Microsoft AZ-104 Entra Identity Management Practice Test

 

Topic 01 focuses on Microsoft Entra Users, Groups, Licensing, External Identities, and SSPR for the Microsoft Certified: Azure Administrator Associate certification and the AZ-104 exam, using Microsoft Azure administration scenarios. For broader exam preparation, review the Microsoft Azure Administrator AZ-104 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

To create and manage an Azure identity entirely in the cloud, which Azure configuration should be selected?

  1. Cloud-only user
  2. Self-service password reset (SSPR)
  3. Group-based licensing
  4. Direct license assignment

Correct Answer: A

 

Correct Answer

Answer A is correct because Cloud-only user is an identity created directly in Microsoft Entra ID rather than synchronized from an on-premises directory. It directly supports the requirement to create and manage an Azure identity entirely in the cloud.

Incorrect Answers

Answer B is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.

Answer C is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.

Answer D is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.

 

Question 2

For Cloud-only user, which administrative outcome is expected?

  1. Support collaboration scenarios that need shared Microsoft 365 services
  2. Maintain identity information that affects administration and access decisions
  3. Control group membership manually when rule-based membership is not required
  4. Create and manage an Azure identity entirely in the cloud

Correct Answer: D

 

Correct Answer

Answer D is correct because Cloud-only user is an identity created directly in Microsoft Entra ID rather than synchronized from an on-premises directory. Its intended administrative use is to create and manage an Azure identity entirely in the cloud.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Microsoft 365 group, which is used to support collaboration scenarios that need shared Microsoft 365 services; it is not the primary purpose of Cloud-only user.

Answer B is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Cloud-only user.

Answer C is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Cloud-only user.

 

Question 3

To support hybrid identity while keeping the authoritative user object on-premises, which Azure configuration should be selected?

  1. SSPR scope
  2. User properties
  3. Security group
  4. Synchronized user

Correct Answer: D

 

Correct Answer

Answer D is correct because Synchronized user is a Microsoft Entra user whose core identity originates in an on-premises directory and is synchronized to the cloud. It directly supports the requirement to support hybrid identity while keeping the authoritative user object on-premises.

Incorrect Answers

Answer A is incorrect because SSPR scope is used to control which users are permitted to use SSPR; it does not provide the capability described in the scenario.

Answer B is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.

Answer C is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.

 

Question 4

For Synchronized user, which administrative outcome is expected?

  1. Provide the location value required for licensing decisions and service availability
  2. Reduce help-desk password-reset work while requiring identity verification
  3. Create and manage an Azure identity entirely in the cloud
  4. Support hybrid identity while keeping the authoritative user object on-premises

Correct Answer: D

 

Correct Answer

Answer D is correct because Synchronized user is a Microsoft Entra user whose core identity originates in an on-premises directory and is synchronized to the cloud. Its intended administrative use is to support hybrid identity while keeping the authoritative user object on-premises.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Synchronized user.

Answer B is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Synchronized user.

Answer C is incorrect because that outcome belongs to Cloud-only user, which is used to create and manage an Azure identity entirely in the cloud; it is not the primary purpose of Synchronized user.

 

Question 5

To manage permissions for multiple identities as a single security principal, which Azure configuration should be selected?

  1. Security group
  2. Direct license assignment
  3. B2B collaboration guest
  4. Microsoft 365 group

Correct Answer: A

 

Correct Answer

Answer A is correct because Security group is a group that can be used to assign access to Azure resources and applications. It directly supports the requirement to manage permissions for multiple identities as a single security principal.

Incorrect Answers

Answer B is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.

Answer C is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.

Answer D is incorrect because Microsoft 365 group is used to support collaboration scenarios that need shared Microsoft 365 services; it does not provide the capability described in the scenario.

 

Question 6

For Security group, which administrative outcome is expected?

  1. Delegate routine group administration without granting broad directory-wide privileges
  2. Manage permissions for multiple identities as a single security principal
  3. Provide the location value required for licensing decisions and service availability
  4. Reduce help-desk password-reset work while requiring identity verification

Correct Answer: B

 

Correct Answer

Answer B is correct because Security group is a group that can be used to assign access to Azure resources and applications. Its intended administrative use is to manage permissions for multiple identities as a single security principal.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of Security group.

Answer C is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Security group.

Answer D is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Security group.

 

Question 7

To support collaboration scenarios that need shared Microsoft 365 services, which Azure configuration should be selected?

  1. Self-service password reset (SSPR)
  2. Microsoft 365 group
  3. B2B collaboration guest
  4. Group owner

Correct Answer: B

 

Correct Answer

Answer B is correct because Microsoft 365 group is a collaboration-oriented group that can provide shared Microsoft 365 resources in addition to group membership. It directly supports the requirement to support collaboration scenarios that need shared Microsoft 365 services.

Incorrect Answers

Answer A is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.

Answer C is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.

Answer D is incorrect because Group owner is used to delegate routine group administration without granting broad directory-wide privileges; it does not provide the capability described in the scenario.

 

Question 8

For Microsoft 365 group, which administrative outcome is expected?

  1. Provide the location value required for licensing decisions and service availability
  2. Support collaboration scenarios that need shared Microsoft 365 services
  3. Control which users are permitted to use SSPR
  4. Administer licenses at scale by managing group membership instead of each user individually

Correct Answer: B

 

Correct Answer

Answer B is correct because Microsoft 365 group is a collaboration-oriented group that can provide shared Microsoft 365 resources in addition to group membership. Its intended administrative use is to support collaboration scenarios that need shared Microsoft 365 services.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Microsoft 365 group.

Answer C is incorrect because that outcome belongs to SSPR scope, which is used to control which users are permitted to use SSPR; it is not the primary purpose of Microsoft 365 group.

Answer D is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of Microsoft 365 group.

 

Question 9

To keep group membership aligned automatically with defined identity attributes, which Azure configuration should be selected?

  1. Security group
  2. B2B collaboration guest
  3. Dynamic group membership
  4. Guest invitation redemption

Correct Answer: C

 

Correct Answer

Answer C is correct because Dynamic group membership is membership that Microsoft Entra ID evaluates automatically from user or device attribute rules. It directly supports the requirement to keep group membership aligned automatically with defined identity attributes.

Incorrect Answers

Answer A is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.

Answer B is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.

Answer D is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.

 

Question 10

For Dynamic group membership, which administrative outcome is expected?

  1. Grant controlled access to users from another organization without creating a normal internal workforce account
  2. Provide the location value required for licensing decisions and service availability
  3. Keep group membership aligned automatically with defined identity attributes
  4. Maintain identity information that affects administration and access decisions

Correct Answer: C

 

Correct Answer

Answer C is correct because Dynamic group membership is membership that Microsoft Entra ID evaluates automatically from user or device attribute rules. Its intended administrative use is to keep group membership aligned automatically with defined identity attributes.

Incorrect Answers

Answer A is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Dynamic group membership.

Answer B is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Dynamic group membership.

Answer D is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Dynamic group membership.

 

Question 11

To control group membership manually when rule-based membership is not required, which Azure configuration should be selected?

  1. B2B collaboration guest
  2. Dynamic group membership
  3. Self-service password reset (SSPR)
  4. Assigned group membership

Correct Answer: D

 

Correct Answer

Answer D is correct because Assigned group membership is membership in which an administrator or group owner explicitly adds and removes members. It directly supports the requirement to control group membership manually when rule-based membership is not required.

Incorrect Answers

Answer A is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.

Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

Answer C is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.

 

Question 12

For Assigned group membership, which administrative outcome is expected?

  1. Control group membership manually when rule-based membership is not required
  2. Complete onboarding of an invited external identity
  3. Reduce help-desk password-reset work while requiring identity verification
  4. Support hybrid identity while keeping the authoritative user object on-premises

Correct Answer: A

 

Correct Answer

Answer A is correct because Assigned group membership is membership in which an administrator or group owner explicitly adds and removes members. Its intended administrative use is to control group membership manually when rule-based membership is not required.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of Assigned group membership.

Answer C is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of Assigned group membership.

Answer D is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Assigned group membership.

 

Question 13

To administer licenses at scale by managing group membership instead of each user individually, which Azure configuration should be selected?

  1. Group-based licensing
  2. Dynamic group membership
  3. Direct license assignment
  4. B2B collaboration guest

Correct Answer: A

 

Correct Answer

Answer A is correct because Group-based licensing is license assignment applied to a group so eligible members inherit the licenses. It directly supports the requirement to administer licenses at scale by managing group membership instead of each user individually.

Incorrect Answers

Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

Answer C is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.

Answer D is incorrect because B2B collaboration guest is used to grant controlled access to users from another organization without creating a normal internal workforce account; it does not provide the capability described in the scenario.

 

Question 14

For Group-based licensing, which administrative outcome is expected?

  1. Support hybrid identity while keeping the authoritative user object on-premises
  2. Administer licenses at scale by managing group membership instead of each user individually
  3. Grant controlled access to users from another organization without creating a normal internal workforce account
  4. Manage permissions for multiple identities as a single security principal

Correct Answer: B

 

Correct Answer

Answer B is correct because Group-based licensing is license assignment applied to a group so eligible members inherit the licenses. Its intended administrative use is to administer licenses at scale by managing group membership instead of each user individually.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Group-based licensing.

Answer C is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Group-based licensing.

Answer D is incorrect because that outcome belongs to Security group, which is used to manage permissions for multiple identities as a single security principal; it is not the primary purpose of Group-based licensing.

 

Question 15

To license an individual user independently of group membership, which Azure configuration should be selected?

  1. Self-service password reset (SSPR)
  2. Guest invitation redemption
  3. Direct license assignment
  4. Group-based licensing

Correct Answer: C

 

Correct Answer

Answer C is correct because Direct license assignment is a product license assigned to a specific user object. It directly supports the requirement to license an individual user independently of group membership.

Incorrect Answers

Answer A is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.

Answer B is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.

Answer D is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.

 

Question 16

For Direct license assignment, which administrative outcome is expected?

  1. Delegate routine group administration without granting broad directory-wide privileges
  2. Support hybrid identity while keeping the authoritative user object on-premises
  3. License an individual user independently of group membership
  4. Control group membership manually when rule-based membership is not required

Correct Answer: C

 

Correct Answer

Answer C is correct because Direct license assignment is a product license assigned to a specific user object. Its intended administrative use is to license an individual user independently of group membership.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of Direct license assignment.

Answer B is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Direct license assignment.

Answer D is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Direct license assignment.

 

Question 17

To provide the location value required for licensing decisions and service availability, which Azure configuration should be selected?

  1. Cloud-only user
  2. Dynamic group membership
  3. User properties
  4. Usage location

Correct Answer: D

 

Correct Answer

Answer D is correct because Usage location is the user property that identifies the country or region used when determining service availability for licensing. It directly supports the requirement to provide the location value required for licensing decisions and service availability.

Incorrect Answers

Answer A is incorrect because Cloud-only user is used to create and manage an Azure identity entirely in the cloud; it does not provide the capability described in the scenario.

Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

Answer C is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.

 

Question 18

For Usage location, which administrative outcome is expected?

  1. Keep group membership aligned automatically with defined identity attributes
  2. Provide the location value required for licensing decisions and service availability
  3. Support hybrid identity while keeping the authoritative user object on-premises
  4. Maintain identity information that affects administration and access decisions

Correct Answer: B

 

Correct Answer

Answer B is correct because Usage location is the user property that identifies the country or region used when determining service availability for licensing. Its intended administrative use is to provide the location value required for licensing decisions and service availability.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of Usage location.

Answer C is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Usage location.

Answer D is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of Usage location.

 

Question 19

To grant controlled access to users from another organization without creating a normal internal workforce account, which Azure configuration should be selected?

  1. B2B collaboration guest
  2. Self-service password reset (SSPR)
  3. Microsoft 365 group
  4. Dynamic group membership

Correct Answer: A

 

Correct Answer

Answer A is correct because B2B collaboration guest is an external identity represented in the tenant so a partner or other outside user can access shared resources. It directly supports the requirement to grant controlled access to users from another organization without creating a normal internal workforce account.

Incorrect Answers

Answer B is incorrect because Self-service password reset (SSPR) is used to reduce help-desk password-reset work while requiring identity verification; it does not provide the capability described in the scenario.

Answer C is incorrect because Microsoft 365 group is used to support collaboration scenarios that need shared Microsoft 365 services; it does not provide the capability described in the scenario.

Answer D is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

 

Question 20

For B2B collaboration guest, which administrative outcome is expected?

  1. Support collaboration scenarios that need shared Microsoft 365 services
  2. Grant controlled access to users from another organization without creating a normal internal workforce account
  3. Complete onboarding of an invited external identity
  4. Support hybrid identity while keeping the authoritative user object on-premises

Correct Answer: B

 

Correct Answer

Answer B is correct because B2B collaboration guest is an external identity represented in the tenant so a partner or other outside user can access shared resources. Its intended administrative use is to grant controlled access to users from another organization without creating a normal internal workforce account.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Microsoft 365 group, which is used to support collaboration scenarios that need shared Microsoft 365 services; it is not the primary purpose of B2B collaboration guest.

Answer C is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of B2B collaboration guest.

Answer D is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of B2B collaboration guest.

 

Question 21

To complete onboarding of an invited external identity, which Azure configuration should be selected?

  1. Synchronized user
  2. Dynamic group membership
  3. Guest invitation redemption
  4. User properties

Correct Answer: C

 

Correct Answer

Answer C is correct because Guest invitation redemption is the process by which an invited external user accepts the invitation and establishes access to the resource tenant. It directly supports the requirement to complete onboarding of an invited external identity.

Incorrect Answers

Answer A is incorrect because Synchronized user is used to support hybrid identity while keeping the authoritative user object on-premises; it does not provide the capability described in the scenario.

Answer B is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

Answer D is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.

 

Question 22

For Guest invitation redemption, which administrative outcome is expected?

  1. Control which users are permitted to use SSPR
  2. Administer licenses at scale by managing group membership instead of each user individually
  3. Grant controlled access to users from another organization without creating a normal internal workforce account
  4. Complete onboarding of an invited external identity

Correct Answer: D

 

Correct Answer

Answer D is correct because Guest invitation redemption is the process by which an invited external user accepts the invitation and establishes access to the resource tenant. Its intended administrative use is to complete onboarding of an invited external identity.

Incorrect Answers

Answer A is incorrect because that outcome belongs to SSPR scope, which is used to control which users are permitted to use SSPR; it is not the primary purpose of Guest invitation redemption.

Answer B is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of Guest invitation redemption.

Answer C is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Guest invitation redemption.

 

Question 23

To maintain identity information that affects administration and access decisions, which Azure configuration should be selected?

  1. Group-based licensing
  2. User properties
  3. Guest invitation redemption
  4. Direct license assignment

Correct Answer: B

 

Correct Answer

Answer B is correct because User properties is attributes such as display name, job information, usage location, and account state stored on a Microsoft Entra user object. It directly supports the requirement to maintain identity information that affects administration and access decisions.

Incorrect Answers

Answer A is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.

Answer C is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.

Answer D is incorrect because Direct license assignment is used to license an individual user independently of group membership; it does not provide the capability described in the scenario.

 

Question 24

For User properties, which administrative outcome is expected?

  1. Maintain identity information that affects administration and access decisions
  2. Keep group membership aligned automatically with defined identity attributes
  3. Reduce help-desk password-reset work while requiring identity verification
  4. Administer licenses at scale by managing group membership instead of each user individually

Correct Answer: A

 

Correct Answer

Answer A is correct because User properties is attributes such as display name, job information, usage location, and account state stored on a Microsoft Entra user object. Its intended administrative use is to maintain identity information that affects administration and access decisions.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of User properties.

Answer C is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of User properties.

Answer D is incorrect because that outcome belongs to Group-based licensing, which is used to administer licenses at scale by managing group membership instead of each user individually; it is not the primary purpose of User properties.

 

Question 25

To delegate routine group administration without granting broad directory-wide privileges, which Azure configuration should be selected?

  1. Dynamic group membership
  2. Group owner
  3. Guest invitation redemption
  4. Assigned group membership

Correct Answer: B

 

Correct Answer

Answer B is correct because Group owner is an identity delegated the ability to manage membership and selected settings for a group. It directly supports the requirement to delegate routine group administration without granting broad directory-wide privileges.

Incorrect Answers

Answer A is incorrect because Dynamic group membership is used to keep group membership aligned automatically with defined identity attributes; it does not provide the capability described in the scenario.

Answer C is incorrect because Guest invitation redemption is used to complete onboarding of an invited external identity; it does not provide the capability described in the scenario.

Answer D is incorrect because Assigned group membership is used to control group membership manually when rule-based membership is not required; it does not provide the capability described in the scenario.

 

Question 26

For Group owner, which administrative outcome is expected?

  1. Delegate routine group administration without granting broad directory-wide privileges
  2. Provide the location value required for licensing decisions and service availability
  3. Control group membership manually when rule-based membership is not required
  4. Keep group membership aligned automatically with defined identity attributes

Correct Answer: A

 

Correct Answer

Answer A is correct because Group owner is an identity delegated the ability to manage membership and selected settings for a group. Its intended administrative use is to delegate routine group administration without granting broad directory-wide privileges.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Usage location, which is used to provide the location value required for licensing decisions and service availability; it is not the primary purpose of Group owner.

Answer C is incorrect because that outcome belongs to Assigned group membership, which is used to control group membership manually when rule-based membership is not required; it is not the primary purpose of Group owner.

Answer D is incorrect because that outcome belongs to Dynamic group membership, which is used to keep group membership aligned automatically with defined identity attributes; it is not the primary purpose of Group owner.

 

Question 27

To reduce help-desk password-reset work while requiring identity verification, which Azure configuration should be selected?

  1. Self-service password reset (SSPR)
  2. Security group
  3. SSPR scope
  4. Group-based licensing

Correct Answer: A

 

Correct Answer

Answer A is correct because Self-service password reset (SSPR) is a Microsoft Entra capability that lets enabled users reset or unlock their password after satisfying configured verification requirements. It directly supports the requirement to reduce help-desk password-reset work while requiring identity verification.

Incorrect Answers

Answer B is incorrect because Security group is used to manage permissions for multiple identities as a single security principal; it does not provide the capability described in the scenario.

Answer C is incorrect because SSPR scope is used to control which users are permitted to use SSPR; it does not provide the capability described in the scenario.

Answer D is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.

 

Question 28

For Self-service password reset (SSPR), which administrative outcome is expected?

  1. Complete onboarding of an invited external identity
  2. Support hybrid identity while keeping the authoritative user object on-premises
  3. Reduce help-desk password-reset work while requiring identity verification
  4. Grant controlled access to users from another organization without creating a normal internal workforce account

Correct Answer: C

 

Correct Answer

Answer C is correct because Self-service password reset (SSPR) is a Microsoft Entra capability that lets enabled users reset or unlock their password after satisfying configured verification requirements. Its intended administrative use is to reduce help-desk password-reset work while requiring identity verification.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Guest invitation redemption, which is used to complete onboarding of an invited external identity; it is not the primary purpose of Self-service password reset (SSPR).

Answer B is incorrect because that outcome belongs to Synchronized user, which is used to support hybrid identity while keeping the authoritative user object on-premises; it is not the primary purpose of Self-service password reset (SSPR).

Answer D is incorrect because that outcome belongs to B2B collaboration guest, which is used to grant controlled access to users from another organization without creating a normal internal workforce account; it is not the primary purpose of Self-service password reset (SSPR).

 

Question 29

To control which users are permitted to use SSPR, which Azure configuration should be selected?

  1. Group-based licensing
  2. User properties
  3. SSPR scope
  4. Assigned group membership

Correct Answer: C

 

Correct Answer

Answer C is correct because SSPR scope is the setting that determines whether self-service password reset is disabled, enabled for selected groups, or enabled for all users. It directly supports the requirement to control which users are permitted to use SSPR.

Incorrect Answers

Answer A is incorrect because Group-based licensing is used to administer licenses at scale by managing group membership instead of each user individually; it does not provide the capability described in the scenario.

Answer B is incorrect because User properties is used to maintain identity information that affects administration and access decisions; it does not provide the capability described in the scenario.

Answer D is incorrect because Assigned group membership is used to control group membership manually when rule-based membership is not required; it does not provide the capability described in the scenario.

 

Question 30

For SSPR scope, which administrative outcome is expected?

  1. Maintain identity information that affects administration and access decisions
  2. Reduce help-desk password-reset work while requiring identity verification
  3. Delegate routine group administration without granting broad directory-wide privileges
  4. Control which users are permitted to use SSPR

Correct Answer: D

 

Correct Answer

Answer D is correct because SSPR scope is the setting that determines whether self-service password reset is disabled, enabled for selected groups, or enabled for all users. Its intended administrative use is to control which users are permitted to use SSPR.

Incorrect Answers

Answer A is incorrect because that outcome belongs to User properties, which is used to maintain identity information that affects administration and access decisions; it is not the primary purpose of SSPR scope.

Answer B is incorrect because that outcome belongs to Self-service password reset (SSPR), which is used to reduce help-desk password-reset work while requiring identity verification; it is not the primary purpose of SSPR scope.

Answer C is incorrect because that outcome belongs to Group owner, which is used to delegate routine group administration without granting broad directory-wide privileges; it is not the primary purpose of SSPR scope.

img