MS-900 Microsoft 365 Fundamentals Identity and Access Management 5 — Questions and Answers
Question 1: What is the purpose of Azure AD 'entitlement management'?
- To set password expiration policies for all users
- To automate access package assignments for groups, apps, and SharePoint sites (Correct answer)
- To monitor privileged role activations in real time
- To configure MFA registration requirements
Correct answer: To automate access package assignments for groups, apps, and SharePoint sites
Entitlement management automates access request workflows and lifecycle management for access packages containing resources like groups and apps.
Question 2: Which Azure AD license tier includes features like dynamic groups and self-service group management?
- Azure AD Free
- Microsoft 365 Apps
- Azure AD Premium P1 (Correct answer)
- Azure AD Premium P2
Correct answer: Azure AD Premium P1
Azure AD Premium P1 includes dynamic group membership and self-service group management capabilities.
Question 3: What happens when a Conditional Access policy is set to 'Report-only' mode?
- The policy blocks all access and logs the activity
- The policy is evaluated but does not enforce; results are logged for review (Correct answer)
- The policy only applies to users in the report viewer role
- The policy sends an email report but does not evaluate sign-ins
Correct answer: The policy is evaluated but does not enforce; results are logged for review
Report-only mode evaluates Conditional Access policies and logs what would happen without actually enforcing the outcome, useful for testing.
Question 4: An admin needs to ensure that global administrator accounts are never used for daily tasks and are protected with strict controls. Which best practice aligns with this goal?
- Assign global admin role to all IT staff for convenience
- Use separate, dedicated accounts for admin tasks and enable PIM for just-in-time activation (Correct answer)
- Disable MFA for global admins to avoid login delays
- Share a single global admin account among the IT team
Correct answer: Use separate, dedicated accounts for admin tasks and enable PIM for just-in-time activation
Best practice dictates using dedicated admin accounts (not daily-use accounts) and leveraging PIM for time-limited, just-in-time role activation.
Question 5: Which Microsoft 365 feature enables users to register and manage their own MFA methods through a self-service portal?
- Microsoft Endpoint Manager
- Combined security information registration (Correct answer)
- Azure AD Connect Health
- Microsoft Secure Score
Correct answer: Combined security information registration
Combined security information registration allows users to register MFA and SSPR methods in a single unified portal experience.
Question 6: What is the key difference between 'authentication' and 'authorization' in the context of Microsoft 365 identity?
- Authentication grants resource access; authorization verifies user identity
- Authentication verifies who you are; authorization determines what you can access (Correct answer)
- Authentication uses MFA; authorization uses single-factor
- Authentication applies to admins; authorization applies to regular users
Correct answer: Authentication verifies who you are; authorization determines what you can access
Authentication confirms the user's identity (who you are), while authorization determines what resources and actions that identity is permitted to access.
Question 7: Which Azure AD capability allows an organization to automatically remove a user's access to a group or application after a specified period?
- Conditional Access time-based restrictions
- Access Reviews with auto-apply results (Correct answer)
- PIM role expiration settings
- Azure AD Identity Protection
Correct answer: Access Reviews with auto-apply results
Access Reviews can be configured to automatically apply results, removing access for users who were not re-approved during the review period.
What is the purpose of Azure AD 'entitlement management'?