MD-102 Managing Identity and Access 1 — Questions and Answers
Question 1: Which Azure AD feature allows users to register their Windows 10 devices so they can access organizational resources with a personal device?
- Azure AD Join
- Azure AD Registered (Correct answer)
- Hybrid Azure AD Join
- Workplace Join
Correct answer: Azure AD Registered
Azure AD Registered is designed for personal (BYOD) devices that users register to access organizational resources without the device being fully joined to Azure AD.
Question 2: A user needs to sign in to Windows 10 using Windows Hello for Business. Which authentication method does Windows Hello for Business replace?
- Smart card authentication
- Password-based authentication (Correct answer)
- Certificate-based authentication
- RADIUS authentication
Correct answer: Password-based authentication
Windows Hello for Business replaces password-based authentication with strong two-factor authentication using a PIN or biometric tied to a device-bound credential.
Question 3: An administrator needs to ensure that only compliant devices can access Microsoft 365 resources. Which Azure AD feature should be configured?
- Identity Protection
- Privileged Identity Management
- Conditional Access (Correct answer)
- Access Reviews
Correct answer: Conditional Access
Conditional Access policies in Azure AD can enforce that only devices marked compliant by Intune are permitted to access Microsoft 365 resources.
Question 4: Which join type requires an on-premises Active Directory domain and Azure AD tenant to both have a trust relationship via Azure AD Connect?
- Azure AD Join
- Azure AD Registered
- Hybrid Azure AD Join (Correct answer)
- Workgroup Join
Correct answer: Hybrid Azure AD Join
Hybrid Azure AD Join requires devices to be joined to on-premises AD and then synchronized to Azure AD via Azure AD Connect.
Question 5: A company wants to enforce multi-factor authentication for all admin sign-ins to Azure AD. What is the simplest way to enforce this for all global administrators?
- Per-user MFA
- Conditional Access policy
- Security defaults (Correct answer)
- Identity Protection policy
Correct answer: Security defaults
Security defaults in Azure AD automatically require MFA for all administrators and provide baseline identity protection with minimal configuration.
Question 6: Which Self-Service Password Reset (SSPR) setting allows users to reset their password using an authenticator app notification?
- Email authentication
- Mobile app notification (Correct answer)
- Security questions
- Office phone
Correct answer: Mobile app notification
The mobile app notification method in SSPR allows users to approve a password reset through a push notification sent to their Microsoft Authenticator app.
Which Azure AD feature allows users to register their Windows 10 devices so they can access organizational resources with a personal device?