MS-500 Identity & Access Management 2 — Questions and Answers
Question 1: Which Azure AD license tier is required to use Azure AD Identity Protection?
- Azure AD Free
- Azure AD Premium P1
- Azure AD Premium P2 (Correct answer)
- Microsoft 365 Business Basic
Correct answer: Azure AD Premium P2
Azure AD Identity Protection features, including risk-based Conditional Access and risky user reports, require Azure AD Premium P2 licensing.
Question 2: A user is locked out because of a high-risk sign-in flag. Which action remediates this in Azure AD Identity Protection?
- Reset the user's password and require MFA re-registration (Correct answer)
- Delete and recreate the user account
- Disable the user account temporarily
- Assign a new license to the user
Correct answer: Reset the user's password and require MFA re-registration
Resetting a risky user's password and requiring MFA re-registration dismisses the user risk and restores their access.
Question 3: What does the 'block legacy authentication' Conditional Access policy prevent?
- Users from signing in outside business hours
- Clients using older protocols like SMTP AUTH and Basic Auth that bypass MFA (Correct answer)
- Guest users from accessing SharePoint
- Administrators from using privileged roles
Correct answer: Clients using older protocols like SMTP AUTH and Basic Auth that bypass MFA
Blocking legacy authentication prevents older protocols (IMAP, POP, Basic Auth) from being used, as they cannot enforce MFA.
Question 4: Which role in Azure AD has the least privilege needed to manage Conditional Access policies?
- Global Administrator
- Security Administrator
- Conditional Access Administrator (Correct answer)
- User Administrator
Correct answer: Conditional Access Administrator
The Conditional Access Administrator role is specifically scoped to create and manage Conditional Access policies with minimal additional permissions.
Question 5: An organization uses hybrid identity. Which Azure AD Connect feature provides seamless SSO for domain-joined devices?
- Password Hash Synchronization (PHS)
- Pass-through Authentication (PTA)
- Azure AD Seamless SSO (Correct answer)
- Federation with AD FS
Correct answer: Azure AD Seamless SSO
Azure AD Seamless SSO automatically signs users in on corporate domain-joined devices without requiring them to enter passwords.
Question 6: Which Azure AD feature allows external partners to sign in using their own organizational credentials?
- Azure AD B2C
- Azure AD B2B Collaboration (Correct answer)
- Azure AD Domain Services
- Azure AD Application Proxy
Correct answer: Azure AD B2B Collaboration
Azure AD B2B Collaboration allows external users to authenticate with their home organization's identity provider to access your tenant's resources.
Which Azure AD license tier is required to use Azure AD Identity Protection?