AD tenant. The acquired company's forest uses a different UPN suffix, and there's no trust between the forests. How should the company configure Azure AD Connect to support this scenario?Implement an identity management solution
  32. 82.A small business is setting up Azure AD for the first time. They want to ensure that all users are prompted to set up security info (MFA methods) when they first sign in to any Azure AD-integrated application. This should be a mandatory, one-time setup for all users. Which feature should be enabled?Implement an identity management solution
  33. 83.A company uses a third-party CI/CD pipeline running outside of Azure to deploy applications to Azure App Services. The CI/CD pipeline needs to authenticate to Azure AD to obtain tokens for deploying code and managing App Service configurations. You want to implement a solution that allows the external CI/CD system to authenticate without storing long-lived secrets in its configuration. Which Azure AD feature should you use?Implement and manage workload identities
  34. 84.A company has implemented Azure AD Identity Protection and configured a policy to block sign-ins when an anonymous IP address is detected. They observe that some legitimate users are being blocked when connecting from certain public Wi-Fi networks or VPN services that are misidentified as anonymous. The security team wants to allow these specific legitimate sources while still blocking truly anonymous (e.g., Tor exit nodes) or malicious IP addresses. How should they refine the policy?Implement an identity management solution
  35. 85.A company is developing a multi-tenant SaaS application that will run in Azure. Customers will subscribe to this application, and it needs to access data in each customer's Azure AD tenant (e.g., read user profiles). The application developers need to ensure that customers can easily grant consent for the application to access their tenant's data. Which authentication flow and application registration configuration is required?Implement and manage workload identities
  36. 86.A company is migrating several on-premises applications to Azure. These applications currently use Active Directory service accounts for authentication and authorization. After migration, they will run on Azure Virtual Machines and need to authenticate to various Azure AD-protected resources, including Azure SQL Database and Azure Key Vault. The security team wants to define specific permissions for each application that aligns with its least privilege requirements. Which type of workload identity object should be created for each application?Implement and manage workload identities
  37. 87.A company is implementing a security policy that mandates all workload identities must have their credentials rotated automatically every 90 days. This applies to both system-assigned and user-assigned managed identities. What is the primary mechanism Azure uses to ensure the automatic rotation of credentials for managed identities?Implement and manage workload identities
  38. 88.A global manufacturing company with subsidiaries in multiple countries wants to implement a hybrid identity solution using Azure AD Connect. Each subsidiary has its own on-premises Active Directory forest, and these forests are not mutually trusted. The company needs to synchronize user identities from all these forests into a single Azure AD tenant. What is the minimum number of Azure AD Connect servers required to achieve this configuration?Implement an identity management solution
  39. 89.A company is implementing Azure AD Identity Protection. They have configured a user risk policy set to 'Medium' and a sign-in risk policy set to 'High'. Both policies are configured to block access. A user attempts to sign in, and Identity Protection detects both a 'Medium' user risk and a 'Medium' sign-in risk for this specific attempt. What will be the outcome for this sign-in attempt?Implement an identity management solution
  40. 90.An organization is deploying a custom application to an Azure virtual machine (VM). The application needs to query Azure AD for user information. You want to ensure that the application can authenticate to Azure AD with the least amount of administrative overhead and without requiring manual credential updates. Which type of Managed Identity should you configure for the VM?Implement and manage workload identities
  41. 91.An organization uses Azure AD for identity management. A new SaaS application, 'DocuSign', needs to be integrated with Azure AD for single sign-on (SSO). The application supports SAML 2.0. You need to configure the necessary workload identity in Azure AD to enable SSO for DocuSign users. Which type of object should you provision for the DocuSign application in Azure AD?Implement and manage workload identities
  42. 92.A global consulting firm uses Azure AD as its primary identity provider. They frequently collaborate with external contractors and partners who need temporary access to specific applications. The firm wants to streamline the invitation process for these external users, allow them to use their existing corporate or social identities, and ensure they only see the applications explicitly shared with them. Which Azure AD feature is best suited for this scenario?Implement an identity management solution
  43. 93.A company is implementing Azure AD for their cloud-only environment. They want to ensure a baseline level of security for all users, including requiring MFA for administrative roles, blocking legacy authentication, and requiring MFA for all users for most sign-ins. They need a simple, pre-configured solution that can be enabled quickly without extensive policy configuration. Which feature should they enable?Implement an identity management solution
  44. 94.A company is implementing a new policy to ensure that all guest users invited via Azure AD B2B collaboration have their access reviewed every 90 days. They want to automate this process to ensure compliance and reduce manual overhead. Which Azure AD feature should they use to achieve this?Implement an identity management solution
  45. 95.A developer is creating an Azure Function that needs to authenticate to Microsoft Graph to retrieve group membership information. The security team insists that the Azure Function should use the OAuth 2.0 client credentials flow to authenticate as itself, without a user context. Which type of permission should be granted to the Azure Function's identity?Implement and manage workload identities
  46. 96.A company is implementing a security policy that mandates all workload identities must have their credentials rotated automatically every 90 days. You have several Azure Web Apps that use Managed Identities to access Azure Storage. How can you ensure these Web Apps comply with the credential rotation policy?Implement and manage workload identities
  47. 97.A company is migrating several legacy applications to Azure. These applications require integrated Windows authentication using Kerberos and LDAP for directory lookups. The company does not want to deploy and manage domain controllers in Azure. Which Azure AD service should they implement to support these legacy application requirements?Implement an identity management solution
  48. 98.A company is implementing Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They want to ensure that user passwords synchronized to Azure AD are not stored in a readable format in the cloud and that a user's password change on-premises is immediately reflected in Azure AD. Which authentication method should they choose during the Azure AD Connect configuration to meet these requirements?Implement an identity management solution
  49. 99.A new Azure Function App is deployed to host several serverless functions. These functions need to authenticate to Azure Key Vault to retrieve database connection strings and also write logs to an Azure Storage Account. The functions are deployed as part of a single Function App resource. You need to configure the most secure and manageable identity solution for this scenario.Implement and manage workload identities
  50. 100.A company is implementing a new Azure-hosted application that needs to securely retrieve secrets from Azure Key Vault without storing any credentials in the application's code or configuration files. The application's lifecycle is tied to a specific Azure App Service instance. Which type of identity should be used for this application?Implement an identity management solution