A financial services company, Woodgrove Bank, is implementing Microsoft Entra Privileged Identity Management (PIM) to manage access to sensitive Azure resources. They have a requirement that any activation of the 'Subscription Owner' role must be approved by at least two members of the 'IT Security Leads' group. Additionally, the activation request must include a mandatory ticket number from their ServiceNow instance. How should you configure the PIM role settings to meet these requirements?
Answer and explanation
Correct answer: B
This is the correct solution because it meets both requirements precisely. PIM role settings allow for multi-member approval by selecting a group and specifying the number of required approvers. The 'Require ticket information on activation' setting is specifically designed to integrate with ticketing systems like ServiceNow, making the ticket number a mandatory field during activation. Simply requiring justification is not sufficient as it doesn't enforce the format or presence of a ticket number.
Question 2
A manufacturing company uses Microsoft Entra Connect cloud sync to provision users from a disconnected on-premises Active Directory forest. After a successful initial deployment, a new organizational unit (OU) named 'Robotics Division' was created in the on-premises AD, and new user accounts were added to it. However, these new users are not appearing in Microsoft Entra ID. Existing users are syncing correctly. What is the most likely cause of this issue?
Answer and explanation
Correct answer: C
Microsoft Entra Connect cloud sync uses scoping filters to determine which objects to synchronize. When a new OU is created, it is not automatically included in the sync scope. An administrator must explicitly edit the cloud sync agent configuration, navigate to the OU scoping filters, and select the new 'Robotics Division' OU to include its objects in the synchronization process. Service account permissions are usually set at the domain level, and password hash sync failure would not prevent object creation, only password synchronization.
Question 3
Multiple answers
A global logistics company has registered a custom line-of-business application in their Microsoft Entra tenant. The application requires access to read user profiles and send emails on behalf of the signed-in user. To adhere to the principle of least privilege, which TWO API permissions should be granted to this application? (Select TWO)
Answer and explanation
Correct answers: B, C
This delegated permission allows the application to send mail as the signed-in user, which directly meets one of the stated requirements.
This delegated permission allows the application to read the basic profile of all users in the organization, which is a least-privilege way to fulfill the requirement of reading user profiles. 'User.Read' would only allow reading the signed-in user's profile, and 'User.Read.All' is more permissive than necessary if only basic profile information is needed.
Question 4
True or False: When configuring a Microsoft Entra access review for a dynamic group, if a user's attributes change during the review period causing them to be removed from the group by the dynamic membership rule, their access is immediately revoked regardless of the reviewer's decision.
Answer and explanation
Correct answer: A
This statement is true. Dynamic group membership is evaluated continuously. If a user no longer meets the criteria of the dynamic membership rule, they are automatically removed from the group. The access review process audits existing membership but does not override the fundamental logic of the dynamic group itself. The removal by the rule takes precedence.
Question 5
To deploy Microsoft Entra pass-through authentication (PTA), you must install an Authentication Agent on a domain-joined server. To ensure high availability, you plan to install agents on three different servers. The PowerShell command to register the first agent is Register-AzureADConnectAuthenticationAgent. What is the value for the ____ parameter when registering the second and third agents to ensure they are part of the same agent group for load balancing and failover?
Answer and explanation
Correct answer: A
When installing additional Pass-through Authentication agents for high availability, you run the same registration command (Register-AzureADConnectAuthenticationAgent) on each new server. The service automatically detects that it's being registered for an existing tenant and adds the new agent to the default agent group, enabling load balancing and failover. No special parameters are needed to join an existing group.
Question 6
Case Study: Litware, Inc. Identity Modernization
Company Background: Litware, Inc. is a software development company with 2,000 employees. They have a hybrid identity environment using Microsoft Entra Connect to synchronize their on-premises Active Directory (ad.litware.com) with Microsoft Entra ID. They currently use Password Hash Synchronization and have an Azure AD Premium P2 license for all users.
Current Situation: Litware has a critical on-premises legacy application called 'CodeVault' that uses Kerberos authentication. Remote developers need to access CodeVault, but the company wants to avoid using a traditional VPN. Litware has recently acquired a smaller company that uses Google Workspace as their identity provider. Litware needs to grant these newly acquired employees access to a specific set of SaaS applications managed in the Litware Microsoft Entra tenant.
Requirements:
Provide remote access to the on-premises 'CodeVault' application without a VPN.
The solution for 'CodeVault' must support Kerberos authentication and enforce Microsoft Entra Conditional Access policies.
Allow the acquired company's employees to use their existing Google Workspace credentials to access designated SaaS apps in the Litware tenant.
Minimize administrative overhead for managing the acquired users' identities.
Problem: You are an Identity Architect tasked with designing a solution that meets all of Litware's requirements. Which of the following solutions is the most effective?
graph TD
subgraph Internet
RemoteDev[Remote Developer]
AcquiredUser[Acquired Co. User]
end
subgraph Litware Azure
EntraID[Microsoft Entra ID]
AppProxy[Application Proxy]
SaaSApps[SaaS Apps]
CAPolicy[CA Policies]
end
subgraph Litware On-Premises
AD[ad.litware.com]
CodeVault[CodeVault App]
Connector[App Proxy Connector]
end
subgraph Acquired Co.
Google[Google Workspace]
end
RemoteDev -->|1. Access Request| EntraID
EntraID -->|2. Enforce CA| CAPolicy
CAPolicy -->|3. Authenticate| EntraID
EntraID -->|4. Forward to Proxy| AppProxy
AppProxy -->|5. To Connector| Connector
Connector -->|6. KCD| AD
AD -->|7. Kerberos Ticket| Connector
Connector -->|8. Access App| CodeVault
AcquiredUser -->|1. Access Request| SaaSApps
SaaSApps -->|2. Redirect to Entra| EntraID
EntraID -->|3. Redirect to Google| Google
Google -->|4. Authenticate User| AcquiredUser
Google -->|5. SAML Token| EntraID
EntraID -->|6. Grant Access| SaaSApps
Answer and explanation
Correct answer: B
This solution correctly addresses all requirements. Microsoft Entra Application Proxy with KCD is the designated solution for publishing on-premises Kerberos-based applications securely while enabling the enforcement of Conditional Access policies. For the acquired users, setting up Google Workspace as a federated identity provider allows them to use their existing credentials (fulfilling requirement 3) and minimizes administrative overhead since user accounts don't need to be manually created or managed in the Litware tenant (fulfilling requirement 4).
Question 7
Multiple answers
A security administrator is reviewing sign-in logs and notices several 'unfamiliar sign-in properties' risk detections. To automate the response, the administrator wants to configure a policy that forces users with a medium or high user risk level to perform a secure password change. Which two services should be configured to achieve this? (Select TWO)
Answer and explanation
Correct answers: A, D
Microsoft Entra ID Protection is the service that detects and calculates user risk levels based on various signals, including 'unfamiliar sign-in properties'. It is where you create the user risk policy.
For the 'secure password change' remediation to be available, SSPR must be enabled and configured for the targeted users. The user risk policy in ID Protection relies on SSPR to facilitate the password reset process.
Question 8
An organization is using group-based licensing to assign Microsoft 365 E5 licenses to all users in the 'Marketing' department. A new user, User1, is added to the 'Marketing' group. However, after 24 hours, User1 still does not have an E5 license. An administrator checks the group's licensing status and sees a processing error stating, 'License assignment failed for one or more users.' What is the most common reason for this specific error?
Answer and explanation
Correct answer: A
While other issues can occur, the most frequent cause for a license assignment to fail for a new user being added to a licensed group is the exhaustion of available licenses in the tenant. Microsoft Entra cannot assign a license that it doesn't have. An administrator would need to purchase more licenses or free up existing ones for the assignment to succeed.
Question 9
A company is configuring a Conditional Access policy to protect a critical application. The policy must block access from all countries except for Canada and the United States. Which configuration for the 'Locations' condition is the correct way to implement this?
Answer and explanation
Correct answer: A
The standard best practice for creating a location-based block policy is to target 'Any location' in the 'Include' condition and then add the approved locations (in this case, a named location containing Canada and the US) to the 'Exclude' condition. This ensures that all traffic is evaluated, and only the explicitly excluded locations are allowed. Trying to include all countries except two is impractical and prone to error.
Question 10
A developer at your company has created an Azure Function App that needs to read secrets from an Azure Key Vault. To follow security best practices, you want to avoid storing any credentials or secrets in the Function App's configuration. What is the most secure and recommended method for the Function App to authenticate to the Key Vault?
Answer and explanation
Correct answer: B
Using a system-assigned managed identity is the most secure and recommended approach. It creates an identity for the Azure Function App directly in Microsoft Entra ID without any credentials being stored in the application's code or configuration. You then grant this identity access to the Key Vault. The Function App can acquire an access token from the managed identity endpoint to authenticate to the Key Vault securely.