MS-102 Microsoft 365 Administrator Expert Managing Entra ID Authentication 3 — Questions and Answers
Question 1: An administrator wants to block legacy authentication protocols across the tenant to reduce attack surface. Which is the most straightforward method to accomplish this?
- Enable Security Defaults
- Create a Conditional Access policy targeting legacy authentication client apps (Correct answer)
- Disable Basic authentication in Exchange Online only
- Configure Smart Lockout thresholds
Correct answer: Create a Conditional Access policy targeting legacy authentication client apps
A Conditional Access policy that targets the 'Other clients' and legacy authentication app types and blocks access is the recommended granular approach for blocking legacy protocols.
Question 2: A global administrator notices a spike in Entra ID Identity Protection risk detections labeled 'Atypical travel.' What does this detection indicate?
- The user signed in with an expired password
- Two sign-ins occurred from geographically distant locations within an impossible timeframe (Correct answer)
- The user's credentials were found in a known breach database
- The user signed in from a Tor exit node
Correct answer: Two sign-ins occurred from geographically distant locations within an impossible timeframe
Atypical travel detection flags sign-ins from two locations that could not be physically reached within the time elapsed between them, suggesting account compromise.
Question 3: Which Entra ID feature allows administrators to require users to re-verify their identity after a set number of hours, even if they have a valid session token?
- Persistent browser session policy
- Sign-in frequency Conditional Access control (Correct answer)
- Token lifetime policy
- Session risk policy
Correct answer: Sign-in frequency Conditional Access control
The Sign-in Frequency control in Conditional Access forces reauthentication after a configurable time interval, overriding persistent session tokens.
Question 4: An administrator is configuring Entra ID self-service password reset (SSPR). The organization requires users to verify identity with two methods. Which combination is NOT a valid SSPR authentication method?
- Mobile app notification and email
- Security questions and mobile phone SMS
- Hardware OATH token and authenticator app code
- Manager approval and backup email (Correct answer)
Correct answer: Manager approval and backup email
Manager approval is not a supported SSPR authentication method; supported methods include phone, email, authenticator app, security questions, and OATH tokens.
Question 5: A company uses AD FS for federated authentication. The administrator wants to migrate to Entra ID cloud authentication without disrupting users. Which migration approach allows gradual rollout by user group?
- Staged Rollout feature (Correct answer)
- Seamless SSO only
- Password writeback toggle
- Directory synchronization cutover
Correct answer: Staged Rollout feature
The Staged Rollout feature in Entra ID Connect allows selective migration of specific groups from AD FS to PHS or PTA while the rest of the tenant remains federated.
Question 6: Which Entra ID audit log category would an administrator review to track changes to Conditional Access policies?
- SignInLogs
- AuditLogs with category 'Policy' (Correct answer)
- ProvisioningLogs
- RiskyUserLogs
Correct answer: AuditLogs with category 'Policy'
Changes to Conditional Access policies are recorded in AuditLogs under the 'Policy' category, capturing who made changes and what was modified.
Question 7: An administrator configures an Authentication Strength policy in Conditional Access requiring phishing-resistant MFA. Which method satisfies this requirement?
- SMS one-time passcode
- Microsoft Authenticator push notification
- FIDO2 security key (Correct answer)
- Voice call verification
Correct answer: FIDO2 security key
FIDO2 security keys are classified as phishing-resistant because they use cryptographic attestation tied to the specific relying party, preventing credential interception.
An administrator wants to block legacy authentication protocols across the tenant to reduce attack surface.
Which is the most straightforward method to accomplish this?