1. A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity model using Azure AD Connect. They have a strict security requirement that user password hashes must NEVER be synchronized to Azure AD. However, users must still be able to sign in to both on-premises and cloud applications using the same credentials. Which authentication method should the client configure in Azure AD Connect?
Implement an authentication and access management solution
A.Password Hash Synchronization (PHS)
B.Federation with AD FS
C.Cloud-only authentication
D.Pass-through Authentication (PTA)
Show answerAnswer
B. Federation with AD FS
Federation with AD FS keeps all authentication requests on-premises, meaning no password hashes (or even the passwords themselves) ever leave the on-premises environment. Azure AD redirects authentication requests to AD FS, which validates against the local AD DS.
2. A security administrator is reviewing sign-in logs in Azure AD and notices a significant number of failed sign-in attempts originating from unusual geographic locations for several user accounts. Some of these accounts also show signs of suspicious activity, such as sign-ins from infected devices. The administrator wants to automatically detect and respond to these types of risks. Which Azure AD feature should be configured?
Implement an authentication and access management solution
A.Azure AD Audit Logs
B.Azure AD PIM
C.Azure AD Conditional Access policies
D.Azure AD Identity Protection
Show answerAnswer
D. Azure AD Identity Protection
Azure AD Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses machine learning to identify suspicious activities like sign-ins from unusual locations or infected devices and can automatically apply Conditional Access policies based on risk levels.
3. A company is migrating its infrastructure to Azure and wants to ensure that Virtual Machines (VMs) can securely access Azure Key Vault to retrieve secrets without requiring hard-coded credentials. The solution must follow the principle of least privilege. What is the most appropriate method to achieve this?
Implement an authentication and access management solution
A.Create a shared access signature (SAS) for the Key Vault and embed it in the VM's startup script.
B.Assign a system-assigned managed identity to the VM and grant it 'Get' and 'List' permissions on the Key Vault secrets.
C.Store Key Vault credentials as environment variables on the VM and configure the application to use them.
D.Create a service principal for the VM, generate a client secret, and store it securely on the VM for Key Vault access.
Show answerAnswer
B. Assign a system-assigned managed identity to the VM and grant it 'Get' and 'List' permissions on the Key Vault secrets.
Managed identities for Azure resources, specifically system-assigned managed identities, provide an identity for Azure services in Azure AD. This allows VMs to authenticate to services like Key Vault without managing credentials. Granting 'Get' and 'List' permissions follows the principle of least privilege for retrieving secrets.
4. A company is implementing a new application that will be hosted on Azure App Service. This application needs to securely access data stored in Azure Key Vault without storing credentials in its code or configuration files. The company wants to use a managed identity for this purpose. Which type of managed identity should be assigned to the Azure App Service instance to meet this requirement?
Implement an authentication and access management solution
A.User-assigned managed identity
B.Service principal managed identity
C.Application registration managed identity
D.System-assigned managed identity
Show answerAnswer
D. System-assigned managed identity
A system-assigned managed identity is directly tied to the lifecycle of the Azure resource it's assigned to. When the resource is deleted, the identity is also deleted. This type of identity is automatically created and managed by Azure, making it suitable for a single resource like an Azure App Service requiring secure access to other Azure services.
5. A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity solution with Azure Active Directory (Azure AD). They want to ensure that users continue to authenticate using their existing on-premises credentials for applications integrated with Azure AD, without storing password hashes in Azure AD. Which authentication method should be implemented?
Implement an authentication and access management solution
A.Federation with Active Directory Federation Services (AD FS)
B.Azure AD Kerberos authentication
C.Pass-through Authentication (PTA)
D.Password Hash Synchronization (PHS)
Show answerAnswer
C. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud applications using the same passwords. It achieves this by validating users' passwords directly against their on-premises Active Directory, without storing password hashes in Azure AD.
6. A company uses Azure AD and has implemented Azure AD Privileged Identity Management (PIM) for its critical administrative roles. The security team wants to ensure that all activations of the 'Global Administrator' role require approval from a designated security group, and that the activation period is limited to a maximum of four hours. Which PIM setting should the administrator configure to meet these requirements?
Implement an authentication and access management solution
A.Azure AD roles
B.Assignment settings
C.Role settings
D.Members settings
Show answerAnswer
C. Role settings
PIM 'Role settings' (also known as 'Assignment settings' in the PIM interface) determine how a role can be activated, including requirements for approval, multi-factor authentication, justification, and the maximum activation duration. Configuring these settings for the 'Global Administrator' role will enforce the approval and time limit requirements.
7. A company uses Azure Active Directory (Azure AD) and has implemented Conditional Access policies. A new policy is being designed to require multifactor authentication (MFA) for all users accessing sensitive applications, but only when they are outside a trusted network location. How should this Conditional Access policy be configured?
Implement an authentication and access management solution
A.Set 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' including trusted locations, and 'Grant' to 'Block access'.
B.Set 'Users and groups' to 'All users', 'Cloud apps or actions' to 'All cloud apps', 'Conditions' to 'Locations' including trusted locations, and 'Grant' to 'Require multifactor authentication'.
C.Set 'Users and groups' to 'Selected users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Device platforms' for all platforms, and 'Grant' to 'Require multifactor authentication'.
D.Set 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' excluding trusted locations, and 'Grant' to 'Require multifactor authentication'.
Show answerAnswer
D. Set 'Users and groups' to 'All users', 'Cloud apps or actions' to 'Selected apps', 'Conditions' to 'Locations' excluding trusted locations, and 'Grant' to 'Require multifactor authentication'.
To meet the requirements, the policy must target all users and the sensitive applications. The key condition is to apply MFA *only when outside a trusted network*, which is achieved by configuring 'Locations' to 'Exclude' the defined trusted locations. Finally, the 'Grant' control must be set to 'Require multifactor authentication'.
8. A global company uses Azure AD and has deployed a new application that uses the OpenID Connect protocol for authentication. The application requires specific custom attributes from the user's profile, such as 'DepartmentID' and 'CostCenter', to be included in the ID token. How can these attributes be added to the ID token?
Implement an authentication and access management solution
A.Create an application role in the application's manifest.
B.Use Microsoft Graph API to retrieve the attributes post-authentication.
C.Configure a custom security attribute in Azure AD.
D.Configure optional claims in the application's manifest.
Show answerAnswer
D. Configure optional claims in the application's manifest.
Azure AD optional claims allow you to add standard or custom attributes to tokens issued by Azure AD. By configuring optional claims in the application's manifest, you can specify 'DepartmentID' and 'CostCenter' to be included directly in the ID token for OpenID Connect applications.
9. A developer is building a multi-tenant SaaS application that needs to access Microsoft Graph API on behalf of signed-in users. The application requires permissions to read user profiles and send emails. To ensure the principle of least privilege, the developer wants to request only the necessary permissions. Which type of permission should the developer request for this scenario?
Implement an authentication and access management solution
A.Delegated permissions
B.Effective permissions
C.Admin consent permissions
D.Application permissions
Show answerAnswer
A. Delegated permissions
Delegated permissions are used when an application acts on behalf of a signed-in user. The application will have access to what the user has access to, limited by the permissions granted to the application. This aligns with the requirement for the SaaS application to access Microsoft Graph API 'on behalf of signed-in users' for tasks like reading profiles and sending emails.
10. A security architect is designing an authentication solution for a new internal web application. The application will be accessed by employees only, and all employees are managed in Azure AD. The architect wants to implement a solution where users are automatically signed in when they access the application from a corporate-joined device within the corporate network, without explicitly entering credentials. If they access from outside the corporate network or from a non-corporate device, they should be prompted for MFA. Which combination of Azure AD features should the architect recommend?
Implement an authentication and access management solution
B. Pass-through Authentication (PTA) + Seamless SSO + Conditional Access
Pass-through Authentication (PTA) allows users to sign in to Azure AD using their on-premises passwords, which are validated directly against on-premises Active Directory. When combined with Seamless SSO, it provides a truly seamless experience for corporate-joined devices within the corporate network. Conditional Access can then be used to enforce MFA for users accessing from outside the corporate network or non-corporate devices. PHS + Seamless SSO would also work, but PTA is often preferred for organizations that want to keep authentication entirely on-premises while avoiding AD FS complexity.
11. A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without storing any credentials in the application code or configuration files. Which type of managed identity should the developer configure for the Azure VM?
Implement an authentication and access management solution
A.User-assigned managed identity
B.System-assigned managed identity
C.Application registration with client secret
D.Service principal with certificate
Show answerAnswer
B. System-assigned managed identity
A system-assigned managed identity is automatically created and managed by Azure for a specific Azure resource (like a VM). It has a lifecycle tied to that resource and is ideal for scenarios where a single resource needs to authenticate to other Azure services without manual credential management.
12. A global company is integrating a critical line-of-business application with Azure AD. The application requires highly granular authorization based on custom user attributes that are specific to the company's business processes (e.g., 'ProjectRole', 'SecurityClearanceLevel'). These attributes are not standard Azure AD properties. The company wants to use Conditional Access policies to enforce access based on these custom attributes. How can these custom attributes be integrated with Azure AD Conditional Access?
Implement an authentication and access management solution
A.By creating custom claims in the application registration's optionalClaims and using them in Conditional Access.
B.By defining custom security attributes in Azure AD and using them in Conditional Access policy conditions.
C.By using application roles in the application manifest and assigning users to these roles.
D.By extending the Azure AD schema and synchronizing attributes from on-premises AD.
Show answerAnswer
B. By defining custom security attributes in Azure AD and using them in Conditional Access policy conditions.
Custom security attributes in Azure AD are designed precisely for this scenario. They allow organizations to define their own business-specific attributes in Azure AD and then use them in Conditional Access policies, as well as for other purposes like access control and filtering. This directly addresses the need for highly granular authorization based on custom user attributes.
13. A security administrator is reviewing user sign-in logs in Azure AD and notices several failed sign-in attempts for a specific user account originating from unusual geographic locations. The administrator suspects a potential brute-force attack or credential compromise. Which Azure AD feature provides automated protection against such threats by analyzing sign-in behavior and applying remediation actions?
Implement an authentication and access management solution
A.Access Reviews
B.Custom security attributes
C.Identity Protection
D.PIM (Privileged Identity Management)
Show answerAnswer
C. Identity Protection
Azure AD Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses machine learning to analyze sign-in behavior and user activity, identifying suspicious actions like sign-ins from unfamiliar locations or impossible travel, and can automatically block or require MFA for risky sign-ins.
14. A company is integrating a custom-developed web application with Azure AD for single sign-on (SSO) using OpenID Connect. The application requires two specific custom attributes, 'EmployeeID' and 'ProjectRole', to be present in the user's ID token upon successful authentication. These attributes are stored as extension attributes in Azure AD. How should the administrator configure Azure AD to include these attributes in the ID token?
Implement an authentication and access management solution
A.Configure Optional Claims in the application registration to include the extension attributes.
B.Define new application roles in the application manifest for 'EmployeeID' and 'ProjectRole'.
C.Create custom security attributes for 'EmployeeID' and 'ProjectRole' and assign them to users.
D.Use a Claims Mapping Policy to transform existing claims into 'EmployeeID' and 'ProjectRole'.
Show answerAnswer
A. Configure Optional Claims in the application registration to include the extension attributes.
Azure AD Optional Claims allow you to include standard or extension attributes (like custom extension attributes) in tokens. By configuring optional claims in the application registration, 'EmployeeID' and 'ProjectRole' can be directly added to the ID token for OpenID Connect applications.
15. A large enterprise with multiple subsidiary companies, each with its own Azure AD tenant, needs to collaborate efficiently. Users from one subsidiary must be able to seamlessly access applications hosted in another subsidiary's tenant, and administrators need a simplified way to manage cross-tenant access without individual B2B invitations. Which Azure AD feature is designed to address this scenario?
Implement an authentication and access management solution
A.Azure AD Guest User Management
B.Azure AD B2C
C.Azure AD B2B Collaboration
D.Azure AD Multi-tenant Organization (MTO)
Show answerAnswer
D. Azure AD Multi-tenant Organization (MTO)
Azure AD Multi-tenant Organization (MTO) is specifically designed for scenarios where multiple Azure AD tenants belonging to the same organization need to collaborate seamlessly. It provides a more streamlined and scalable approach to cross-tenant access and management compared to individual B2B invitations.
16. A company is configuring an Azure AD Conditional Access policy to enforce multi-factor authentication (MFA) for all users accessing a specific sensitive application. The company wants to ensure that users who are already MFA-compliant from their trusted corporate network are not prompted again. Which condition should be configured in the Conditional Access policy to achieve this goal?
Implement an authentication and access management solution
A.Client apps
B.Filter for devices
C.Sign-in risk
D.Locations
Show answerAnswer
D. Locations
The 'Locations' condition in Conditional Access policies allows administrators to specify trusted IP ranges (named locations). By excluding these named locations from the MFA requirement, users accessing the sensitive application from the trusted corporate network will not be prompted for MFA, fulfilling the company's requirement.
17. A developer is creating an application that needs to retrieve a list of all users in an Azure AD tenant. The application will run as a background service without a signed-in user. To follow the principle of least privilege, the developer wants to grant the minimum necessary permissions. Which Microsoft Graph permission should be assigned to the application's service principal for this task?
Implement an authentication and access management solution
A.User.Read.All
B.User.ReadBasic.All
C.Directory.Read.All
D.User.Read
Show answerAnswer
C. Directory.Read.All
The application runs as a background service without a signed-in user, meaning it requires application permissions. To 'retrieve a list of all users', the most appropriate and least privileged application permission is 'Directory.Read.All'. While 'User.Read.All' is also an application permission that allows reading all user profiles, 'Directory.Read.All' encompasses reading all directory objects, including users, groups, and devices, making it a more comprehensive yet still read-only option for directory-wide information. However, if the question was strictly about *only* users, User.Read.All would be more specific. Given the options and the need to retrieve 'all users', Directory.Read.All is often the permission granted for such scenarios as it covers a broader read scope of the directory, which includes all users.
18. A company is implementing a new application that uses the OAuth 2.0 authorization code flow to obtain access tokens for accessing a protected API. The application is registered in Azure AD. Which of the following is a critical security best practice for handling the client secret in this flow?
Implement an authentication and access management solution
A.Use a certificate instead of a client secret for confidential client applications.
B.Hard-code the client secret into the mobile application's source code for direct API calls.
C.Store the client secret directly in the client-side JavaScript code of the web application.
D.Embed the client secret in the redirect URI when performing the authorization request.
Show answerAnswer
A. Use a certificate instead of a client secret for confidential client applications.
For confidential client applications (like web apps or APIs that can securely store credentials), using a certificate for client authentication is a more secure alternative to client secrets. Certificates are harder to compromise than strings of text, especially if they are managed securely in a Key Vault or by managed identities.
19. A global company is deploying a new web application that needs to authenticate users from multiple Azure Active Directory (Azure AD) tenants, including external partners. The application is registered in the company's home tenant. What type of user account should be used to allow users from external Azure AD tenants to access this application?
Implement an authentication and access management solution
A.Cloud-only users
B.Member users
C.Guest users (B2B collaboration)
D.Synchronized users
Show answerAnswer
C. Guest users (B2B collaboration)
Guest users, facilitated by Azure AD B2B collaboration, are specifically designed for inviting external users from other Azure AD tenants, Microsoft accounts, or social identities to access applications and resources in your tenant. This allows the global company to onboard external partners securely.
20. A company uses Azure AD and has several line-of-business (LOB) applications. One critical application requires that users accessing it must be registered with Microsoft Entra ID and have a specific 'Partner' attribute set to 'True'. The company wants to enforce this condition before users are granted access to the application, without modifying the application code. Which Azure AD feature should be used to achieve this?
Implement an authentication and access management solution
A.External Identities settings
B.Groups and dynamic membership rules
C.Application Proxy
D.Conditional Access policies with custom security attributes
Show answerAnswer
D. Conditional Access policies with custom security attributes
Conditional Access policies, when combined with custom security attributes, provide the exact solution. The 'Partner' attribute can be defined as a custom security attribute in Azure AD, assigned to users, and then a Conditional Access policy can be configured to grant access to the application only if the user's 'Partner' attribute is set to 'True'. This enforcement happens before access is granted and requires no application code changes.
21. A company is planning to implement Azure AD Connect to synchronize identities from its on-premises Active Directory to Azure AD. Due to strict security policies, the company requires that no password hashes are synchronized to Azure AD. However, users must still be able to use their on-premises credentials for single sign-on to cloud applications. Which authentication method should the company choose for Azure AD Connect to satisfy these requirements?
Implement an authentication and access management solution
A.Seamless Single Sign-On (SSO)
B.Pass-through Authentication (PTA)
C.Federation with AD FS
D.Password Hash Synchronization (PHS)
Show answerAnswer
C. Federation with AD FS
Federation with AD FS (Active Directory Federation Services) allows users to authenticate directly against their on-premises Active Directory. Azure AD acts as a relying party, trusting AD FS to authenticate users. This means no password hashes are synchronized to Azure AD, and users authenticate using their existing on-premises credentials, fulfilling both requirements.
22. A global organization uses Azure AD Connect to synchronize user accounts from its on-premises Active Directory to Azure AD. The organization has users located in different geographical regions, and each region has its own set of domain controllers. To ensure high availability and disaster recovery for the synchronization service, what is the recommended deployment strategy for Azure AD Connect?
Implement an authentication and access management solution
A.Deploy a single Azure AD Connect server in the primary datacenter and rely on its built-in redundancy.
B.Deploy multiple Azure AD Connect servers in an active-active configuration across different regions.
C.Deploy a primary Azure AD Connect server and a staging server in separate datacenters.
D.Deploy a single Azure AD Connect server with a redundant power supply and网络 connectivity.
Show answerAnswer
C. Deploy a primary Azure AD Connect server and a staging server in separate datacenters.
Azure AD Connect does not support an active-active configuration. The recommended high availability strategy is to deploy a primary Azure AD Connect server handling synchronization and a secondary (staging) server that is kept up-to-date but not actively synchronizing. In case of primary server failure, the staging server can be promoted to active.
23. A developer is building a new application that will run on an Azure Virtual Machine (VM). The application needs to securely access Azure Key Vault to retrieve secrets without requiring hardcoded credentials or managing service principal secrets. Which identity solution should the developer implement for the VM?
Implement an authentication and access management solution
A.System-assigned managed identity
B.User-assigned managed identity
C.Service principal with a client secret
D.Application registration with certificates
Show answerAnswer
A. System-assigned managed identity
A system-assigned managed identity provides an identity for an Azure service (like a VM) in Azure AD. This identity is tied to the lifecycle of the VM and can be used to authenticate to Azure Key Vault without requiring the developer to manage any credentials or secrets.
24. A pilot project team is developing a new line-of-business application that will be hosted on Azure App Service. This application needs to securely access data from an Azure SQL Database and secrets from Azure Key Vault. The developers want to avoid embedding credentials in the application code or configuration files. Which Azure AD feature provides the most secure and manageable solution for this scenario?
Implement an authentication and access management solution
A.Service principals with client secrets
B.Conditional Access policies
C.Managed identities for Azure resources
D.Azure AD Application proxy
Show answerAnswer
C. Managed identities for Azure resources
Managed identities for Azure resources provide an automatically managed identity in Azure AD for Azure services, eliminating the need for developers to manage credentials. This is the most secure and manageable solution for Azure-hosted applications accessing other Azure resources.
25. A company is using Azure AD and wants to standardize user access to all corporate resources based on job function. They plan to use Azure AD groups to manage permissions. What type of Azure AD group should be used to assign licenses and access to Microsoft 365 applications, as well as access to non-Microsoft SaaS applications integrated with Azure AD for SSO?
Implement an authentication and access management solution
A.Dynamic user group
B.Security group
C.Mail-enabled security group
D.Microsoft 365 group
Show answerAnswer
B. Security group
Azure AD security groups are the primary type of group used for managing access to Azure resources, assigning licenses, and granting access to applications (both Microsoft 365 and integrated SaaS apps). They are designed for managing user and computer access.
Federation with Active Directory Federation Services (AD FS) in a hybrid identity model means that Azure AD delegates authentication to an on-premises AD FS server. This allows users to sign in using their on-premises credentials without their passwords or hashes ever leaving the on-premises environment.
Azure AD redirects authentication requests to AD FS.
AD FS validates credentials against on-premises AD DS.
Azure AD receives a security token, not credentials.
Azure AD identities automatically managed by Azure, allowing Azure services to authenticate to cloud services without requiring developers to manage credentials.
Eliminates the need for hard-coded credentials.
Can be system-assigned (tied to a resource's lifecycle) or user-assigned (independent resource).
Used for authenticating to any service that supports Azure AD authentication.
A type of Azure AD identity automatically created and managed by Azure for a specific Azure resource, enabling that resource to authenticate to other services securely.
Tied to the lifecycle of a single Azure resource.
Automatically created and deleted with the resource.
Configurations within Azure AD Privileged Identity Management that define requirements for activating and assigning a privileged role, such as approval, MFA, and maximum duration.
A feature in Azure AD that allows administrators to configure additional claims to be included in the security tokens (ID, access, SAML) issued to applications.
Can include standard claims or directory extension attributes.
Configured in the application's manifest or through Azure portal.
Reduces the need for applications to make additional Graph API calls.
Permissions used by an application to act on behalf of a signed-in user, with access limited by both the granted permissions and the user's own permissions.
Application acts 'on behalf of' a user.
Requires user consent (or admin consent).
Combined scope of app permissions and user's access.
A common Azure AD authentication architecture that provides seamless sign-on for corporate users on trusted networks/devices and enforces adaptive access policies like MFA for others.
PTA validates passwords against on-premises AD.
Seamless SSO provides automatic sign-in on corporate networks/devices.
Conditional Access enforces policies based on context (location, device, risk).
A feature in Azure AD that allows organizations to define their own business-specific attributes for directory objects (users, applications, devices) and use them for authorization and policy enforcement.
User-defined attributes in Azure AD.
Can be assigned to users, applications, etc.
Integrates with Conditional Access for policy enforcement.
A feature that enables the inclusion of Azure AD directory extension attributes as claims within security tokens issued to applications by Azure AD, particularly useful for custom application requirements.
Configured via the Azure portal or application manifest.
Supports both standard claims and directory extension attributes.
Ensures custom user data is available in the ID or access token.
A feature in Azure AD that enables seamless collaboration across multiple Azure AD tenants belonging to the same enterprise, providing a unified experience for users and simplified administration.
Facilitates cross-tenant access without individual B2B invitations.
Users maintain their home tenant identity.
Simplifies resource sharing and administration across organizational boundaries.
A Conditional Access policy condition that allows administrators to specify network locations (e.g., trusted IP ranges) to include or exclude from policy enforcement.
Uses 'Named locations' defined in Azure AD.
Can be used to enforce or bypass MFA based on network.
Crucial for balancing security and user experience.
A Microsoft Graph application permission that allows an application to read all properties of all directory objects (users, groups, devices, etc.) in an Azure AD tenant.
Application permission (no signed-in user).
Provides read access to all directory objects.
Requires administrator consent due to broad scope.
Conditional Access with Custom Security Attributes
Flip card
Leveraging Azure AD Conditional Access policies to enforce access control based on user-defined custom security attributes, enabling highly granular authorization without modifying application code.
Custom attributes are defined in Azure AD.
Conditional Access policies evaluate these attributes.
Enforcement happens at the authentication boundary.
An Azure AD Connect authentication method where users authenticate directly against an on-premises AD FS farm, and Azure AD trusts AD FS for identity verification.
Authentication occurs entirely on-premises.
No password hashes or passwords stored/synchronized to Azure AD.
Requires deployment and management of AD FS infrastructure.
A feature of Azure AD Connect that allows deploying a second server that imports and synchronizes data without exporting it to Azure AD, serving as a hot standby.
Provides high availability and disaster recovery for the synchronization service.
Allows testing configuration changes before promoting the server to active.
Only one server can be in active export mode at a time.
Managed identities provide an automatically managed identity in Azure Active Directory for Azure services. This allows Azure services to authenticate to services that support Azure AD authentication without managing credentials.
Eliminates the need to store credentials in code or configuration.
Automatically managed by Azure.
Can be system-assigned (tied to a resource) or user-assigned (standalone).
A capability within Azure AD B2B collaboration that allows external users to sign in using various identity providers beyond just other Azure AD tenants.
Supports personal Microsoft accounts (MSA).
Supports social identity providers like Google and Facebook (after configuration).
External users are added as guest users in the inviting tenant.
A hybrid identity method where a hash of the on-premises AD password hash is synchronized to Azure AD, allowing users to sign in with the same credentials.
Simplest to implement and deploy.
Provides high availability and resilience as authentication can occur even if on-premises AD is down.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.