MS-100 Azure AD Identity Management 1 — Questions and Answers
Question 1: Which Azure AD feature allows you to enforce multi-factor authentication based on user location, device compliance, and application sensitivity?
- Conditional Access (Correct answer)
- Identity Protection
- Privileged Identity Management
- Azure AD B2C
Correct answer: Conditional Access
Conditional Access policies evaluate signals like location, device state, and app sensitivity to grant or block access with MFA requirements.
Question 2: An administrator needs to provide just-in-time privileged access to Azure resources with approval workflows. Which Azure AD feature should they use?
- Azure AD Roles
- Privileged Identity Management (PIM) (Correct answer)
- Access Reviews
- Entitlement Management
Correct answer: Privileged Identity Management (PIM)
PIM provides just-in-time privileged access with approval workflows, time-limited assignments, and audit trails for Azure AD and Azure resources.
Question 3: What is the maximum number of objects that can be synchronized to a single Azure AD tenant using Azure AD Connect?
- 100,000
- 300,000
- 500,000 (Correct answer)
- 1,000,000
Correct answer: 500,000
A single Azure AD tenant supports up to 500,000 objects when synchronized using Azure AD Connect from an on-premises directory.
Question 4: Which Azure AD Identity Protection risk detection identifies sign-ins from anonymous IP addresses such as Tor browsers?
- Leaked credentials
- Anonymous IP address (Correct answer)
- Impossible travel
- Malware-linked IP address
Correct answer: Anonymous IP address
The Anonymous IP address risk detection flags sign-ins originating from anonymous proxies or Tor network exit nodes.
Question 5: A company wants to allow external partners to access specific SharePoint sites without creating guest accounts in Azure AD. Which feature enables this?
- Azure AD B2B collaboration
- Azure AD External Identities
- Entitlement Management with connected organizations (Correct answer)
- Azure AD B2C
Correct answer: Entitlement Management with connected organizations
Entitlement Management with connected organizations allows external partners to request access to resources using their own organizational credentials.
Question 6: Which Azure AD feature periodically reviews and certifies user access to applications and groups to ensure access is still appropriate?
- Access Reviews (Correct answer)
- Entitlement Management
- Identity Governance
- Lifecycle Workflows
Correct answer: Access Reviews
Access Reviews enable periodic certification of user memberships and application assignments to validate that access remains appropriate.
Which Azure AD feature allows you to enforce multi-factor authentication based on user location, device compliance, and application sensitivity?