MSCE Identity Management & Access Solutions Flashcards
7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 MSCE Identity Management & Access Solutions flashcards as text
You need to grant an application permission to read all users' calendars in Microsoft 365 without a signed-in user. Which permission type should you assign?
Answer: Application permission (app role) with admin consent
Application permissions allow a service to act without a user context and require admin consent due to their broad scope.
An enterprise wants to prevent Azure AD users from consenting to third-party apps that request access to company data. What setting should an admin configure?
Answer: Set user consent settings to 'Do not allow user consent'
Setting user consent to 'Do not allow user consent' forces all app consent requests to go through admin approval workflows.
You are using Azure AD Pass-through Authentication (PTA). Where does the actual password validation occur?
Answer: On the on-premises Active Directory domain controllers
PTA forwards the sign-in password validation request to on-premises DCs via lightweight agents; passwords never leave your network.
Which Azure AD feature allows an application to verify its identity using a certificate stored in Azure Key Vault instead of a client secret?
Answer: Certificate-based app credential (client assertion)
Applications can authenticate to Azure AD using a certificate (client assertion) instead of a shared secret, which is more secure.
A company runs workloads in Azure and needs the workload to access Key Vault without storing any credentials in code. What is the recommended solution?
Answer: Assign a system-assigned managed identity to the resource and grant it Key Vault access
System-assigned managed identities provide an automatically managed credential tied to the Azure resource, eliminating the need to store secrets.
During an Azure AD access review of group membership, a reviewer takes no action on a member before the review deadline. The access review is configured to 'Auto-apply results' and the default action is 'Remove access'. What happens?
Answer: The member's access is removed automatically at review end
When auto-apply is enabled and no decision is made, the configured default action (Remove access) is applied automatically.
Which Azure AD feature enables you to define which attributes are synchronized from on-premises AD to Azure AD, filtering out sensitive attributes like payroll data?
Answer: Azure AD Connect attribute filtering
Azure AD Connect's attribute filtering lets administrators control exactly which object attributes are included in synchronization to the cloud.