Microsoft Certified: Identity and Access Administrator Associate practice questions

207 free questions with answers and explanations.

Practice test
  1. 101.An organization uses Azure AD for identity management. A new SaaS application, 'DocuSign', needs to be integrated with Azure AD for single sign-on (SSO) and user provisioning. The application is already pre-integrated by Microsoft and supports SAML-based SSO. Which type of workload identity object should be configured in Azure AD to facilitate this integration?Implement and manage workload identities
  2. 102.A company is deploying Azure AD Connect to synchronize user accounts from an on-premises Active Directory forest to Azure AD. They have a specific requirement to exclude a particular Organizational Unit (OU) containing service accounts from being synchronized to Azure AD. Which synchronization filtering method should be used to achieve this exclusion?Implement an identity management solution
  3. 103.A company uses Azure AD for all its cloud applications. They have recently implemented Azure AD Identity Protection and configured a 'User risk policy' to block users with a 'High' risk level. A user, John Doe, frequently travels internationally and uses a VPN. His sign-ins are often flagged as 'Anomalous sign-in location' and 'Unfamiliar sign-in properties' which contribute to a 'Medium' user risk score. However, a single sign-in from a known anonymous IP address has just increased his user risk score to 'High'. What will be the immediate impact on John Doe's access attempts based on the configured policy?Implement an identity management solution
  4. 104.A company is implementing Azure AD Identity Protection. They have configured a policy to require multi-factor authentication (MFA) for users with a 'High' risk level. A user, User1, consistently signs in from unusual locations and devices, triggering a 'High' risk level. However, User1 is a critical executive and cannot tolerate MFA prompts due to an existing accessibility issue. The security team needs to ensure User1 can still sign in without MFA, even with a 'High' risk, while keeping the policy active for all other high-risk users. What is the most appropriate way to achieve this?Implement an identity management solution
  5. 105.A company is integrating a new Human Resources (HR) system with Azure AD. They need to automate the creation, update, and deletion of user accounts in Azure AD based on changes in the HR system. This integration should also ensure that user attributes like department and job title are consistently synchronized. Which Azure AD feature is best suited for this requirement?Implement an identity management solution
  6. 106.A company uses Azure AD for identity management. They have several guest users from partner organizations who need access to specific applications. The security team wants to ensure that these guest users are automatically removed from Azure AD after 90 days of inactivity. Which feature should be configured to achieve this?Implement an identity management solution
  7. 107.A company is integrating a new SaaS application with Azure AD for single sign-on (SSO). They also need to automate the creation, updating, and deletion of user accounts in the SaaS application based on changes in Azure AD group memberships. Which Azure AD feature, utilizing the SCIM protocol, should be configured to achieve this automated provisioning?Implement an identity management solution
  8. 108.A developer is creating an Azure Function that needs to authenticate to Microsoft Graph to read user profiles (User.Read.All). The function will run without a signed-in user (i.e., as a daemon process). The security team requires that the application only be granted application permissions, not delegated permissions. Which type of permission should the developer request in the Azure AD application registration?Implement and manage workload identities
  9. 109.A company wants to ensure that all guest user accounts in their Azure AD tenant are regularly reviewed to confirm their continued need for access. They need to automate this review process and involve the guest users' sponsors in the approval decisions. Which Azure AD Identity Governance feature should be used?Implement an identity management solution
  10. 110.A global company has multiple on-premises Active Directory forests (Forest A, Forest B, Forest C) with non-routable UPN suffixes. They want to consolidate identity management by synchronizing all user accounts from these forests into a single Azure AD tenant. Users must be able to sign in to Azure AD with their on-premises credentials. What is the minimum number of Azure AD Connect servers required to achieve this, assuming high availability is not a primary concern for the initial setup?Implement an identity management solution
  11. 111.A small business is setting up Azure AD for the first time. They want to ensure that all users have a baseline level of security enabled without requiring extensive configuration or licensing beyond Azure AD Free. They need to enforce MFA for administrative roles, block legacy authentication protocols, and require MFA for all users when they are deemed risky. Which Azure AD feature provides this out-of-the-box protection?Implement an identity management solution
  12. 112.A company uses Azure AD as its primary identity provider. They need to ensure that all users, including guest users, are prompted for multi-factor authentication (MFA) when accessing sensitive applications, regardless of their location or device. What is the most efficient way to achieve this requirement?Implement an identity management solution
  13. 113.A new Azure Function App is deployed to host several serverless functions. These functions need to authenticate to Azure Key Vault to retrieve connection strings and API keys. The security team mandates that the authentication mechanism must not rely on any secrets stored in environment variables or code. Additionally, the functions should inherit permissions based on their hosting environment. Which identity configuration should you recommend for the Azure Function App?Implement and manage workload identities
  14. 114.A company has a hybrid identity environment with Azure AD Connect synchronizing users from an on-premises Active Directory. They observe that some users who are members of a specific security group in on-premises AD are not having their group memberships synchronized to Azure AD. All other user attributes and group memberships appear to synchronize correctly. What is the most likely reason for this issue?Implement an identity management solution
  15. 115.A company is implementing Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password hashes are securely synchronized to Azure AD while also allowing users to sign in with their existing on-premises credentials. Which authentication method should be configured in Azure AD Connect to meet these requirements?Implement an identity management solution
  16. 116.A company is planning to deploy Azure AD Connect for synchronizing user accounts from their on-premises Active Directory to Azure AD. They want to ensure that only users from specific departments, such as 'Sales' and 'Marketing', are synchronized, while all other users remain only in the on-premises directory. Which synchronization filtering method should they implement?Implement an identity management solution
  17. 117.A company has implemented Azure AD Identity Protection and configured a policy to block sign-ins from 'Anonymous IP addresses'. Recently, legitimate users have reported being blocked when signing in from public Wi-Fi networks that utilize VPNs or proxies, which are sometimes flagged as anonymous. The security team wants to allow these legitimate sign-ins while still protecting against truly anonymous or malicious sources. What is the most effective adjustment to the policy?Implement an identity management solution
  18. 118.A company uses a third-party CI/CD pipeline, hosted outside of Azure, to deploy application updates to Azure Kubernetes Service (AKS). The pipeline needs to authenticate to Azure AD to obtain tokens to manage AKS resources. The security team wants to avoid storing any long-lived Azure credentials (like client secrets) in the CI/CD system. Which feature should you implement?Implement and manage workload identities
  19. 119.A company is preparing to deploy Azure AD Connect to synchronize user accounts from their on-premises Active Directory. They have a requirement to ensure that only user accounts located in specific Organizational Units (OUs) are synchronized to Azure AD, as other OUs contain service accounts and disabled user accounts that should not be synced. What is the most efficient way to achieve this during the Azure AD Connect installation?Implement an identity management solution
  20. 120.A company is implementing a new application that will be hosted in Azure. This application needs to securely access Azure Key Vault to retrieve secrets and Azure SQL Database to store data. The security team requires that the application authenticates to these Azure services using its own identity, without requiring hardcoded credentials or secrets to be stored within the application's code or configuration. Which type of managed identity should be assigned to the application?Implement an identity management solution
  21. 121.A company is migrating its applications to Azure. Some legacy applications require LDAP authentication and rely on Kerberos for single sign-on within a domain. These applications are being containerized and deployed to Azure Kubernetes Service (AKS). The company wants to leverage Azure AD identities for these applications without deploying and managing traditional domain controllers in Azure VMs. Which Azure service should be implemented?Implement an identity management solution
  22. 122.A company is migrating several on-premises applications to Azure. These applications currently use service accounts for authentication. You need to create an equivalent secure identity in Azure AD for these applications that requires explicit credential management and rotation. Which object type should you provision in Azure AD?Implement and manage workload identities
  23. 123.A company is developing a multi-tenant SaaS application that will run in Azure. Customers will use their own Azure AD tenants to authenticate to the application. You need to configure the application in Azure AD to allow customers from different tenants to sign in. Which property must be configured when registering the application?Implement and manage workload identities
  24. 124.A company is setting up Azure AD Connect with Password Hash Synchronization (PHS). During the initial synchronization, they observe that some user accounts are not synchronizing from on-premises Active Directory to Azure AD. Upon investigation, they find that the `userPrincipalName` attribute for these users is missing or improperly formatted in the on-premises AD. What is the most likely reason for these accounts failing to synchronize with PHS?Implement an identity management solution
  25. 125.A company is using Azure AD Connect to synchronize user accounts from their on-premises Active Directory. They want to ensure that if a user's password is changed on-premises, it is immediately reflected in Azure AD, allowing cloud applications to use the new password without delay. Which synchronization feature should be enabled and configured?Implement an identity management solution
  26. 126.A company is integrating a new SaaS application with Azure AD for single sign-on (SSO). The application supports SAML 2.0 for authentication. The company wants to ensure that users are automatically provisioned and deprovisioned in the SaaS application based on their group membership in Azure AD. Which Azure AD feature should be configured to automate this user lifecycle management?Implement an identity management solution
  27. 127.A company is planning to deploy Azure AD Connect to synchronize their on-premises Active Directory with Azure AD. They want to implement Pass-through Authentication (PTA) to ensure that users authenticate against their on-premises domain controllers, but they also need to maintain authentication availability even if the on-premises domain controllers or network connectivity to them is temporarily unavailable. What specific component or configuration is essential to meet the high availability requirement for PTA?Implement an identity management solution
  28. 128.A small startup is implementing Azure AD for their cloud-only environment. They want to ensure a baseline level of security for all user accounts without requiring extensive configuration or licensing beyond the free Azure AD tier. They are particularly concerned about protecting against common identity attacks and ensuring all users register for multi-factor authentication (MFA). Which feature should they enable?Implement an identity management solution
  29. 129.A company is migrating its applications to Azure. Some legacy applications require LDAP authentication against on-premises Active Directory. The company wants to extend its on-premises AD to Azure to support these applications without deploying domain controllers in Azure IaaS VMs. Which Azure AD service should be used to provide LDAP authentication for Azure-hosted applications against a managed domain controller equivalent?Implement an identity management solution
  30. 130.A company is onboarding a large number of external contractors who need temporary access to specific applications and data in their Azure AD tenant. These contractors use their own existing identities from various email providers (e.g., Gmail, Outlook.com). The company wants to streamline the invitation process and allow contractors to use their existing credentials without creating new accounts in the company's Azure AD. Which feature should be implemented?Implement an identity management solution
  31. 131.A company is migrating its on-premises applications to Azure. Many of these applications rely on Lightweight Directory Access Protocol (LDAP) for authentication and cannot be easily re-architected to use modern authentication protocols. The company needs to minimize changes to these legacy applications while providing secure access in Azure.Implement an identity management solution
  32. 132.A company is using Azure AD Connect to synchronize user accounts from an on-premises Active Directory to Azure AD. They want to prevent specific user accounts, located in a particular Organizational Unit (OU) named 'Contractors', from being synchronized to Azure AD. What is the most efficient way to achieve this?Implement an identity management solution
  33. 133.A company is developing a new application that will run on an Azure Virtual Machine (VM). This application needs to access data stored in an Azure Storage Account. The security team has mandated that no secrets or connection strings should be hardcoded in the application. You need to recommend a secure and efficient way for the application to authenticate to the Azure Storage Account.Implement and manage workload identities
  34. 134.A company is onboarding a large number of external contractors who need temporary access to specific applications in Azure AD. These contractors do not have existing Microsoft accounts or Azure AD accounts. The company wants to streamline the onboarding process by allowing the contractors to use their existing corporate email addresses (e.g., Gmail, Yahoo) to sign in. Which feature allows this type of external identity access?Implement an identity management solution
  35. 135.A company wants to allow external contractors to access specific applications hosted in their Azure AD tenant. These contractors use their existing Google accounts for authentication. The company needs to configure a method that allows these external users to sign in using their Google credentials and access the applications with minimal administrative overhead. Which external identity configuration should be implemented?Implement an identity management solution
  36. 136.An organization is deploying a custom application to an Azure virtual machine (VM). The application needs to authenticate to an Azure SQL Database. The security team insists that the application should not store any credentials (username, password, connection string) directly. The identity solution should be tightly coupled to the VM's lifecycle. Which type of workload identity should be configured?Implement and manage workload identities
  37. 137.A company is implementing a new HR application that requires user provisioning and deprovisioning to be automated based on changes in the company's HR system (Workday). They want to ensure that user accounts are automatically created, updated, and deleted in Azure AD and connected SaaS applications when changes occur in Workday. Which Azure AD feature should be used to integrate Workday with Azure AD for identity provisioning?Implement an identity management solution
  38. 138.A security auditor has identified that an Azure AD application registration used by a critical line-of-business application has a client secret with an expiration date 5 years in the future. The auditor recommends enforcing a maximum secret lifetime of 1 year for all workload identities. Which Azure AD feature should you use to implement this policy for the application registration?Implement and manage workload identities
  39. 139.A company is implementing Azure AD Identity Protection. They have configured a policy to require MFA for all users when a high sign-in risk is detected. However, a specific group of service accounts needs to be excluded from this policy because they are used by automated processes that cannot perform MFA. How should the security administrator configure this exclusion while maintaining the policy for all other users?Implement an identity management solution
  40. 140.An organization uses Azure AD for all user accounts. They want to implement a security policy that requires users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this period, they should be blocked from signing in until MFA registration is complete. Which Azure AD Identity Protection policy can achieve this requirement?Implement an identity management solution
  41. 141.A company is deploying Azure AD Connect to synchronize user accounts from an on-premises Active Directory. They have a complex OU structure and only want to synchronize users located in OUs named 'Sales' and 'Marketing' within a specific domain, 'contoso.com'. Users in other OUs, even within 'contoso.com', or in other domains/forests, should not be synchronized. Which synchronization filtering method should be configured in Azure AD Connect?Implement an identity management solution
  42. 142.A company uses Azure AD for identity management and has implemented Conditional Access policies. They want to ensure that all users accessing highly sensitive applications are prompted for multi-factor authentication (MFA), regardless of their location or device compliance. However, they also want to allow a specific group of service accounts to bypass MFA when accessing these applications from a trusted network location. How should they configure this?Implement an identity management solution
  43. 143.A company is implementing a new security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this period, they should be blocked from signing in until MFA registration is completed. Which Azure AD Identity Protection policy should be configured to enforce this requirement?Implement an identity management solution
  44. 144.An organization is configuring Azure AD Identity Protection and wants to ensure that users who sign in from anonymous IP addresses are always challenged for multi-factor authentication (MFA) and if they fail, their sign-in is blocked. However, they have a legitimate business requirement for a specific service account that must sign in from a known anonymous VPN endpoint for system maintenance. How can they configure the Anonymous IP address sign-in risk policy to accommodate this exception?Implement an identity management solution
  45. 145.A development team is building a new microservices application that will consist of multiple Azure Functions and Azure App Services. All these components need to access a shared Azure Key Vault to retrieve secrets. The team wants a single identity that can be assigned to all these different resources, simplifying management and role assignments. Which type of workload identity should you recommend?Implement and manage workload identities
  46. 146.A company is implementing a new application that will be hosted in Azure. This application needs to securely access data stored in Azure Key Vault. The developers want to avoid embedding credentials in the application code and ensure that the application's identity is managed directly by Azure. Which type of identity should be used for the application?Implement an identity management solution
  47. 147.A security auditor has identified that an Azure AD application registration used by a critical application has a client secret that expires in over two years. The auditor recommends enforcing a maximum client secret lifetime of 180 days for all application registrations. What should you configure in Azure AD to meet this requirement for all *new* and *existing* application registrations?Implement and manage workload identities
  48. 148.A company is using Azure AD Connect with Pass-through Authentication (PTA) to allow users to sign in using their on-premises credentials. To ensure high availability and resilience for authentication, they need to deploy additional PTA agents. How many additional Pass-through Authentication agents should they deploy at a minimum to achieve high availability, assuming they already have one agent running?Implement an identity management solution
  49. 149.A company is implementing a new policy in Azure AD Identity Protection to detect sign-ins from anonymous IP addresses. They want to configure the policy to automatically block any sign-in attempt from an anonymous IP address. However, they are concerned about potential false positives and want to monitor the policy's impact before enforcing it. Which action should they initially configure for the Anonymous IP address sign-in risk policy?Implement an identity management solution
  50. 150.A global manufacturing company with subsidiaries in multiple countries wants to implement Azure AD Connect. Each subsidiary has its own on-premises Active Directory forest, and all forests are independent (no trust relationships). The company needs to synchronize all user accounts from these disparate forests into a single Azure AD tenant. Which Azure AD Connect topology should they use?Implement an identity management solution