Microsoft Certified: Identity and Access Administrator Associate practice questions
207 free questions with answers and explanations.
- 201.A consulting firm uses Microsoft Entra ID and has implemented PIM for its Azure AD roles. They have a policy that consultants assigned to the 'Global Reader' role should only have eligible assignments for a maximum of 30 days. After this period, their eligibility should automatically expire, requiring a new request if access is still needed. Which PIM setting should be configured to enforce this policy?Implement access governance
- 202.A company is migrating several legacy on-premises applications to Azure. These applications currently rely on service accounts stored in on-premises Active Directory for authentication to various resources. The security team wants to move away from storing credentials in code or configuration files in Azure. They also require that the identities used by these applications are automatically managed by Azure and tied to the lifecycle of the application's hosting resource. Which identity solution should be implemented for these applications?Implement an authentication and access management solution
- 203.A large enterprise with multiple subsidiary companies, each with its own Azure AD tenant, is implementing a new cross-company collaboration portal. Users from any subsidiary should be able to authenticate to the portal and access shared resources located in the main corporate tenant using their existing credentials from their respective home tenants. The solution must support seamless collaboration and centralized management of access policies. Which Azure AD feature is best suited for establishing this trust relationship?Implement an authentication and access management solution
- 204.A global manufacturing company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a critical role, 'Global Admin', which requires an additional layer of security before activation. Specifically, any activation of the 'Global Admin' role must be approved by at least two designated security managers. This approval should happen even if the requesting user is already eligible for the role. Which PIM setting should be configured to enforce this requirement?Implement access governance
- 205.A company with an existing on-premises Active Directory environment plans to migrate some applications to Azure. These applications are critical and require seamless single sign-on (SSO) and LDAP authentication against the same user accounts stored in their on-premises Active Directory. The company wants to avoid deploying and managing domain controllers in Azure IaaS virtual machines. Which Azure AD feature should be implemented to meet these requirements?Implement an identity management solution
- 206.A retail company uses Microsoft Entra ID and has implemented entitlement management. They have an access package for their 'Marketing Team Resources' which includes access to several SharePoint sites and an internal application. The company wants to ensure that members of the Marketing Team automatically lose access to these resources if they leave the 'Marketing Team' Microsoft Entra security group. Which entitlement management lifecycle setting should be configured to achieve this?Implement access governance
- 207.A large manufacturing company uses Azure Active Directory (Azure AD) and has several line-of-business (LOB) applications. One critical LOB application, 'Production Control', manages sensitive operational data. The company needs to implement a Conditional Access policy that requires users to use a compliant device AND be within a specific IP range to access the Production Control application. Users accessing from outside this IP range, even with a compliant device, should be blocked. Which two conditions should be configured in the Conditional Access policy to meet these requirements? (Choose two.)Implement an authentication and access management solution