Microsoft Identity and Access Administrator Free Sample Questions

20 free sample questions263 in the full practice test Other version: MS-500(218)

Try simulator

SC-300 Sample Questions

  1. Question 1

    A financial services company, Woodgrove Bank, is implementing Microsoft Entra Privileged Identity Management (PIM) to manage access to sensitive Azure resources. They have a requirement that any activation of the 'Subscription Owner' role must be approved by at least two members of the 'IT Security Leads' group. Additionally, the activation request must include a mandatory ticket number from their ServiceNow instance. How should you configure the PIM role settings to meet these requirements?

    Answer and explanation

    Correct answer: B

    This is the correct solution because it meets both requirements precisely. PIM role settings allow for multi-member approval by selecting a group and specifying the number of required approvers. The 'Require ticket information on activation' setting is specifically designed to integrate with ticketing systems like ServiceNow, making the ticket number a mandatory field during activation. Simply requiring justification is not sufficient as it doesn't enforce the format or presence of a ticket number.

  2. Question 2

    A manufacturing company uses Microsoft Entra Connect cloud sync to provision users from a disconnected on-premises Active Directory forest. After a successful initial deployment, a new organizational unit (OU) named 'Robotics Division' was created in the on-premises AD, and new user accounts were added to it. However, these new users are not appearing in Microsoft Entra ID. Existing users are syncing correctly. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: C

    Microsoft Entra Connect cloud sync uses scoping filters to determine which objects to synchronize. When a new OU is created, it is not automatically included in the sync scope. An administrator must explicitly edit the cloud sync agent configuration, navigate to the OU scoping filters, and select the new 'Robotics Division' OU to include its objects in the synchronization process. Service account permissions are usually set at the domain level, and password hash sync failure would not prevent object creation, only password synchronization.

  3. Question 3

    Multiple answers

    A global logistics company has registered a custom line-of-business application in their Microsoft Entra tenant. The application requires access to read user profiles and send emails on behalf of the signed-in user. To adhere to the principle of least privilege, which TWO API permissions should be granted to this application? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    This delegated permission allows the application to send mail as the signed-in user, which directly meets one of the stated requirements.

    This delegated permission allows the application to read the basic profile of all users in the organization, which is a least-privilege way to fulfill the requirement of reading user profiles. 'User.Read' would only allow reading the signed-in user's profile, and 'User.Read.All' is more permissive than necessary if only basic profile information is needed.

  4. Question 4

    True or False: When configuring a Microsoft Entra access review for a dynamic group, if a user's attributes change during the review period causing them to be removed from the group by the dynamic membership rule, their access is immediately revoked regardless of the reviewer's decision.

    Answer and explanation

    Correct answer: A

    This statement is true. Dynamic group membership is evaluated continuously. If a user no longer meets the criteria of the dynamic membership rule, they are automatically removed from the group. The access review process audits existing membership but does not override the fundamental logic of the dynamic group itself. The removal by the rule takes precedence.

  5. Question 5

    To deploy Microsoft Entra pass-through authentication (PTA), you must install an Authentication Agent on a domain-joined server. To ensure high availability, you plan to install agents on three different servers. The PowerShell command to register the first agent is Register-AzureADConnectAuthenticationAgent. What is the value for the ____ parameter when registering the second and third agents to ensure they are part of the same agent group for load balancing and failover?

    Answer and explanation

    Correct answer: A

    When installing additional Pass-through Authentication agents for high availability, you run the same registration command (Register-AzureADConnectAuthenticationAgent) on each new server. The service automatically detects that it's being registered for an existing tenant and adds the new agent to the default agent group, enabling load balancing and failover. No special parameters are needed to join an existing group.

  6. Question 6

    Case Study: Litware, Inc. Identity Modernization

    Company Background:
    Litware, Inc. is a software development company with 2,000 employees. They have a hybrid identity environment using Microsoft Entra Connect to synchronize their on-premises Active Directory (ad.litware.com) with Microsoft Entra ID. They currently use Password Hash Synchronization and have an Azure AD Premium P2 license for all users.

    Current Situation:
    Litware has a critical on-premises legacy application called 'CodeVault' that uses Kerberos authentication. Remote developers need to access CodeVault, but the company wants to avoid using a traditional VPN. Litware has recently acquired a smaller company that uses Google Workspace as their identity provider. Litware needs to grant these newly acquired employees access to a specific set of SaaS applications managed in the Litware Microsoft Entra tenant.

    Requirements:

    1. Provide remote access to the on-premises 'CodeVault' application without a VPN.
    2. The solution for 'CodeVault' must support Kerberos authentication and enforce Microsoft Entra Conditional Access policies.
    3. Allow the acquired company's employees to use their existing Google Workspace credentials to access designated SaaS apps in the Litware tenant.
    4. Minimize administrative overhead for managing the acquired users' identities.

    Problem:
    You are an Identity Architect tasked with designing a solution that meets all of Litware's requirements. Which of the following solutions is the most effective?

    graph TD subgraph Internet RemoteDev[Remote Developer] AcquiredUser[Acquired Co. User] end subgraph Litware Azure EntraID[Microsoft Entra ID] AppProxy[Application Proxy] SaaSApps[SaaS Apps] CAPolicy[CA Policies] end subgraph Litware On-Premises AD[ad.litware.com] CodeVault[CodeVault App] Connector[App Proxy Connector] end subgraph Acquired Co. Google[Google Workspace] end RemoteDev -->|1. Access Request| EntraID EntraID -->|2. Enforce CA| CAPolicy CAPolicy -->|3. Authenticate| EntraID EntraID -->|4. Forward to Proxy| AppProxy AppProxy -->|5. To Connector| Connector Connector -->|6. KCD| AD AD -->|7. Kerberos Ticket| Connector Connector -->|8. Access App| CodeVault AcquiredUser -->|1. Access Request| SaaSApps SaaSApps -->|2. Redirect to Entra| EntraID EntraID -->|3. Redirect to Google| Google Google -->|4. Authenticate User| AcquiredUser Google -->|5. SAML Token| EntraID EntraID -->|6. Grant Access| SaaSApps

    Answer and explanation

    Correct answer: B

    This solution correctly addresses all requirements. Microsoft Entra Application Proxy with KCD is the designated solution for publishing on-premises Kerberos-based applications securely while enabling the enforcement of Conditional Access policies. For the acquired users, setting up Google Workspace as a federated identity provider allows them to use their existing credentials (fulfilling requirement 3) and minimizes administrative overhead since user accounts don't need to be manually created or managed in the Litware tenant (fulfilling requirement 4).

  7. Question 7

    Multiple answers

    A security administrator is reviewing sign-in logs and notices several 'unfamiliar sign-in properties' risk detections. To automate the response, the administrator wants to configure a policy that forces users with a medium or high user risk level to perform a secure password change. Which two services should be configured to achieve this? (Select TWO)

    Answer and explanation

    Correct answers: A, D

    Microsoft Entra ID Protection is the service that detects and calculates user risk levels based on various signals, including 'unfamiliar sign-in properties'. It is where you create the user risk policy.

    For the 'secure password change' remediation to be available, SSPR must be enabled and configured for the targeted users. The user risk policy in ID Protection relies on SSPR to facilitate the password reset process.

  8. Question 8

    An organization is using group-based licensing to assign Microsoft 365 E5 licenses to all users in the 'Marketing' department. A new user, User1, is added to the 'Marketing' group. However, after 24 hours, User1 still does not have an E5 license. An administrator checks the group's licensing status and sees a processing error stating, 'License assignment failed for one or more users.' What is the most common reason for this specific error?

    Answer and explanation

    Correct answer: A

    While other issues can occur, the most frequent cause for a license assignment to fail for a new user being added to a licensed group is the exhaustion of available licenses in the tenant. Microsoft Entra cannot assign a license that it doesn't have. An administrator would need to purchase more licenses or free up existing ones for the assignment to succeed.

  9. Question 9

    A company is configuring a Conditional Access policy to protect a critical application. The policy must block access from all countries except for Canada and the United States. Which configuration for the 'Locations' condition is the correct way to implement this?

    Answer and explanation

    Correct answer: A

    The standard best practice for creating a location-based block policy is to target 'Any location' in the 'Include' condition and then add the approved locations (in this case, a named location containing Canada and the US) to the 'Exclude' condition. This ensures that all traffic is evaluated, and only the explicitly excluded locations are allowed. Trying to include all countries except two is impractical and prone to error.

  10. Question 10

    A developer at your company has created an Azure Function App that needs to read secrets from an Azure Key Vault. To follow security best practices, you want to avoid storing any credentials or secrets in the Function App's configuration. What is the most secure and recommended method for the Function App to authenticate to the Key Vault?

    Answer and explanation

    Correct answer: B

    Using a system-assigned managed identity is the most secure and recommended approach. It creates an identity for the Azure Function App directly in Microsoft Entra ID without any credentials being stored in the application's code or configuration. You then grant this identity access to the Key Vault. The Function App can acquire an access token from the managed identity endpoint to authenticate to the Key Vault securely.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 481 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon