Step2Study
IT & TechnologySC-900100% Free

Microsoft Security, Compliance, and Identity Fundamentals (SC-900)

Practice bank
310 Qs
Real exam
40 Qs
Time limit
45 min
Passing
700 out of 1000

Exam blueprint

Describe the concepts of security, compliance, and identity
25%
Describe the capabilities of Microsoft Entra
30%
Describe the capabilities of Microsoft Security solutions
30%
Describe the capabilities of Microsoft compliance solutions
15%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 101 min · pass 70% · 310 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice test questions

Sample questions from the 310-question bank, with answers and explanations.

All questions
  1. 1. A company is migrating various legacy applications to Azure. These applications rely heavily on traditional LDAP and Kerberos authentication protocols and are not easily rewritable to use modern authentication methods. The company needs a managed service in Azure that provides domain controller functionality to support these applications without deploying and managing virtual machines for Active Directory. Which Microsoft Entra capability should they use?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Domain Services
    • B. Microsoft Entra Application Proxy
    • C. Microsoft Entra ID Protection
    • D. Microsoft Entra Connect
    Show answer

    A. Microsoft Entra Domain Services

    Microsoft Entra Domain Services provides managed domain services, including LDAP and Kerberos authentication, that are fully compatible with traditional Active Directory. This allows legacy applications to run in Azure without changes, without the overhead of managing virtual machines for domain controllers.

  2. 2. A small business is setting up its cloud environment and wants to implement a security policy that ensures all network traffic entering or leaving their virtual network is filtered based on predefined rules, such as source IP, destination port, and protocol. Which security concept is being applied here?

    Describe the concepts of security, compliance, and identity

    • A. Identity Protection
    • B. Data Encryption
    • C. Network Security
    • D. Endpoint Protection
    Show answer

    C. Network Security

    Network Security focuses on protecting the network infrastructure and network traffic from unauthorized access, misuse, modification, or denial. Filtering traffic based on IP, port, and protocol is a fundamental aspect of network security, typically implemented using firewalls or Network Security Groups (NSGs).

  3. 3. A financial institution requires a high level of assurance for identity verification when onboarding new customers remotely. They want to enable users to present verifiable credentials issued by trusted third parties, such as government agencies, to instantly prove their identity during the onboarding process without sharing underlying sensitive data. Which Microsoft Entra capability supports this scenario?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra B2C
    • B. Microsoft Entra Verified ID
    • C. Microsoft Entra Self-Service Password Reset (SSPR)
    • D. Microsoft Entra Identity Protection
    Show answer

    B. Microsoft Entra Verified ID

    Microsoft Entra Verified ID allows organizations to issue and verify digital credentials based on open standards, enabling users to present verifiable proofs of identity (e.g., from government agencies) without sharing unnecessary personal data. This provides a high level of assurance for remote onboarding.

  4. 4. A manufacturing company is integrating its operational technology (OT) systems with its IT network. They need to implement security measures that assume any entity, whether inside or outside the network perimeter, could be a potential threat. All access requests must be verified explicitly, regardless of origin. Which security model is being adopted?

    Describe the concepts of security, compliance, and identity

    • A. Defense in Depth
    • B. Perimeter Security
    • C. Zero Trust
    • D. Shared Responsibility Model
    Show answer

    C. Zero Trust

    Zero Trust is a security model that assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. It requires verification of every access request as if it originated from an untrusted network.

  5. 5. A financial institution needs to implement a solution that allows its employees to prove their identity digitally using verifiable credentials issued by trusted third parties, rather than relying solely on traditional username and password combinations. Which Microsoft Entra capability supports this requirement?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Application Proxy
    • B. Microsoft Entra Verified ID
    • C. Microsoft Entra PIM
    • D. Microsoft Entra Password Protection
    Show answer

    B. Microsoft Entra Verified ID

    Microsoft Entra Verified ID allows organizations to issue and verify digital verifiable credentials, enabling users to prove their identity in a privacy-preserving and secure manner without traditional passwords.

  6. 6. An organization is implementing a new security policy that dictates all users must have the minimum necessary permissions to perform their job functions and nothing more. This policy is designed to limit the potential damage from compromised accounts or insider threats. Which security principle is this organization enforcing?

    Describe the concepts of security, compliance, and identity

    • A. Least Privilege
    • B. Separation of Duties
    • C. Non-repudiation
    • D. Defense in Depth
    Show answer

    A. Least Privilege

    The principle of Least Privilege states that users should be granted only the minimum necessary permissions to perform their job functions. This directly aligns with the organization's policy to limit potential damage.

  7. 7. A global enterprise needs to manage access to thousands of applications, both cloud-based and on-premises. They want to centralize the management of these applications within Microsoft Entra ID and streamline the user experience for accessing them. Which Microsoft Entra capability allows this centralized management?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra ID Protection
    • B. Microsoft Entra Application Proxy
    • C. Microsoft Entra Application Management
    • D. Microsoft Entra Connect
    Show answer

    C. Microsoft Entra Application Management

    Microsoft Entra Application Management provides a centralized platform for managing access to all applications, whether cloud-based (SaaS) or on-premises, integrating them with Microsoft Entra ID for authentication and authorization.

  8. 8. A large organization with a complex IT environment needs to ensure that sensitive data stored across various cloud services (e.g., Office 365, Azure, third-party SaaS apps) is discovered, classified, and protected according to regulatory requirements. They need a solution that can identify sensitive information like credit card numbers or personal identifiable information (PII) wherever it resides. Which security concept is this related to?

    Describe the concepts of security, compliance, and identity

    • A. Privileged Identity Management (PIM)
    • B. Cloud Access Security Broker (CASB)
    • C. Information Protection
    • D. Identity Governance
    Show answer

    C. Information Protection

    Information Protection focuses on discovering, classifying, labeling, and protecting sensitive data across an organization's digital estate, regardless of location. This includes identifying specific types of sensitive information like PII and credit card numbers.

  9. 9. A small business is setting up its Microsoft Entra ID tenant. They want to allow employees to sign in to cloud applications using their existing Microsoft Entra credentials and ensure that the process is seamless and secure. Which core Microsoft Entra capability enables this functionality?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Application Proxy
    • B. Microsoft Entra authentication
    • C. Microsoft Entra device management
    • D. Microsoft Entra Domain Services
    Show answer

    B. Microsoft Entra authentication

    Microsoft Entra authentication is the core capability that allows users to sign in to applications and services using their Microsoft Entra credentials. This fundamental service provides the identity verification required for secure access.

  10. 10. A global enterprise is evaluating its data privacy practices. They need to ensure that personal data collected from customers is processed lawfully, fairly, and transparently, and that individuals have rights over their data. Which regulatory compliance standard is most directly concerned with these principles?

    Describe the concepts of security, compliance, and identity

    • A. General Data Protection Regulation (GDPR)
    • B. Payment Card Industry Data Security Standard (PCI DSS)
    • C. Health Insurance Portability and Accountability Act (HIPAA)
    • D. Sarbanes-Oxley Act (SOX)
    Show answer

    A. General Data Protection Regulation (GDPR)

    GDPR is a comprehensive data protection law that focuses on the lawful, fair, and transparent processing of personal data and grants individuals significant rights over their information, particularly for residents of the European Union.

  11. 11. A global organization uses Microsoft 365 and Azure services. They want to ensure that employees can only access sensitive data from managed devices located within specific geographical regions during business hours. Access from unmanaged devices or outside business hours should be blocked or require additional verification. Which identity concept would best facilitate this granular access control?

    Describe the concepts of security, compliance, and identity

    • A. Single Sign-On (SSO)
    • B. Role-Based Access Control (RBAC)
    • C. Just-in-Time (JIT) Access
    • D. Conditional Access
    Show answer

    D. Conditional Access

    Conditional Access evaluates conditions like user location, device state, and sign-in risk during authentication to enforce access policies. This allows for granular control, such as blocking access or requiring MFA based on specific criteria.

  12. 12. A security auditor observes that several users have been assigned highly privileged roles in Microsoft Entra ID for an extended period, even though they only require these permissions for specific, infrequent tasks. The auditor recommends implementing a solution that provides just-in-time (JIT) access and requires multi-factor authentication (MFA) and a business justification for activating these roles. Which Microsoft Entra capability should be configured to meet these recommendations?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Conditional Access
    • B. Microsoft Entra Privileged Identity Management (PIM)
    • C. Microsoft Entra Access Reviews
    • D. Microsoft Entra Identity Protection
    Show answer

    B. Microsoft Entra Privileged Identity Management (PIM)

    Microsoft Entra Privileged Identity Management (PIM) is the primary service for managing and reducing the risks associated with privileged access. It enables just-in-time access, requires MFA for activation, enforces business justifications, and provides approval workflows, directly addressing the auditor's recommendations.

  13. 13. A company is designing a new cloud application that will handle highly sensitive customer data. They want to ensure that every action taken by an administrator within the application is recorded, including who performed the action, what they did, and when. This is crucial for forensic investigations and compliance. Which identity concept is primarily focused on recording these actions?

    Describe the concepts of security, compliance, and identity

    • A. Authentication
    • B. Auditing
    • C. Authorization
    • D. Federated Identity
    Show answer

    B. Auditing

    Auditing (or accounting) is the process of recording and reviewing events and actions within a system to maintain a security log. The scenario explicitly describes the need for actions to be 'recorded, including who performed the action, what they did, and when', which is the definition of auditing.

  14. 14. A financial institution needs to implement a solution that allows its employees to prove their identity in a secure, privacy-preserving, and verifiable manner across different organizations and services, without relying on a central authority to store all their personal data. They want to issue digital credentials that users control. Which Microsoft Entra capability supports this requirement?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Verified ID
    • B. Microsoft Entra B2C
    • C. Microsoft Entra Domain Services
    • D. Microsoft Entra Application Proxy
    Show answer

    A. Microsoft Entra Verified ID

    Microsoft Entra Verified ID allows organizations to issue, hold, and verify digital credentials based on decentralized identity standards. This gives individuals control over their identity and enables secure, privacy-preserving verification without a central authority storing all personal data, directly matching the scenario.

  15. 15. A company wants to ensure that all administrative roles in Microsoft Entra ID are assigned with just-in-time (JIT) access and require approval for activation. This helps minimize standing access for highly privileged accounts. Which Microsoft Entra capability should they implement?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Verified ID
    • B. Microsoft Entra Privileged Identity Management (PIM)
    • C. Microsoft Entra Access Reviews
    • D. Microsoft Entra Identity Protection
    Show answer

    B. Microsoft Entra Privileged Identity Management (PIM)

    Microsoft Entra Privileged Identity Management (PIM) allows organizations to manage, control, and monitor access to important resources. This includes providing just-in-time access, requiring approval for role activation, and enforcing multi-factor authentication.

  16. 16. A financial institution is implementing a new security system. They need to ensure that when a user logs into their internal banking application, their identity is verified by a trusted third-party identity provider, rather than the banking application itself. This allows users to use their existing corporate credentials without creating new ones for each application. Which identity concept does this scenario describe?

    Describe the concepts of security, compliance, and identity

    • A. Single Sign-On (SSO)
    • B. Federated Identity
    • C. Privileged Identity Management (PIM)
    • D. Multi-Factor Authentication (MFA)
    Show answer

    B. Federated Identity

    Federated Identity enables identity information to be shared and trusted across different security domains, allowing users to authenticate with one identity provider (e.g., their corporate network) and gain access to resources in another domain (e.g., the banking application) without re-authenticating.

  17. 17. A company is integrating a legacy on-premises application with Microsoft Entra ID. The application uses Kerberos authentication and cannot be directly exposed to the internet. Users need to access this application from outside the corporate network using their Microsoft Entra credentials. Which Microsoft Entra capability should be deployed to facilitate this access?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra B2B collaboration
    • B. Microsoft Entra Domain Services
    • C. Microsoft Entra Application Proxy
    • D. Microsoft Entra Connect
    Show answer

    C. Microsoft Entra Application Proxy

    Microsoft Entra Application Proxy allows you to publish on-premises web applications to external users, providing secure remote access using Microsoft Entra ID for single sign-on. It handles authentication and traffic routing without requiring a VPN or exposing the internal network.

  18. 18. A consulting firm frequently collaborates with external partners on projects. They want to provide these partners with access to specific project-related resources in their Azure environment, but without creating full user accounts for them in their own corporate directory (Azure AD tenant). The partners should authenticate using their existing corporate identities from their own organizations. Which identity concept would facilitate this secure collaboration?

    Describe the concepts of security, compliance, and identity

    • A. Privileged Identity Management (PIM)
    • B. Federated Identity
    • C. Device Identity
    • D. Managed Identity
    Show answer

    B. Federated Identity

    Federated identity allows users from one organization (identity provider) to authenticate and access resources in another organization (service provider) using their existing credentials, without needing to create new accounts in the service provider's directory. This perfectly matches the scenario where external partners use their 'existing corporate identities' to access resources in the consulting firm's tenant.

  19. 19. A client is developing a new application that will process highly sensitive personal identifiable information (PII). They want to ensure that if the data is ever exfiltrated or accessed by unauthorized individuals, it remains unintelligible and unusable. Which security control directly addresses this requirement?

    Describe the concepts of security, compliance, and identity

    • A. Access Control List (ACL)
    • B. Firewall
    • C. Encryption
    • D. Intrusion Detection System (IDS)
    Show answer

    C. Encryption

    Encryption transforms data into an unreadable format, ensuring that even if unauthorized individuals gain access, the data remains unintelligible and unusable without the proper decryption key. This directly addresses the requirement for data to be unusable if exfiltrated.

  20. 20. A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They require a centralized system to store user identities, authenticate users, and manage access rights efficiently. Which identity concept is essential for this requirement?

    Describe the concepts of security, compliance, and identity

    • A. Federated Identity
    • B. Directory Services
    • C. Multi-Factor Authentication (MFA)
    • D. Conditional Access
    Show answer

    B. Directory Services

    Directory Services provide the centralized repository for user identities and attributes, crucial for managing a large user base across diverse applications and enabling authentication and authorization.

  21. 21. A large enterprise is migrating its on-premises Active Directory to a cloud-based identity solution. They need a service that allows them to centrally manage user accounts, groups, and devices, and provides authentication and authorization services for applications both in the cloud and on-premises. Which type of service is best suited for this requirement?

    Describe the concepts of security, compliance, and identity

    • A. Data Loss Prevention (DLP)
    • B. Cloud Access Security Broker (CASB)
    • C. Security Information and Event Management (SIEM)
    • D. Identity and Access Management (IAM)
    Show answer

    D. Identity and Access Management (IAM)

    Identity and Access Management (IAM) systems are designed to manage digital identities and control access to resources. This includes user provisioning, authentication, authorization, and directory services, perfectly matching the scenario's requirements for central management of users, groups, devices, and access services.

  22. 22. A company is migrating various legacy applications to Azure and needs to provide managed domain services (like domain join, group policy, and LDAP) for their Azure-hosted virtual machines without deploying and managing traditional domain controllers. Which Microsoft Entra capability provides this service?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Application Proxy
    • B. Microsoft Entra Connect
    • C. Microsoft Entra ID Protection
    • D. Microsoft Entra Domain Services
    Show answer

    D. Microsoft Entra Domain Services

    Microsoft Entra Domain Services provides managed domain services for Azure virtual machines, allowing them to use traditional AD DS features like domain join, group policy, and LDAP without deploying and managing domain controllers.

  23. 23. A global organization is implementing a new security policy that requires all users to provide two different forms of verification before accessing sensitive internal applications. Which security concept is this organization primarily implementing?

    Describe the concepts of security, compliance, and identity

    • A. Least Privilege
    • B. Single Sign-On (SSO)
    • C. Conditional Access
    • D. Multi-Factor Authentication (MFA)
    Show answer

    D. Multi-Factor Authentication (MFA)

    Multi-Factor Authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, significantly increasing security by making it harder for unauthorized users to gain access.

  24. 24. A company is migrating several legacy applications to Azure. These applications rely heavily on traditional LDAP and Kerberos authentication for user and group management, but the company wants to avoid deploying and managing domain controllers in Azure VMs. Which Microsoft Entra capability provides managed domain services for these legacy applications in Azure?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Connect
    • B. Microsoft Entra Domain Services
    • C. Microsoft Entra B2B Collaboration
    • D. Microsoft Entra Application Proxy
    Show answer

    B. Microsoft Entra Domain Services

    Microsoft Entra Domain Services provides managed domain services in Azure, offering compatibility with traditional LDAP and Kerberos authentication without the need to deploy, manage, and patch domain controllers. This directly supports legacy applications migrating to Azure while leveraging Microsoft Entra ID identities.

  25. 25. A global enterprise uses Microsoft Entra ID and has a complex organizational structure with many departments and projects. They need a scalable solution to delegate the management of access to specific internal applications and resources to department leads, empowering them to approve or deny access requests without involving central IT. Which Microsoft Entra capability supports this delegated access management?

    Describe the capabilities of Microsoft Entra

    • A. Microsoft Entra Conditional Access
    • B. Microsoft Entra Access Reviews
    • C. Microsoft Entra Entitlement Management
    • D. Microsoft Entra Privileged Identity Management (PIM)
    Show answer

    C. Microsoft Entra Entitlement Management

    Microsoft Entra Entitlement Management allows organizations to manage identity and access lifecycle at scale by enabling delegated administration to non-IT users (like department leads) for approving access to groups, applications, and SharePoint sites. This directly addresses the need for delegated access management and approval workflows.

Microsoft Security, Compliance, and Identity Fundamentals (SC-900) flashcards

Tap a card to flip it. 111 flashcards in the full deck.

  • Microsoft Entra Domain Services

    Flip card

    Provides managed domain services in Azure, including domain join, LDAP, Kerberos, and NTLM authentication, compatible with traditional Windows Server Active Directory.

    • Managed domain controllers for Azure workloads
    • Supports legacy authentication protocols (LDAP, Kerberos, NTLM)
    • No need to deploy/manage VMs for domain controllers
    Study this card →
  • Network Security

    Flip card

    Measures taken to protect the underlying networking infrastructure and network traffic from unauthorized access, misuse, malfunction, modification, destruction, or improper disclosure.

    • Includes firewalls, intrusion detection/prevention systems, VPNs.
    • Focuses on controlling traffic flow and securing network devices.
    • Aims to prevent network-based attacks.
    Study this card →
  • Microsoft Entra Verified ID

    Flip card

    A decentralized identity solution that allows organizations to issue and verify digital credentials, enabling individuals to control their identity data and securely prove information to relying parties.

    • Based on open standards (Decentralized Identifiers, Verifiable Credentials).
    • Users control their identity data.
    • Enables trusted, privacy-preserving identity verification.
    Study this card →
  • Zero Trust

    Flip card

    A security model where no user or device is inherently trusted, regardless of whether they are inside or outside the network perimeter. All access requests are explicitly verified.

    • Never trust, always verify.
    • Assumes breach.
    • Requires explicit verification for every access attempt.
    Study this card →
  • Least Privilege

    Flip card

    A security principle where a user or process is granted only the minimum access rights needed to perform its function.

    • Reduces the attack surface.
    • Limits potential damage from breaches.
    • Fundamental to secure system design.
    Study this card →
  • Microsoft Entra Application Management

    Flip card

    The capability within Microsoft Entra ID that allows organizations to manage access to all applications (cloud-based and on-premises) by integrating them with Entra ID for authentication, authorization, and centralized user experience.

    • Centralizes application access control
    • Supports various authentication protocols (SAML, OIDC, password SSO)
    • Enables Single Sign-On (SSO) for integrated apps
    Study this card →
  • Information Protection

    Flip card

    A comprehensive strategy and set of technologies for identifying, classifying, labeling, and protecting sensitive data throughout its lifecycle.

    • Discovers sensitive data across disparate sources.
    • Applies labels and encryption based on sensitivity.
    • Helps comply with data privacy regulations.
    Study this card →
  • Microsoft Entra Authentication

    Flip card

    The process by which Microsoft Entra ID verifies a user's identity to grant access to resources.

    • Enables single sign-on (SSO) for cloud applications.
    • Supports various methods like password, MFA, passwordless.
    • Centralizes identity verification for Microsoft cloud services.
    Study this card →
  • General Data Protection Regulation (GDPR)

    Flip card

    A regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.

    • Mandates strict rules for processing personal data.
    • Grants individuals rights over their data (e.g., right to access, erasure).
    • Applies to any organization processing EU citizens' data, regardless of location.
    Study this card →
  • Conditional Access

    Flip card

    A security feature that evaluates specific conditions (e.g., user, location, device, risk) to determine if and how a user can access a resource.

    • Enforces policies based on real-time conditions.
    • Can block access, require MFA, or limit capabilities.
    • Integrates with identity providers and device management.
    Study this card →
  • Microsoft Entra Privileged Identity Management (PIM)

    Flip card

    A service that helps manage, control, and monitor access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services, by providing just-in-time, time-bound, and approval-based access.

    • Minimizes standing privileged access ('zero standing access').
    • Enforces time-bound access, requiring re-activation after expiration.
    • Can require MFA and business justification for role activation.
    Study this card →
  • Auditing (Accounting)

    Flip card

    The process of recording and reviewing events and actions within a security system to maintain a log of activity, crucial for accountability and forensic analysis.

    • Tracks user actions and system events.
    • Provides a trail for accountability and non-repudiation.
    • Essential for compliance and security investigations.
    Study this card →
  • Federated Identity

    Flip card

    A system that allows users to authenticate with one identity provider and gain access to resources managed by other service providers without needing to create separate credentials for each service. It establishes trust between disparate identity systems.

    • Enables single sign-on across different organizations.
    • Relies on trusted identity providers.
    • Simplifies user access and reduces credential sprawl.
    Study this card →
  • Microsoft Entra Application Proxy

    Flip card

    A Microsoft Entra ID feature that provides secure remote access to on-premises web applications. It acts as a reverse proxy, allowing users to access internal apps from anywhere without a VPN.

    • Publishes on-premises web apps to be accessible from outside the corporate network.
    • Integrates with Microsoft Entra ID for authentication and Conditional Access.
    • Supports various authentication methods including Kerberos (via KCD).
    Study this card →
  • Encryption

    Flip card

    The process of converting information or data into a code to prevent unauthorized access, making it unreadable without the correct key.

    • Protects data at rest and in transit.
    • Essential for confidentiality.
    • Uses algorithms and keys to scramble/unscramble data.
    Study this card →
  • Directory Services

    Flip card

    A centralized, hierarchical database that stores information about network resources and users, enabling efficient management and access control.

    • Examples include Active Directory and Azure Active Directory.
    • Provides a single source of truth for user identities.
    • Facilitates authentication and authorization across an organization's resources.
    Study this card →
  • Identity and Access Management (IAM)

    Flip card

    A framework of policies and technologies for ensuring that the right individuals and things have the right access to the right resources at the right time and for the right reasons.

    • Manages user identities and their access privileges.
    • Includes authentication, authorization, and user lifecycle management.
    • Central to modern security strategies.
    Study this card →
  • Multi-Factor Authentication (MFA)

    Flip card

    A security system that requires users to provide two or more verification factors to gain access to a resource.

    • Enhances security by requiring multiple proofs of identity.
    • Combines different types of authentication factors (e.g., something you know, something you have, something you are).
    • Significantly reduces the risk of unauthorized access.
    Study this card →
  • Microsoft Entra Entitlement Management

    Flip card

    A governance capability that enables organizations to manage identity and access lifecycle at scale, by automating access requests, approvals, provisioning, and de-provisioning.

    • Delegates access management to business owners.
    • Manages access to groups, applications, and SharePoint sites.
    • Automates access lifecycle (request, approval, review, expiration).
    Study this card →
  • Data Integrity

    Flip card

    The principle of ensuring that data is accurate, complete, and trustworthy, and has not been altered or destroyed in an unauthorized or accidental manner.

    • Protects against unauthorized modification or deletion.
    • Ensures data accuracy and consistency.
    • Crucial for reliable decision-making and compliance.
    Study this card →
  • FIDO2 (Fast Identity Online 2) security keys

    Flip card

    A passwordless authentication standard that uses public-key cryptography and physical security keys to provide strong, phishing-resistant authentication for web services.

    • Uses asymmetric cryptography (public/private key pairs)
    • Offers phishing resistance
    • Compatible with various devices and platforms
    Study this card →
  • Microsoft Entra multifactor authentication (MFA)

    Flip card

    A security system that requires users to provide two or more verification methods to gain access to a resource, significantly enhancing security.

    • Adds an extra layer of security beyond just a password.
    • Common verification methods include phone calls, text messages, or authenticator apps.
    • Helps protect against credential theft and unauthorized access.
    Study this card →
  • Microsoft Entra B2B Collaboration

    Flip card

    A feature of Microsoft Entra ID that allows you to invite external users (guests) to your Microsoft Entra tenant to access your applications and resources, while they sign in with their own identities.

    • Supports identities from other Microsoft Entra tenants, social providers (Google, Facebook), or email one-time passcodes.
    • Simplifies sharing resources with partners, vendors, and contractors.
    • Guest users are managed within your Microsoft Entra tenant.
    Study this card →
  • Microsoft Entra Access Reviews

    Flip card

    An identity governance feature that enables organizations to efficiently manage group memberships, access to enterprise applications, and privileged role assignments.

    • Automates periodic review and certification of access.
    • Reviewers can be group owners or business users.
    • Can automatically remove access for unapproved users.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.