MS-900 Microsoft 365 Fundamentals Identity and Access Management 3 — Questions and Answers
Question 1: What is the main difference between Azure AD B2B and Azure AD B2C?
- B2B is for consumer apps; B2C is for partner collaboration
- B2B enables collaboration with external partners; B2C is for customer-facing apps (Correct answer)
- B2B requires Premium P2; B2C requires Premium P1
- B2B uses federation; B2C uses password sync only
Correct answer: B2B enables collaboration with external partners; B2C is for customer-facing apps
Azure AD B2B is designed for collaborating with external business partners, while B2C manages identities for customer-facing applications.
Question 2: Which feature in Azure AD allows an administrator to assign a user to an admin role only when needed, rather than permanently?
- Role-Based Access Control (RBAC)
- Just-In-Time (JIT) access via PIM (Correct answer)
- Conditional Access
- Access Reviews
Correct answer: Just-In-Time (JIT) access via PIM
PIM's Just-In-Time access lets users activate privileged roles only when needed for a limited duration.
Question 3: An admin wants to review whether users still need the access they have been granted. Which Azure AD feature supports this?
- Azure AD Identity Protection
- Access Reviews (Correct answer)
- Self-Service Password Reset
- Passwordless Authentication
Correct answer: Access Reviews
Azure AD Access Reviews allow administrators to periodically review and certify user access to groups, applications, and roles.
Question 4: What authentication method does FIDO2 security keys provide in Microsoft 365?
- Password-based authentication with a hardware OTP
- Passwordless authentication using a physical security key (Correct answer)
- Smart card authentication requiring a PIN
- Biometric authentication through Windows Hello only
Correct answer: Passwordless authentication using a physical security key
FIDO2 security keys enable passwordless authentication using a physical hardware key that complies with the FIDO2 standard.
Question 5: Which Azure AD feature provides a report showing users who have not signed in recently or whose credentials may be at risk?
- Azure AD Identity Protection risky users report (Correct answer)
- Azure AD Access Reviews
- Microsoft Secure Score
- Conditional Access named locations
Correct answer: Azure AD Identity Protection risky users report
Azure AD Identity Protection's risky users report identifies accounts flagged due to suspicious activity or leaked credentials.
Question 6: What is the role of a 'Named Location' in Azure AD Conditional Access?
- It defines trusted IP ranges or countries used in access policies (Correct answer)
- It stores the physical office addresses of employees
- It specifies the geographic region where data is stored
- It lists devices approved for corporate use
Correct answer: It defines trusted IP ranges or countries used in access policies
Named Locations define trusted or blocked IP address ranges and countries/regions that can be referenced in Conditional Access policies.
Question 7: Which Microsoft 365 feature enables employees to share files and collaborate with external users who have a Gmail account?
- Azure AD B2C
- Azure AD B2B guest access (Correct answer)
- Azure AD Proxy
- Azure AD Seamless SSO
Correct answer: Azure AD B2B guest access
Azure AD B2B guest access allows external users, including those with non-Microsoft accounts like Gmail, to be invited to collaborate.
What is the main difference between Azure AD B2B and Azure AD B2C?