Microsoft Azure Administrator AZ-104 Microsoft Entra Users and Groups Practice Test 1

 

Topic 01 Practice Test 1 covers Microsoft Entra Users and Groups for Microsoft Azure Administrator AZ-104 and maps to the objective: Manage Microsoft Entra users and groups. For broader exam preparation, review the Microsoft AZ-104 Exam Dumps. Every option includes focused technical reasoning explaining both the Azure concept and its fit to the scenario.

Question 1

Contoso hires a consultant from a partner company for a three-month project. The consultant must use the partner-managed identity to access a Contoso enterprise application. What should the administrator create? Choose ONE.

  1. Invite the person as a Microsoft Entra B2B guest user
  2. Use a security group
  3. Use a Microsoft 365 group
  4. Create a Microsoft Entra member user

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. For Contoso, that directly satisfies the requirement that the external contractor should keep an external identity lifecycle and receive tenant access through invitation.

Incorrect Answers

 

Answer B is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. The Contoso scenario instead requires that the external contractor should keep an external identity lifecycle and receive tenant access through invitation, so this option would leave the key requirement unresolved.

Answer C is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. Applied to Contoso, this does not provide the required behavior because the external contractor should keep an external identity lifecycle and receive tenant access through invitation.

Answer D is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. In Contoso, this is not sufficient because the external contractor should keep an external identity lifecycle and receive tenant access through invitation; the capability addresses a neighboring use case.

 

Question 2

Fabrikam wants partner engineers to sign in with identities managed by their own organization instead of issuing internal workforce accounts. Which Microsoft Entra object approach is best? Choose ONE.

  1. Use a security group
  2. Invite the person as a Microsoft Entra B2B guest user
  3. Use a Microsoft 365 group
  4. Create a Microsoft Entra member user

Correct Answer: B

Correct Answer

 

 

Answer B is correct because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. In Fabrikam, this is the best fit because the external contractor should keep an external identity lifecycle and receive tenant access through invitation.

Incorrect Answers

 

Answer A is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to Fabrikam, this does not provide the required behavior because the external contractor should keep an external identity lifecycle and receive tenant access through invitation.

Answer C is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. The Fabrikam scenario instead requires that the external contractor should keep an external identity lifecycle and receive tenant access through invitation, so this option would leave the key requirement unresolved.

Answer D is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. For Fabrikam, that does not satisfy the requirement that the external contractor should keep an external identity lifecycle and receive tenant access through invitation; it solves a different administrative need.

 

Question 3

Northwind hires a full-time administrator whose sign-in account and lifecycle must be managed entirely by Northwind. Which identity should be created? Choose ONE.

  1. Manage the external user object after invitation redemption
  2. Use a security group
  3. Create a Microsoft Entra member user
  4. Invite the person as a Microsoft Entra B2B guest user

Correct Answer: C

Correct Answer

 

 

Answer C is correct because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. The the northwind hires a full-time case scenario specifically requires that the new employee is an internal workforce identity owned and managed by the tenant, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because An invited external identity remains represented by a user object in the tenant, so administrators can manage its properties and group/app access after redemption. In the northwind hires a full-time case, this is not sufficient because the new employee is an internal workforce identity owned and managed by the tenant; the capability addresses a neighboring use case.

Answer B is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For the northwind hires a full-time case, that does not satisfy the requirement that the new employee is an internal workforce identity owned and managed by the tenant; it solves a different administrative need.

Answer D is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. Applied to the northwind hires a full-time case, this does not provide the required behavior because the new employee is an internal workforce identity owned and managed by the tenant.

 

Question 4

Adventure Works is replacing a contractor with a permanent employee and wants the employee account treated as an internal workforce identity. Which account type should it provision? Choose ONE.

  1. Use a security group
  2. Manage the external user object after invitation redemption
  3. Invite the person as a Microsoft Entra B2B guest user
  4. Create a Microsoft Entra member user

Correct Answer: D

Correct Answer

 

 

Answer D is correct because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to Adventure Works, the capability meets the requirement that the new employee is an internal workforce identity owned and managed by the tenant without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. In Adventure Works, this is not sufficient because the new employee is an internal workforce identity owned and managed by the tenant; the capability addresses a neighboring use case.

Answer B is incorrect because An invited external identity remains represented by a user object in the tenant, so administrators can manage its properties and group/app access after redemption. For Adventure Works, that does not satisfy the requirement that the new employee is an internal workforce identity owned and managed by the tenant; it solves a different administrative need.

Answer C is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. The Adventure Works scenario instead requires that the new employee is an internal workforce identity owned and managed by the tenant, so this option would leave the key requirement unresolved.

 

Question 5

Tailspin wants every user whose department attribute equals Finance to join an access group automatically and leave it when the attribute changes. What should be configured? Choose ONE.

  1. Use a dynamic user security group
  2. Use a security group
  3. Use an assigned-membership group and add the required identities explicitly
  4. Use a Microsoft 365 group

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. For the tailspin wants every user case, that directly satisfies the requirement that group membership must automatically follow a user attribute that changes in Microsoft Entra ID.

Incorrect Answers

 

Answer B is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. The the tailspin wants every user case scenario instead requires that group membership must automatically follow a user attribute that changes in Microsoft Entra ID, so this option would leave the key requirement unresolved.

Answer C is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. In the tailspin wants every user case, this is not sufficient because group membership must automatically follow a user attribute that changes in Microsoft Entra ID; the capability addresses a neighboring use case.

Answer D is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. Applied to the tailspin wants every user case, this does not provide the required behavior because group membership must automatically follow a user attribute that changes in Microsoft Entra ID.

 

Question 6

Woodgrove reorganizes staff frequently and wants an access group to recalculate membership from each user’s job-related directory attributes. Which group membership model should it use? Choose ONE.

  1. Use an assigned-membership group and add the required identities explicitly
  2. Use a dynamic user security group
  3. Use a security group
  4. Use a Microsoft 365 group

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. In the woodgrove reorganizes staff frequently case, this is the best fit because group membership must automatically follow a user attribute that changes in Microsoft Entra ID.

Incorrect Answers

 

Answer A is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. For the woodgrove reorganizes staff frequently case, that does not satisfy the requirement that group membership must automatically follow a user attribute that changes in Microsoft Entra ID; it solves a different administrative need.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to the woodgrove reorganizes staff frequently case, this does not provide the required behavior because group membership must automatically follow a user attribute that changes in Microsoft Entra ID.

Answer D is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. The the woodgrove reorganizes staff frequently case scenario instead requires that group membership must automatically follow a user attribute that changes in Microsoft Entra ID, so this option would leave the key requirement unresolved.

 

Question 7

Proseware needs a security group that automatically contains corporate Windows devices matching a device rule. Which group should it create? Choose ONE.

  1. Use an assigned-membership group and add the required identities explicitly
  2. Use a dynamic user security group
  3. Use a dynamic device security group
  4. Use a security group

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. The Proseware scenario specifically requires that membership must be calculated automatically from device attributes rather than user attributes, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. Applied to Proseware, this does not provide the required behavior because membership must be calculated automatically from device attributes rather than user attributes.

Answer B is incorrect because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. For Proseware, that does not satisfy the requirement that membership must be calculated automatically from device attributes rather than user attributes; it solves a different administrative need.

Answer D is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. In Proseware, this is not sufficient because membership must be calculated automatically from device attributes rather than user attributes; the capability addresses a neighboring use case.

 

Question 8

Litware wants devices to enter or leave a deployment group automatically when their registered device properties change. What membership type is appropriate? Choose ONE.

  1. Use a dynamic user security group
  2. Use an assigned-membership group and add the required identities explicitly
  3. Use a security group
  4. Use a dynamic device security group

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. Applied to Litware, the capability meets the requirement that membership must be calculated automatically from device attributes rather than user attributes without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. In Litware, this is not sufficient because membership must be calculated automatically from device attributes rather than user attributes; the capability addresses a neighboring use case.

Answer B is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. The Litware scenario instead requires that membership must be calculated automatically from device attributes rather than user attributes, so this option would leave the key requirement unresolved.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For Litware, that does not satisfy the requirement that membership must be calculated automatically from device attributes rather than user attributes; it solves a different administrative need.

 

Question 9

Wingtip needs one group to grant an application permission to 300 employees. The group does not need a shared mailbox or SharePoint site. Which group type is the best fit? Choose ONE.

  1. Use a security group
  2. Invite the person as a Microsoft Entra B2B guest user
  3. Use a Microsoft 365 group
  4. Create a Microsoft Entra member user

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For the wingtip needs one group case, that directly satisfies the requirement that the group is needed primarily to assign permissions rather than provide a collaboration workspace.

Incorrect Answers

 

Answer B is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. The the wingtip needs one group case scenario instead requires that the group is needed primarily to assign permissions rather than provide a collaboration workspace, so this option would leave the key requirement unresolved.

Answer C is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. In the wingtip needs one group case, this is not sufficient because the group is needed primarily to assign permissions rather than provide a collaboration workspace; the capability addresses a neighboring use case.

Answer D is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to the wingtip needs one group case, this does not provide the required behavior because the group is needed primarily to assign permissions rather than provide a collaboration workspace.

 

Question 10

A company is rolling out dynamic user groups. Which TWO conditions should the administrator verify for a reliable design? Choose TWO.

  1. Use a Microsoft 365 group
  2. Use a dynamic user security group
  3. Assign the product license directly to each user
  4. Use an assigned-membership group and add the required identities explicitly
  5. Ensure each user covered by dynamic membership has the required Microsoft Entra ID P1 licensing

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. In the a company is rolling case, this is the best fit because dynamic membership must be attribute-driven and the affected users must meet the licensing requirement.

Answer E is correct because Dynamic membership groups require appropriate Microsoft Entra licensing for the unique users who benefit from the dynamic group capability. The the a company is rolling case scenario specifically requires that dynamic membership must be attribute-driven and the affected users must meet the licensing requirement, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. For the a company is rolling case, that does not satisfy the requirement that dynamic membership must be attribute-driven and the affected users must meet the licensing requirement; it solves a different administrative need.

Answer C is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. In the a company is rolling case, this is not sufficient because dynamic membership must be attribute-driven and the affected users must meet the licensing requirement; the capability addresses a neighboring use case.

Answer D is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. Applied to the a company is rolling case, this does not provide the required behavior because dynamic membership must be attribute-driven and the affected users must meet the licensing requirement.

 

Question 11

  1. Datum is creating an Azure access group whose only purpose is authorization. Collaboration resources are explicitly unwanted. Which group type should the administrator choose? Choose ONE.
  2. Use a Microsoft 365 group
  3. Create a Microsoft Entra member user
  4. Use a security group
  5. Invite the person as a Microsoft Entra B2B guest user

Correct Answer: C

Correct Answer

 

 

Answer C is correct because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. The A. Datum scenario specifically requires that the group is needed primarily to assign permissions rather than provide a collaboration workspace, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. In A. Datum, this is not sufficient because the group is needed primarily to assign permissions rather than provide a collaboration workspace; the capability addresses a neighboring use case.

Answer B is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to A. Datum, this does not provide the required behavior because the group is needed primarily to assign permissions rather than provide a collaboration workspace.

Answer D is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. For A. Datum, that does not satisfy the requirement that the group is needed primarily to assign permissions rather than provide a collaboration workspace; it solves a different administrative need.

 

Question 12

Contoso creates a project team that needs shared collaboration services such as a group mailbox and SharePoint-backed workspace. Which group type is appropriate? Choose ONE.

  1. Use an assigned-membership group and add the required identities explicitly
  2. Use a dynamic device security group
  3. Use a security group
  4. Use a Microsoft 365 group

Correct Answer: D

Correct Answer

 

 

Answer D is correct because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. Applied to Contoso, the capability meets the requirement that the team requires collaboration resources in addition to membership management without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. The Contoso scenario instead requires that the team requires collaboration resources in addition to membership management, so this option would leave the key requirement unresolved.

Answer B is incorrect because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. In Contoso, this is not sufficient because the team requires collaboration resources in addition to membership management; the capability addresses a neighboring use case.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For Contoso, that does not satisfy the requirement that the team requires collaboration resources in addition to membership management; it solves a different administrative need.

 

Question 13

Fabrikam wants a group whose members collaborate through Microsoft 365 services rather than using the group only as an authorization principal. Which choice best fits? Choose ONE.

  1. Use a Microsoft 365 group
  2. Use a dynamic device security group
  3. Use a security group
  4. Use an assigned-membership group and add the required identities explicitly

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. For Fabrikam, that directly satisfies the requirement that the team requires collaboration resources in addition to membership management.

Incorrect Answers

 

Answer B is incorrect because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. The Fabrikam scenario instead requires that the team requires collaboration resources in addition to membership management, so this option would leave the key requirement unresolved.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to Fabrikam, this does not provide the required behavior because the team requires collaboration resources in addition to membership management.

Answer D is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. In Fabrikam, this is not sufficient because the team requires collaboration resources in addition to membership management; the capability addresses a neighboring use case.

 

Question 14

Northwind licenses 800 sales users and wants new direct members of the Sales-Licensed group to receive the product automatically. What should the administrator configure? Choose ONE.

  1. Assign the product license directly to each user
  2. Assign the product license to an eligible Microsoft Entra group
  3. Use a security group
  4. Update the Microsoft Entra user or group properties in the directory

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. In the northwind licenses 800 sales case, this is the best fit because licenses must automatically follow direct group membership at scale.

Incorrect Answers

 

Answer A is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. The the northwind licenses 800 sales case scenario instead requires that licenses must automatically follow direct group membership at scale, so this option would leave the key requirement unresolved.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to the northwind licenses 800 sales case, this does not provide the required behavior because licenses must automatically follow direct group membership at scale.

Answer D is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. For the northwind licenses 800 sales case, that does not satisfy the requirement that licenses must automatically follow direct group membership at scale; it solves a different administrative need.

 

Question 15

Adventure Works wants product licenses removed automatically when users leave a designated licensing group. Which licensing approach meets the requirement with the least manual work? Choose ONE.

  1. Use a security group
  2. Assign the product license directly to each user
  3. Assign the product license to an eligible Microsoft Entra group
  4. Update the Microsoft Entra user or group properties in the directory

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. The Adventure Works scenario specifically requires that licenses must automatically follow direct group membership at scale, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For Adventure Works, that does not satisfy the requirement that licenses must automatically follow direct group membership at scale; it solves a different administrative need.

Answer B is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. In Adventure Works, this is not sufficient because licenses must automatically follow direct group membership at scale; the capability addresses a neighboring use case.

Answer D is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. Applied to Adventure Works, this does not provide the required behavior because licenses must automatically follow direct group membership at scale.

 

Question 16

Tailspin has a single temporary user who needs one product license for a short exception and should not inherit the license from a broader group. What should the administrator do? Choose ONE.

  1. Use direct user membership in the licensed group rather than relying on a nested group
  2. Use a Microsoft 365 group
  3. Assign the product license to an eligible Microsoft Entra group
  4. Assign the product license directly to each user

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. Applied to the tailspin has a single case, the capability meets the requirement that a one-off license must be applied only to one named user without tying the assignment to group membership without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Group-based licensing does not process nested group membership as license inheritance; users must be direct members of the group receiving the license. In the tailspin has a single case, this is not sufficient because a one-off license must be applied only to one named user without tying the assignment to group membership; the capability addresses a neighboring use case.

Answer B is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. The the tailspin has a single case scenario instead requires that a one-off license must be applied only to one named user without tying the assignment to group membership, so this option would leave the key requirement unresolved.

Answer C is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. For the tailspin has a single case, that does not satisfy the requirement that a one-off license must be applied only to one named user without tying the assignment to group membership; it solves a different administrative need.

 

Question 17

Woodgrove must license one executive immediately while leaving all group-based license assignments unchanged. Which action is most direct? Choose ONE.

  1. Assign the product license directly to each user
  2. Assign the product license to an eligible Microsoft Entra group
  3. Use direct user membership in the licensed group rather than relying on a nested group
  4. Use a Microsoft 365 group

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. For the woodgrove must license one case, that directly satisfies the requirement that a one-off license must be applied only to one named user without tying the assignment to group membership.

Incorrect Answers

 

Answer B is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. Applied to the woodgrove must license one case, this does not provide the required behavior because a one-off license must be applied only to one named user without tying the assignment to group membership.

Answer C is incorrect because Group-based licensing does not process nested group membership as license inheritance; users must be direct members of the group receiving the license. The the woodgrove must license one case scenario instead requires that a one-off license must be applied only to one named user without tying the assignment to group membership, so this option would leave the key requirement unresolved.

Answer D is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. In the woodgrove must license one case, this is not sufficient because a one-off license must be applied only to one named user without tying the assignment to group membership; the capability addresses a neighboring use case.

 

Question 18

Proseware is piloting self-service password reset with only the Helpdesk-Pilot group before a company-wide rollout. Which SSPR setting should it use? Choose ONE.

  1. Use an account with at least the Authentication Policy Administrator role
  2. Enable SSPR for Selected and choose the pilot group
  3. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  4. Enable SSPR for All users

Correct Answer: B

Correct Answer

 

 

Answer B is correct because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. In Proseware, this is the best fit because self-service password reset must be limited to the defined pilot population.

Incorrect Answers

 

Answer A is incorrect because Configuring SSPR requires an appropriate Microsoft Entra role; Authentication Policy Administrator is sufficient for the SSPR configuration task. Applied to Proseware, this does not provide the required behavior because self-service password reset must be limited to the defined pilot population.

Answer C is incorrect because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. For Proseware, that does not satisfy the requirement that self-service password reset must be limited to the defined pilot population; it solves a different administrative need.

Answer D is incorrect because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. The Proseware scenario instead requires that self-service password reset must be limited to the defined pilot population, so this option would leave the key requirement unresolved.

 

Question 19

Litware wants 50 test users to use SSPR while every other user remains excluded during validation. Which configuration meets that requirement? Choose ONE.

  1. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  2. Use an account with at least the Authentication Policy Administrator role
  3. Enable SSPR for Selected and choose the pilot group
  4. Enable SSPR for All users

Correct Answer: C

Correct Answer

 

 

Answer C is correct because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. The Litware scenario specifically requires that self-service password reset must be limited to the defined pilot population, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. Applied to Litware, this does not provide the required behavior because self-service password reset must be limited to the defined pilot population.

Answer B is incorrect because Configuring SSPR requires an appropriate Microsoft Entra role; Authentication Policy Administrator is sufficient for the SSPR configuration task. For Litware, that does not satisfy the requirement that self-service password reset must be limited to the defined pilot population; it solves a different administrative need.

Answer D is incorrect because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. In Litware, this is not sufficient because self-service password reset must be limited to the defined pilot population; the capability addresses a neighboring use case.

 

Question 20

A staged SSPR rollout is failing for pilot users. Which TWO configuration areas are the most important first checks? Choose TWO.

  1. Create a Microsoft Entra member user
  2. Enable SSPR for Selected and choose the pilot group
  3. Assign a group owner to manage the group membership
  4. Enable SSPR for All users
  5. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. Applied to the a staged sspr rollout case, the capability meets the requirement that the pilot population must be selected for SSPR and the users must have appropriate licensing without adding unrelated scope.

Answer E is correct because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. For the a staged sspr rollout case, that directly satisfies the requirement that the pilot population must be selected for SSPR and the users must have appropriate licensing.

Incorrect Answers

 

Answer A is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to the a staged sspr rollout case, this does not provide the required behavior because the pilot population must be selected for SSPR and the users must have appropriate licensing.

Answer C is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. The the a staged sspr rollout case scenario instead requires that the pilot population must be selected for SSPR and the users must have appropriate licensing, so this option would leave the key requirement unresolved.

Answer D is incorrect because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. In the a staged sspr rollout case, this is not sufficient because the pilot population must be selected for SSPR and the users must have appropriate licensing; the capability addresses a neighboring use case.

 

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!