MS-100 Azure AD Identity Management 2 — Questions and Answers
Question 1: Which Azure AD license is required to use Azure AD Privileged Identity Management (PIM)?
- Azure AD Free
- Azure AD Premium P1
- Azure AD Premium P2 (Correct answer)
- Microsoft 365 Business Basic
Correct answer: Azure AD Premium P2
Azure AD PIM requires Azure AD Premium P2 licensing for each user who is managed or uses PIM features.
Question 2: An administrator configures a Conditional Access policy with 'Grant access - Require compliant device'. What happens when a user signs in from a non-enrolled device?
- Access is granted with MFA
- Access is blocked (Correct answer)
- A risk event is logged
- The user is redirected to enroll the device
Correct answer: Access is blocked
When device compliance is required and the device is not Intune-enrolled or compliant, the Conditional Access policy blocks access entirely.
Question 3: What Azure AD feature enables you to create automatic group membership based on user attribute values such as department or job title?
- Dynamic groups (Correct answer)
- Access packages
- Group writeback
- Nested groups
Correct answer: Dynamic groups
Dynamic groups use membership rules based on user attributes like department or job title to automatically add or remove members.
Question 4: Which type of Azure AD group can be assigned Microsoft 365 licenses directly?
- Security groups only
- Microsoft 365 groups only
- Both Security and Microsoft 365 groups (Correct answer)
- Distribution groups only
Correct answer: Both Security and Microsoft 365 groups
Both Security groups and Microsoft 365 groups support group-based license assignment in Azure AD.
Question 5: An organization needs to enforce a minimum password length of 14 characters for all cloud-only Azure AD accounts. Where should this policy be configured?
- Azure AD Password Protection
- Azure AD Smart Lockout
- Microsoft 365 admin center password policy (Correct answer)
- Azure AD Custom Banned Passwords
Correct answer: Microsoft 365 admin center password policy
Cloud-only Azure AD account password policies (minimum length, complexity) are configured in the Microsoft 365 admin center under Security settings.
Question 6: Which Azure AD feature detects users whose credentials have been found in dark web breaches and flags them as high-risk?
- Impossible travel
- Anonymous IP address
- Leaked credentials (Correct answer)
- Malware-linked IP address
Correct answer: Leaked credentials
The Leaked credentials risk detection correlates Azure AD usernames and passwords against known breach databases to flag compromised accounts.
Which Azure AD license is required to use Azure AD Privileged Identity Management (PIM)?