โ† All MCSE Flashcard Decks

MSCE Identity Management & Access Solutions Flashcards

7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 MSCE Identity Management & Access Solutions flashcards as text
  1. You need to configure Azure AD so that users who sign in from a risky IP address are automatically required to change their password. Which feature combination achieves this?

    Answer: Azure AD Identity Protection user risk policy set to require password change

    An Identity Protection user risk policy can require a secure password change when user risk (elevated by risky sign-ins) meets the threshold.

  2. An organization wants to use Azure AD as an identity provider for a SaaS app that supports SAML 2.0. What must be configured in the SaaS app to trust Azure AD?

    Answer: Azure AD's SAML signing certificate and issuer URI

    For SAML federation, the relying party (SaaS app) must be configured with Azure AD's signing certificate and the issuer (Entity ID) so it can validate SAML assertions.

  3. A company needs to provide secure remote access to an on-premises web app without opening firewall ports. Which Azure AD solution enables this?

    Answer: Azure AD Application Proxy

    Azure AD Application Proxy uses outbound connections from an on-premises connector to publish internal apps securely without inbound firewall rules.

  4. Which Azure AD Conditional Access session control limits the duration of browser sessions so users must re-authenticate after a specified period of inactivity?

    Answer: Sign-in frequency control

    The sign-in frequency session control in Conditional Access forces re-authentication after a configurable period, regardless of persistent session state.

  5. You need to implement entitlement management so that external users can request access to a set of SharePoint sites, Teams, and an app registration as a bundle. What Azure AD object should you create?

    Answer: An access package in Azure AD Entitlement Management

    Access packages in Entitlement Management bundle multiple resources (groups, apps, SharePoint sites) and allow external users to request access through a self-service workflow.

  6. Which protocol does Azure AD use when an application requests a token on behalf of a signed-in user to call a downstream API?

    Answer: OAuth 2.0 On-Behalf-Of (OBO) flow

    The On-Behalf-Of flow allows a middle-tier API to exchange an incoming access token for a new token scoped to a downstream API while preserving the user's identity.

  7. An Azure AD tenant has Continuous Access Evaluation (CAE) enabled. A user's account is disabled in Azure AD. Which of the following best describes what happens to an active CAE-capable session?

    Answer: The resource provider is notified and revokes the session within minutes

    CAE enables near-real-time revocation; when an account is disabled, Azure AD sends a critical event to CAE-capable resource providers that immediately terminates active sessions.