MSCE Identity Management & Access Solutions Flashcards
7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 MSCE Identity Management & Access Solutions flashcards as text
You are configuring Azure AD Connect and need users to sign in with their on-premises UPN suffix, which is non-routable (e.g., corp.local). What should you do?
Answer: Change the on-premises UPN suffix to match a verified Azure AD domain
Azure AD requires a routable, verified domain for UPNs; the on-premises suffix must be updated to a domain verified in Azure AD.
Which Azure AD Identity Protection signal automatically elevates a sign-in risk level when credentials are detected in a known breach database?
Answer: Leaked credentials
The 'Leaked credentials' detection fires when Azure AD finds a user's credentials in publicly exposed breach data.
An application registered in Azure AD uses the client credentials flow. Which entity authenticates in this flow?
Answer: The application itself using its own identity
Client credentials flow is a daemon/service pattern where the application authenticates as itself using a client secret or certificate.
You want to ensure that users in the Sales group can only access Salesforce from managed devices and only during business hours. Which Azure AD feature should you use?
Answer: Conditional Access policy targeting the Sales group with device and time conditions
Conditional Access policies support targeting specific groups and combining device compliance with named location/time-based conditions.
When configuring Azure AD Privileged Identity Management for a role, what is the 'activation maximum duration' setting?
Answer: The maximum time a user can keep a role active after requesting it
Activation maximum duration limits how many hours an eligible user can hold a role active before it automatically deactivates.
A user reports they cannot complete SSPR (Self-Service Password Reset). You confirm the user has a mobile phone registered. What is the most likely reason SSPR fails?
Answer: SSPR is not licensed or not enabled for that user's group
SSPR must be enabled and scoped to the user's group; if the user's group is not in the SSPR-enabled scope, they cannot use it.
Which claim in a JSON Web Token (JWT) identifies the intended audience of the token (i.e., the resource it was issued for)?
Answer: aud
The 'aud' (audience) claim specifies the resource or application the token is intended for, and resource APIs should validate it.