MS-900 - Microsoft 365 Fundamentals Identity and Access Management Questions and Answers — Questions and Answers
Question 1: A company is planning to implement a hybrid identity solution to synchronize its on-premises Active Directory with Microsoft Entra ID. Which tool is specifically designed for this purpose?
- Azure AD B2C
- Active Directory Federation Services (AD FS)
- Microsoft Entra Connect (Correct answer)
- Microsoft Intune
Correct answer: Microsoft Entra Connect
Microsoft Entra Connect is the Microsoft tool designed to meet and accomplish hybrid identity goals. It provides features like password hash sync, pass-through authentication, and federation integration, which are essential for synchronizing on-premises directories with Microsoft Entra ID.
Question 2: Which of the following BEST describes the principle of 'authentication' in the context of Identity and Access Management?
- Determining the level of access a user has to a specific resource.
- The process of creating and managing user accounts and their permissions.
- Verifying the identity of a user or device to ensure they are who they claim to be. (Correct answer)
- Granting users just-in-time access to administrative roles.
Correct answer: Verifying the identity of a user or device to ensure they are who they claim to be.
Authentication is the process of challenging a user or device for credentials and verifying that they are who they say they are. This is distinct from authorization, which happens after successful authentication and determines what resources the verified user can access.
Question 3: A financial services company wants to enhance its security by requiring employees to provide a second form of verification, such as a code from a mobile app, when accessing sensitive applications. Which Microsoft 365 security feature should they implement?
- Self-Service Password Reset (SSPR)
- Conditional Access
- Microsoft Defender for Identity
- Multi-Factor Authentication (MFA) (Correct answer)
Correct answer: Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds a layer of protection to the sign-in process. When accessing accounts or apps, users provide additional identity verification, such as scanning a fingerprint or entering a code received on their phone.
Question 4: An organization wants to ensure that users can only access Microsoft 365 services from company-managed and compliant devices. Which Microsoft Entra feature allows an administrator to create rules that evaluate specific conditions before granting access?
- Privileged Identity Management (PIM)
- Conditional Access (Correct answer)
- Dynamic Groups
- Microsoft Entra ID Protection
Correct answer: Conditional Access
Conditional Access policies are if-then statements that combine signals, such as user location or device compliance, to make decisions and enforce organizational policies. This allows an administrator to block access or require additional verification if a user is trying to connect from a non-compliant device.
Question 5: What is the primary identity and access management service that underpins all Microsoft 365 services?
- On-premises Active Directory Domain Services (AD DS)
- Microsoft Account
- Microsoft Entra ID (Correct answer)
- Microsoft 365 Defender
Correct answer: Microsoft Entra ID
Microsoft Entra ID (formerly known as Azure Active Directory) is Microsoft's cloud-based identity and access management service. It is the foundational identity provider for Microsoft 365, allowing users to sign in and access various services like Exchange Online, SharePoint Online, and Teams.
Question 6: A user who exists only in Microsoft Entra ID and is not synchronized from an on-premises directory is referred to as what type of identity?
- Federated identity
- Hybrid identity
- Cloud-only identity (Correct answer)
- Guest user identity
Correct answer: Cloud-only identity
A cloud-only identity is a user account that is created and exists exclusively in Microsoft Entra ID. This is in contrast to synchronized or federated identities, which originate in an on-premises Active Directory and are synced to the cloud.
A company is planning to implement a hybrid identity solution to synchronize its on-premises Active Directory with Microsoft Entra ID.
Which tool is specifically designed for this purpose?