← All MCSE Flashcard Decks

MSCE Identity Management & Access Solutions Flashcards

7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 MSCE Identity Management & Access Solutions flashcards as text
  1. A company needs to allow external partners to access internal SharePoint sites without creating AD accounts for them. Which Azure AD feature should you configure?

    Answer: Azure AD B2B collaboration

    Azure AD B2B collaboration lets you invite external users using their own identity provider without managing their credentials.

  2. You want to enforce that users can only register MFA methods from a corporate network. Which Azure AD feature enforces this?

    Answer: Conditional Access policy with network location condition

    A Conditional Access policy with a named location (network) condition can restrict MFA registration to trusted networks.

  3. An administrator needs to review which users have been assigned the Global Administrator role over the last 90 days. Where is this information found?

    Answer: Azure AD Privileged Identity Management — Role assignment history

    PIM maintains a detailed history of role assignments and activations, making it the correct source for this audit.

  4. Which token type does Azure AD issue that contains a user's group memberships and is used by resource applications to make authorization decisions?

    Answer: Access token

    Access tokens contain claims such as group memberships and are presented to resource APIs to authorize requests.

  5. Your organization uses AD FS. You want to migrate relying party trusts to Azure AD without disrupting users. Which tool automates the compatibility assessment?

    Answer: AD FS Migration Toolkit (AD FS application activity report)

    The AD FS application activity report in Azure AD analyzes relying party trusts and flags any that need remediation before migration.

  6. A Conditional Access policy is set to require a compliant device. A user with a non-compliant device tries to access Exchange Online. What is the result?

    Answer: Access is blocked regardless of MFA completion

    When a Conditional Access grant control requires device compliance, non-compliant devices are blocked even if MFA is satisfied.

  7. You need to synchronize on-premises AD password hashes to Azure AD so users can sign in to cloud apps with the same password. Which sync method should you enable?

    Answer: Password Hash Synchronization

    Password Hash Synchronization (PHS) copies hashed password hashes to Azure AD, enabling cloud authentication with on-premises credentials.