Microsoft Azure Administrator AZ-104 Microsoft Entra Users and Groups Practice Test 2

 

Topic 01 Practice Test 2 covers Microsoft Entra Users and Groups for Microsoft Azure Administrator AZ-104 and maps to the objective: Manage Microsoft Entra users and groups. For broader exam preparation, review the Microsoft AZ-104 Exam Dumps. Every option includes focused technical reasoning explaining both the Azure concept and its fit to the scenario.

Question 1

Wingtip has completed its SSPR pilot and now wants every eligible user in the tenant to reset passwords without helpdesk assistance. What should it configure? Choose ONE.

  1. Enable SSPR for All users
  2. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  3. Enable SSPR for Selected and choose the pilot group
  4. Assign a group owner to manage the group membership

Correct Answer: A

Correct Answer

 

 

Answer A is correct because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. In the wingtip has completed its case, this is the best fit because all eligible users in the tenant should be enabled for self-service password reset.

Incorrect Answers

 

Answer B is incorrect because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. For the wingtip has completed its case, that does not satisfy the requirement that all eligible users in the tenant should be enabled for self-service password reset; it solves a different administrative need.

Answer C is incorrect because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. The the wingtip has completed its case scenario instead requires that all eligible users in the tenant should be enabled for self-service password reset, so this option would leave the key requirement unresolved.

Answer D is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. Applied to the wingtip has completed its case, this does not provide the required behavior because all eligible users in the tenant should be enabled for self-service password reset.

 

Question 2

  1. Datum no longer needs a limited SSPR pilot and wants tenant-wide enablement for eligible users. Which SSPR scope should be selected? Choose ONE.
  2. Assign a group owner to manage the group membership
  3. Enable SSPR for All users
  4. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  5. Enable SSPR for Selected and choose the pilot group

Correct Answer: B

Correct Answer

 

 

Answer B is correct because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. The A. Datum scenario specifically requires that all eligible users in the tenant should be enabled for self-service password reset, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. For A. Datum, that does not satisfy the requirement that all eligible users in the tenant should be enabled for self-service password reset; it solves a different administrative need.

Answer C is incorrect because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. Applied to A. Datum, this does not provide the required behavior because all eligible users in the tenant should be enabled for self-service password reset.

Answer D is incorrect because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. In A. Datum, this is not sufficient because all eligible users in the tenant should be enabled for self-service password reset; the capability addresses a neighboring use case.

 

Question 3

Contoso delegates SSPR configuration to a junior identity administrator but wants to avoid Global Administrator. Which role level is sufficient for the task? Choose ONE.

  1. Create a Microsoft Entra member user
  2. Update the Microsoft Entra user or group properties in the directory
  3. Use an account with at least the Authentication Policy Administrator role
  4. Assign a group owner to manage the group membership

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Configuring SSPR requires an appropriate Microsoft Entra role; Authentication Policy Administrator is sufficient for the SSPR configuration task. Applied to Contoso, the capability meets the requirement that the operator needs sufficient Microsoft Entra privilege to configure SSPR settings without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. The Contoso scenario instead requires that the operator needs sufficient Microsoft Entra privilege to configure SSPR settings, so this option would leave the key requirement unresolved.

Answer B is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. In Contoso, this is not sufficient because the operator needs sufficient Microsoft Entra privilege to configure SSPR settings; the capability addresses a neighboring use case.

Answer D is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. For Contoso, that does not satisfy the requirement that the operator needs sufficient Microsoft Entra privilege to configure SSPR settings; it solves a different administrative need.

 

Question 4

Fabrikam needs an administrator to enable and tune self-service password reset without granting broad tenant-wide administrative control. Which role is the best match? Choose ONE.

  1. Update the Microsoft Entra user or group properties in the directory
  2. Create a Microsoft Entra member user
  3. Assign a group owner to manage the group membership
  4. Use an account with at least the Authentication Policy Administrator role

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Configuring SSPR requires an appropriate Microsoft Entra role; Authentication Policy Administrator is sufficient for the SSPR configuration task. For Fabrikam, that directly satisfies the requirement that the operator needs sufficient Microsoft Entra privilege to configure SSPR settings.

Incorrect Answers

 

Answer A is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. The Fabrikam scenario instead requires that the operator needs sufficient Microsoft Entra privilege to configure SSPR settings, so this option would leave the key requirement unresolved.

Answer B is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. In Fabrikam, this is not sufficient because the operator needs sufficient Microsoft Entra privilege to configure SSPR settings; the capability addresses a neighboring use case.

Answer C is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. Applied to Fabrikam, this does not provide the required behavior because the operator needs sufficient Microsoft Entra privilege to configure SSPR settings.

 

Question 5

Northwind wants the Marketing manager to add and remove members from one assigned group without granting a tenant-wide identity administrator role. What should Northwind configure? Choose ONE.

  1. Assign a group owner to manage the group membership
  2. Use a security group
  3. Update the Microsoft Entra user or group properties in the directory
  4. Use an assigned-membership group and add the required identities explicitly

Correct Answer: A

Correct Answer

 

 

Answer A is correct because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. In the northwind wants the marketing case, this is the best fit because routine membership management should be delegated to a person responsible for that specific group.

Incorrect Answers

 

Answer B is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. For the northwind wants the marketing case, that does not satisfy the requirement that routine membership management should be delegated to a person responsible for that specific group; it solves a different administrative need.

Answer C is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. The the northwind wants the marketing case scenario instead requires that routine membership management should be delegated to a person responsible for that specific group, so this option would leave the key requirement unresolved.

Answer D is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. Applied to the northwind wants the marketing case, this does not provide the required behavior because routine membership management should be delegated to a person responsible for that specific group.

 

Question 6

Adventure Works wants a team lead to maintain the membership of a specific project group while central admins retain overall directory control. Which action is best? Choose ONE.

  1. Use a security group
  2. Assign a group owner to manage the group membership
  3. Update the Microsoft Entra user or group properties in the directory
  4. Use an assigned-membership group and add the required identities explicitly

Correct Answer: B

Correct Answer

 

 

Answer B is correct because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. The Adventure Works scenario specifically requires that routine membership management should be delegated to a person responsible for that specific group, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to Adventure Works, this does not provide the required behavior because routine membership management should be delegated to a person responsible for that specific group.

Answer C is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. In Adventure Works, this is not sufficient because routine membership management should be delegated to a person responsible for that specific group; the capability addresses a neighboring use case.

Answer D is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. For Adventure Works, that does not satisfy the requirement that routine membership management should be delegated to a person responsible for that specific group; it solves a different administrative need.

 

Question 7

Tailspin creates several dynamic user groups, but some included users do not have the required Microsoft Entra license. What should the administrator correct? Choose ONE.

  1. Assign the product license directly to each user
  2. Assign a group owner to manage the group membership
  3. Ensure each user covered by dynamic membership has the required Microsoft Entra ID P1 licensing
  4. Use an assigned-membership group and add the required identities explicitly

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Dynamic membership groups require appropriate Microsoft Entra licensing for the unique users who benefit from the dynamic group capability. Applied to the tailspin creates several dynamic case, the capability meets the requirement that users benefiting from dynamic group membership must satisfy the licensing requirement for that capability without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. In the tailspin creates several dynamic case, this is not sufficient because users benefiting from dynamic group membership must satisfy the licensing requirement for that capability; the capability addresses a neighboring use case.

Answer B is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. The the tailspin creates several dynamic case scenario instead requires that users benefiting from dynamic group membership must satisfy the licensing requirement for that capability, so this option would leave the key requirement unresolved.

Answer D is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. For the tailspin creates several dynamic case, that does not satisfy the requirement that users benefiting from dynamic group membership must satisfy the licensing requirement for that capability; it solves a different administrative need.

 

Question 8

Woodgrove plans to replace assigned groups with dynamic membership rules for hundreds of users. Which prerequisite must be validated for the affected users? Choose ONE.

  1. Assign a group owner to manage the group membership
  2. Use an assigned-membership group and add the required identities explicitly
  3. Assign the product license directly to each user
  4. Ensure each user covered by dynamic membership has the required Microsoft Entra ID P1 licensing

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Dynamic membership groups require appropriate Microsoft Entra licensing for the unique users who benefit from the dynamic group capability. For the woodgrove plans to replace case, that directly satisfies the requirement that users benefiting from dynamic group membership must satisfy the licensing requirement for that capability.

Incorrect Answers

 

Answer A is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. In the woodgrove plans to replace case, this is not sufficient because users benefiting from dynamic group membership must satisfy the licensing requirement for that capability; the capability addresses a neighboring use case.

Answer B is incorrect because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. Applied to the woodgrove plans to replace case, this does not provide the required behavior because users benefiting from dynamic group membership must satisfy the licensing requirement for that capability.

Answer C is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. The the woodgrove plans to replace case scenario instead requires that users benefiting from dynamic group membership must satisfy the licensing requirement for that capability, so this option would leave the key requirement unresolved.

 

Question 9

Proseware has an existing guest who already redeemed an invitation. The administrator must update the guest’s group memberships and directory properties. What should be managed? Choose ONE.

  1. Manage the external user object after invitation redemption
  2. Update the Microsoft Entra user or group properties in the directory
  3. Create a Microsoft Entra member user
  4. Invite the person as a Microsoft Entra B2B guest user

Correct Answer: A

Correct Answer

 

 

Answer A is correct because An invited external identity remains represented by a user object in the tenant, so administrators can manage its properties and group/app access after redemption. In Proseware, this is the best fit because an already invited external identity needs its directory object properties or access relationships managed after redemption.

Incorrect Answers

 

Answer B is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. For Proseware, that does not satisfy the requirement that an already invited external identity needs its directory object properties or access relationships managed after redemption; it solves a different administrative need.

Answer C is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to Proseware, this does not provide the required behavior because an already invited external identity needs its directory object properties or access relationships managed after redemption.

Answer D is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. The Proseware scenario instead requires that an already invited external identity needs its directory object properties or access relationships managed after redemption, so this option would leave the key requirement unresolved.

 

Question 10

An organization wants external consultants to retain partner identities and then be managed in tenant groups after joining. Which TWO actions support that lifecycle? Choose TWO.

  1. Assign the product license directly to each user
  2. Invite the person as a Microsoft Entra B2B guest user
  3. Use a dynamic device security group
  4. Create a Microsoft Entra member user
  5. Manage the external user object after invitation redemption

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. The the an organization wants external case scenario specifically requires that the users must enter as external guest identities and their tenant user objects must remain manageable after redemption, so this choice matches the intended behavior.

Answer E is correct because An invited external identity remains represented by a user object in the tenant, so administrators can manage its properties and group/app access after redemption. Applied to the an organization wants external case, the capability meets the requirement that the users must enter as external guest identities and their tenant user objects must remain manageable after redemption without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. In the an organization wants external case, this is not sufficient because the users must enter as external guest identities and their tenant user objects must remain manageable after redemption; the capability addresses a neighboring use case.

Answer C is incorrect because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. The the an organization wants external case scenario instead requires that the users must enter as external guest identities and their tenant user objects must remain manageable after redemption, so this option would leave the key requirement unresolved.

Answer D is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. For the an organization wants external case, that does not satisfy the requirement that the users must enter as external guest identities and their tenant user objects must remain manageable after redemption; it solves a different administrative need.

 

Question 11

Litware needs to change access-related properties for an external user who has already joined the tenant. Which object should the administrator manage? Choose ONE.

  1. Update the Microsoft Entra user or group properties in the directory
  2. Create a Microsoft Entra member user
  3. Manage the external user object after invitation redemption
  4. Invite the person as a Microsoft Entra B2B guest user

Correct Answer: C

Correct Answer

 

 

Answer C is correct because An invited external identity remains represented by a user object in the tenant, so administrators can manage its properties and group/app access after redemption. Applied to Litware, the capability meets the requirement that an already invited external identity needs its directory object properties or access relationships managed after redemption without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. For Litware, that does not satisfy the requirement that an already invited external identity needs its directory object properties or access relationships managed after redemption; it solves a different administrative need.

Answer B is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. In Litware, this is not sufficient because an already invited external identity needs its directory object properties or access relationships managed after redemption; the capability addresses a neighboring use case.

Answer D is incorrect because A B2B guest represents an external identity in the tenant and can redeem an invitation while retaining an external identity lifecycle. The Litware scenario instead requires that an already invited external identity needs its directory object properties or access relationships managed after redemption, so this option would leave the key requirement unresolved.

 

Question 12

Wingtip assigns a product license to ParentGroup and nests SalesGroup inside it, but SalesGroup users do not receive the license. What should the administrator change? Choose ONE.

  1. Use a Microsoft 365 group
  2. Assign the product license directly to each user
  3. Assign the product license to an eligible Microsoft Entra group
  4. Use direct user membership in the licensed group rather than relying on a nested group

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Group-based licensing does not process nested group membership as license inheritance; users must be direct members of the group receiving the license. For the wingtip assigns a product case, that directly satisfies the requirement that users in a nested child group must actually receive licenses from the licensing design.

Incorrect Answers

 

Answer A is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. Applied to the wingtip assigns a product case, this does not provide the required behavior because users in a nested child group must actually receive licenses from the licensing design.

Answer B is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. The the wingtip assigns a product case scenario instead requires that users in a nested child group must actually receive licenses from the licensing design, so this option would leave the key requirement unresolved.

Answer C is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. In the wingtip assigns a product case, this is not sufficient because users in a nested child group must actually receive licenses from the licensing design; the capability addresses a neighboring use case.

 

Question 13

  1. Datum expects nested group members to inherit a license assigned to the parent group, but licensing is not occurring. Which design change resolves the issue? Choose ONE.
  2. Use direct user membership in the licensed group rather than relying on a nested group
  3. Use a Microsoft 365 group
  4. Assign the product license to an eligible Microsoft Entra group
  5. Assign the product license directly to each user

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Group-based licensing does not process nested group membership as license inheritance; users must be direct members of the group receiving the license. In A. Datum, this is the best fit because users in a nested child group must actually receive licenses from the licensing design.

Incorrect Answers

 

Answer B is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. The A. Datum scenario instead requires that users in a nested child group must actually receive licenses from the licensing design, so this option would leave the key requirement unresolved.

Answer C is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. For A. Datum, that does not satisfy the requirement that users in a nested child group must actually receive licenses from the licensing design; it solves a different administrative need.

Answer D is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. Applied to A. Datum, this does not provide the required behavior because users in a nested child group must actually receive licenses from the licensing design.

 

Question 14

Contoso enables SSPR for a pilot group, but an included user receives a message that the feature is not enabled for the account. The group scope is correct. What should be checked next? Choose ONE.

  1. Enable SSPR for Selected and choose the pilot group
  2. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  3. Enable SSPR for All users
  4. Assign the product license directly to each user

Correct Answer: B

Correct Answer

 

 

Answer B is correct because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. The Contoso scenario specifically requires that the users enabled for SSPR also need the appropriate feature licensing, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. Applied to Contoso, this does not provide the required behavior because the users enabled for SSPR also need the appropriate feature licensing.

Answer C is incorrect because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. For Contoso, that does not satisfy the requirement that the users enabled for SSPR also need the appropriate feature licensing; it solves a different administrative need.

Answer D is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. In Contoso, this is not sufficient because the users enabled for SSPR also need the appropriate feature licensing; the capability addresses a neighboring use case.

 

Question 15

Fabrikam has correctly selected an SSPR test group, yet several pilot users cannot use the feature. Which prerequisite should the administrator verify? Choose ONE.

  1. Enable SSPR for All users
  2. Assign the product license directly to each user
  3. Assign appropriate Microsoft Entra licensing to the users included in the SSPR pilot
  4. Enable SSPR for Selected and choose the pilot group

Correct Answer: C

Correct Answer

 

 

Answer C is correct because SSPR capabilities require appropriate licensing for the users who use the feature; enabling a group alone does not satisfy licensing prerequisites. Applied to Fabrikam, the capability meets the requirement that the users enabled for SSPR also need the appropriate feature licensing without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because The All setting enables self-service password reset tenant-wide for eligible users and is appropriate after a successful staged rollout. In Fabrikam, this is not sufficient because the users enabled for SSPR also need the appropriate feature licensing; the capability addresses a neighboring use case.

Answer B is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. For Fabrikam, that does not satisfy the requirement that the users enabled for SSPR also need the appropriate feature licensing; it solves a different administrative need.

Answer D is incorrect because The Selected setting limits self-service password reset to the chosen group, which is appropriate for a staged rollout or pilot. The Fabrikam scenario instead requires that the users enabled for SSPR also need the appropriate feature licensing, so this option would leave the key requirement unresolved.

 

Question 16

Northwind needs to update an existing employee’s display name and other Microsoft Entra user attributes after a legal name change. Which action should it take? Choose ONE.

  1. Assign a group owner to manage the group membership
  2. Use a security group
  3. Create a Microsoft Entra member user
  4. Update the Microsoft Entra user or group properties in the directory

Correct Answer: D

Correct Answer

 

 

Answer D is correct because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. For the northwind needs to update case, that directly satisfies the requirement that an existing directory object attribute must be changed rather than access or licensing behavior.

Incorrect Answers

 

Answer A is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. In the northwind needs to update case, this is not sufficient because an existing directory object attribute must be changed rather than access or licensing behavior; the capability addresses a neighboring use case.

Answer B is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. Applied to the northwind needs to update case, this does not provide the required behavior because an existing directory object attribute must be changed rather than access or licensing behavior.

Answer C is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. The the northwind needs to update case scenario instead requires that an existing directory object attribute must be changed rather than access or licensing behavior, so this option would leave the key requirement unresolved.

 

Question 17

Adventure Works changes the description and owner metadata for an existing group but does not want to alter Azure resource permissions. Which administrative area should be used? Choose ONE.

  1. Update the Microsoft Entra user or group properties in the directory
  2. Create a Microsoft Entra member user
  3. Use a security group
  4. Assign a group owner to manage the group membership

Correct Answer: A

Correct Answer

 

 

Answer A is correct because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. In Adventure Works, this is the best fit because an existing directory object attribute must be changed rather than access or licensing behavior.

Incorrect Answers

 

Answer B is incorrect because A member user is appropriate for an internal workforce identity whose account lifecycle is owned by the tenant. Applied to Adventure Works, this does not provide the required behavior because an existing directory object attribute must be changed rather than access or licensing behavior.

Answer C is incorrect because A security group is designed to group identities for permissions and access-control scenarios, without the collaboration resources of a Microsoft 365 group. The Adventure Works scenario instead requires that an existing directory object attribute must be changed rather than access or licensing behavior, so this option would leave the key requirement unresolved.

Answer D is incorrect because A group owner can manage group membership for the groups they own, reducing routine membership administration by central identity administrators. For Adventure Works, that does not satisfy the requirement that an existing directory object attribute must be changed rather than access or licensing behavior; it solves a different administrative need.

 

Question 18

Tailspin has a highly sensitive group whose membership must be approved and entered explicitly by administrators. Attribute-based automatic membership is prohibited. Which membership model should it use? Choose ONE.

  1. Use a dynamic device security group
  2. Use an assigned-membership group and add the required identities explicitly
  3. Assign the product license to an eligible Microsoft Entra group
  4. Use a dynamic user security group

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. The the tailspin has a highly case scenario specifically requires that membership must remain a manually curated list that does not change when directory attributes change, so this choice matches the intended behavior.

Incorrect Answers

 

Answer A is incorrect because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. For the tailspin has a highly case, that does not satisfy the requirement that membership must remain a manually curated list that does not change when directory attributes change; it solves a different administrative need.

Answer C is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. In the tailspin has a highly case, this is not sufficient because membership must remain a manually curated list that does not change when directory attributes change; the capability addresses a neighboring use case.

Answer D is incorrect because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. Applied to the tailspin has a highly case, this does not provide the required behavior because membership must remain a manually curated list that does not change when directory attributes change.

 

Question 19

Woodgrove wants a project group with a fixed manually maintained membership list even when user department values change. What type of membership should be configured? Choose ONE.

  1. Assign the product license to an eligible Microsoft Entra group
  2. Use a dynamic device security group
  3. Use an assigned-membership group and add the required identities explicitly
  4. Use a dynamic user security group

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Assigned membership is appropriate when the exact membership must be curated manually rather than calculated from changing directory attributes. Applied to the woodgrove wants a project case, the capability meets the requirement that membership must remain a manually curated list that does not change when directory attributes change without adding unrelated scope.

Incorrect Answers

 

Answer A is incorrect because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. For the woodgrove wants a project case, that does not satisfy the requirement that membership must remain a manually curated list that does not change when directory attributes change; it solves a different administrative need.

Answer B is incorrect because Dynamic device membership evaluates device attributes and automatically maintains device membership without manual updates. In the woodgrove wants a project case, this is not sufficient because membership must remain a manually curated list that does not change when directory attributes change; the capability addresses a neighboring use case.

Answer D is incorrect because Dynamic user membership evaluates user attributes against a membership rule and automatically adds or removes matching users. The the woodgrove wants a project case scenario instead requires that membership must remain a manually curated list that does not change when directory attributes change, so this option would leave the key requirement unresolved.

 

Question 20

A company wants licenses to follow a department group automatically. Which TWO design choices are required? Choose TWO.

  1. Use a Microsoft 365 group
  2. Assign the product license to an eligible Microsoft Entra group
  3. Assign the product license directly to each user
  4. Update the Microsoft Entra user or group properties in the directory
  5. Use direct user membership in the licensed group rather than relying on a nested group

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Group-based licensing automatically applies the assigned product licenses to eligible direct user members and removes inherited licenses when membership ends. For the a company wants licenses case, that directly satisfies the requirement that the license should be assigned to an eligible group and the licensed users must be direct members rather than relying on nested licensing.

Answer E is correct because Group-based licensing does not process nested group membership as license inheritance; users must be direct members of the group receiving the license. In the a company wants licenses case, this is the best fit because the license should be assigned to an eligible group and the licensed users must be direct members rather than relying on nested licensing.

Incorrect Answers

 

Answer A is incorrect because A Microsoft 365 group is intended for collaboration and can provide shared resources such as a mailbox and SharePoint-backed collaboration experience. Applied to the a company wants licenses case, this does not provide the required behavior because the license should be assigned to an eligible group and the licensed users must be direct members rather than relying on nested licensing.

Answer C is incorrect because Direct licensing works for individual users but requires per-user lifecycle management and does not automatically follow group membership. The the a company wants licenses case scenario instead requires that the license should be assigned to an eligible group and the licensed users must be direct members rather than relying on nested licensing, so this option would leave the key requirement unresolved.

Answer D is incorrect because User and group properties are directory attributes managed on their respective objects and are distinct from Azure RBAC assignments or subscription settings. For the a company wants licenses case, that does not satisfy the requirement that the license should be assigned to an eligible group and the licensed users must be direct members rather than relying on nested licensing; it solves a different administrative need.

 

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!