Microsoft SC-300 External Identities and Cross-Tenant Collaboration Practice Test

 

Topic 03 covers external identities and cross-tenant collaboration for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

A workforce tenant allows invitations only from users assigned to the specific administrator roles permitted by its guest-invite policy. Partner-domain and cross-tenant policies already permit the invitations. A procurement employee must invite partners but must not receive general user-management authority. Which change meets the requirement?

  1. Assign Guest Inviter to the procurement employee
  2. Make the employee an owner of an ordinary security group
  3. Assign User Administrator to the procurement employee
  4. Add the partner domain to an allow list without changing the employee’s role
  5. Allow every member and guest to invite users

Correct Answer: A

 

Correct Answer

Answer A is correct because Guest Inviter is explicitly permitted under this policy and supplies invitation authority without the broader user-management capabilities of User Administrator.

Incorrect Answers

Answer B is incorrect because group ownership is not the specific invitation-role exception allowed by the configured policy. It does not establish the required tenant invitation authority.

Answer C is incorrect because this would enable invitations but also grants broader user administration. It exceeds the explicitly limited procurement responsibility.

Answer D is incorrect because domain eligibility and inviter authority are separate requirements. An allowed destination domain does not authorize this employee to issue invitations.

Answer E is incorrect because this broadens invitation eligibility across the tenant rather than delegating it to the designated employee.

 

Question 2

Security requires B2B guests to see only their own directory-object properties and memberships. A guest must still use an application already shared with them. Which setting addresses the directory-visibility requirement without treating it as an application access revocation?

  1. Block every inbound cross-tenant application request
  2. Disable all guest invitations while leaving existing guest access settings unchanged
  3. Set guest permissions equal to member permissions
  4. Remove the guest’s application assignment
  5. Select the guest access restriction limited to guests’ own directory objects

Correct Answer: E

 

Correct Answer

Answer E is correct because this is the most restrictive documented directory-visibility setting. It controls directory reads; application authorization remains a separate consideration.

Incorrect Answers

Answer A is incorrect because that would prevent the required application access rather than narrowly limiting what guests can inspect in the directory.

Answer B is incorrect because invitation eligibility controls onboarding. It does not narrow the directory visibility of an already existing guest.

Answer C is incorrect because this expands default visibility and conflicts with the own-object-only requirement. The scenario requires the narrower Microsoft Entra behavior described in the stem.

Answer D is incorrect because this revokes the business access that must remain. It does not implement the requested directory-visibility boundary.

 

Question 3

A tenant blocks invitations from partner.example after two partners were invited. One already redeemed the invitation; the other’s invitation is still pending. No account or access-policy change accompanies the new domain restriction. Which TWO outcomes follow from the documented invitation-list behavior? Choose TWO.

  1. The redeemed user must be removed from every group automatically
  2. Both guest objects are automatically permanently deleted
  3. The pending user can fail redemption because the domain is now blocked
  4. The previously redeemed user’s existing access is not revoked by this invitation list alone
  5. The pending invitation bypasses the restriction because it predates the policy
  6. The domain restriction blocks only email delivery and cannot affect redemption

Correct Answers: C, D

 

Correct Answers

Answer C is correct because Microsoft applies the configured restriction to a pending invitation when the user attempts redemption. An earlier invitation does not guarantee later redemption.

Answer D is correct because the allow/block list does not apply retroactively to users who already redeemed. Continued access must be assessed through account and resource-access controls.

Incorrect Answers

Answer A is incorrect because the list does not automatically revoke existing redeemed-user access. Group membership is a separate administrative state.

Answer B is incorrect because the invitation policy is not a directory deletion operation. The described change does not remove those objects.

Answer E is incorrect because the documentation specifically states that pending redemption can fail after the domain becomes blocked.

Answer F is incorrect because the policy also affects attempts to redeem pending invitations. Limiting it to message transport understates its documented effect.

 

Question 4

SharePoint B2B integration is enabled. A partner tenant is allowed in organization-specific cross-tenant access settings, but native SharePoint invitations to that partner still fail. The resource tenant’s external collaboration allow list excludes the partner’s email domain. What should the administrator correct?

  1. Convert every partner user to UserType Member
  2. Change only the resource tenant’s outbound access settings
  3. Add the approved partner domain to the external collaboration allow list
  4. Enable trust for the partner’s MFA claims
  5. Allow the resource application in the partner’s outbound policy while leaving the domain exclusion intact

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft documents this additional requirement for native SharePoint and OneDrive sharing with B2B integration. Cross-tenant permission alone does not override the invitation-domain restriction.

Incorrect Answers

Answer A is incorrect because changing the local relationship classification does not fix the blocked invitation domain. It also changes permissions unnecessarily.

Answer B is incorrect because the invitation is being issued to external users for resource-tenant collaboration. The identified domain exclusion remains regardless of that unrelated outbound change.

Answer D is incorrect because MFA trust affects whether authentication evidence is accepted. It does not make an excluded invitation domain pass the collaboration allow list.

Answer E is incorrect because a partner outbound permission does not remove the resource tenant’s external-collaboration invitation restriction. The identified domain block would still apply.

 

Question 5

A supplier sends a roster of external employees who will keep using their own supported identity providers. An operator proposes bulk creating internal members with initial passwords. The approved onboarding process instead requires B2B invitations and the supplier’s existing credentials. Which workflow should be used?

  1. Use bulk internal-user creation and assign the same initial password to every row
  2. Use Bulk invite users with the guest-invitation CSV template
  3. Assign a license to each supplier email address without creating or inviting users
  4. Bulk create internal members and then change their UserType to Guest
  5. Create mail contacts only and assume they can authenticate as guests

Correct Answer: B

 

Correct Answer

Answer B is correct because this creates the intended B2B invitation flow. Bulk internal-user creation would establish a different account and credential model.

Incorrect Answers

Answer A is incorrect because this creates local workforce credentials rather than federating the external identities. It conflicts with the approved authentication model.

Answer C is incorrect because licensing is not an identity onboarding operation. It does not create a B2B invitation or bind the supplier’s authentication identity.

Answer D is incorrect because UserType describes the relationship to the organization. Changing it does not replace newly created local credentials with the intended external B2B identity binding.

Answer E is incorrect because a contact entry is not an invited B2B user identity. It does not establish the required sign-in and redemption flow.

 

Question 6

An invitation CSV contains the correct external email addresses, but its Redirection URL points to an obsolete portal. Guests successfully accept their invitations and then land on that obsolete page. The replacement portal’s access assignments are already correct. What should be corrected for subsequent invitations?

  1. Set the invitation Redirection URL to the approved destination
  2. Change the partner’s identity-provider issuer URI
  3. Issue additional application permissions without changing the invitation
  4. Change invitation redemption order to prefer the partner identity provider
  5. Change the guest’s UserType to Member

Correct Answer: A

 

Correct Answer

Answer A is correct because this field controls where the user is forwarded after acceptance. The observed timing isolates the problem from authentication and app assignment.

Incorrect Answers

Answer B is incorrect because the guests successfully authenticate and accept. An issuer change would not correct the post-acceptance destination specified in the invitation.

Answer C is incorrect because authorization is already correct. More permissions do not replace the obsolete URL in the invitation flow.

Answer D is incorrect because redemption order selects the authentication provider. The guests already authenticate successfully; it does not replace the post-acceptance destination URL.

Answer E is incorrect because relationship classification does not define the invitation’s redirect destination. It would introduce an unrelated permissions change.

 

Question 7

A bulk invitation job succeeds, and its guest objects appear in the directory. Several objects still show Pending acceptance, and automatic redemption is not enabled. The onboarding dashboard reports all suppliers as having completed their first-time consent. Which TWO changes would make the report defensible? Choose TWO.

  1. Track invitation creation separately from redemption status
  2. Delete pending guests immediately because pending status proves the bulk operation failed
  3. Assume every successful bulk job signs in each guest automatically
  4. Use the guest’s redemption state or relevant completed sign-in evidence for the onboarding completion measure
  5. Count application assignments as completed invitation acceptance
  6. Treat the existence of a #EXT# UPN as proof of completed consent

Correct Answers: A, D

 

Correct Answers

Answer A is correct because successful invitation processing proves that the invitations were created. Pending acceptance shows that the user-dependent redemption step is not yet complete.

Answer D is correct because completion must be tied to the actual user step being measured. Directory-object existence alone is insufficient for a claim about first-time consent.

Incorrect Answers

Answer B is incorrect because pending redemption is compatible with successful invitation creation. Deletion is not justified by that status alone.

Answer C is incorrect because the job does not perform each external user’s interactive authentication and consent. Its success has a narrower meaning.

Answer E is incorrect because an application assignment can exist before the guest redeems. It establishes authorization intent, not completion of the first-time user action.

Answer F is incorrect because the guest object and its UPN can exist before redemption. That identifier does not establish completion of the user’s acceptance step.

 

Question 8

A B2B guest remains Pending acceptance and reports losing the invitation email. The guest’s email address and intended identity provider have not changed. The team wants to preserve the existing guest object. What should support do first?

  1. Invite a different alias as a second guest and copy the application assignment
  2. Change the guest’s UserType to Member to mark redemption complete
  3. Permanently delete the guest and create an internal member with a password
  4. Replace the partner’s authentication-provider configuration before resending
  5. Resend the invitation for the existing pending guest

Correct Answer: E

 

Correct Answer

Answer E is correct because the administration workflow exposes Resend invitation for pending acceptance. It restores the delivery path without replacing the existing object.

Incorrect Answers

Answer A is incorrect because the requested identity information has not changed. Creating a second object is unnecessary and conflicts with preserving the existing guest lifecycle.

Answer B is incorrect because UserType describes the relationship to the organization. It does not perform invitation acceptance or authenticate the guest.

Answer C is incorrect because this changes both the object and the authentication model. It is unnecessary when the only issue is the missing invitation message.

Answer D is incorrect because there is no reported provider change or authentication failure. Reconfiguring trust is not a targeted response to a missing email.

 

Question 9

A partner user’s home account was deleted and recreated. The resource tenant must bind the guest to the replacement identity while preserving its object ID, group memberships and application assignments. Which supported operation addresses that requirement?

  1. Change the resource-tenant guest’s display name to match the new home account
  2. Delete the guest permanently and invite the same email address again
  3. Reset the existing guest’s redemption status and reinvite the user
  4. Assign the guest an additional application role without resetting redemption
  5. Reset a local password on the guest object and keep its external identity unchanged

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft supports this operation for a recreated home account. It allows a new identity binding while retaining the existing resource-tenant object’s ID and assignments.

Incorrect Answers

Answer A is incorrect because a display-name edit does not rebind the guest’s external authentication identity. The scenario requires the narrower Microsoft Entra behavior described in the stem.

Answer B is incorrect because a recreated guest is not guaranteed to retain the original object identity and assignments. This discards the preservation benefit explicitly required.

Answer D is incorrect because an application assignment changes authorization, not the external identity binding that failed after home-account recreation.

Answer E is incorrect because the guest authenticates using the external identity provider. A local password-reset approach does not perform the required external identity rebinding.

 

Question 10

An administrator changes a B2B collaborator’s UserType from Guest to Member because the partner is now part of a larger corporate organization. The Identities property still points to the external provider. The user continues to authenticate there. Which interpretation is correct?

  1. Changing UserType automatically grants a directory administrator role
  2. The successful external sign-in proves the UserType change failed
  3. Every Member must authenticate with a password stored in the resource tenant
  4. The relationship classification changed, but the authentication identity remained external
  5. The external account must be deleted immediately because Member and an external identity cannot coexist

Correct Answer: D

 

Correct Answer

Answer D is correct because UserType and Identities are independent. Editing the former does not automatically move credentials or authentication into the resource tenant.

Incorrect Answers

Answer A is incorrect because relationship classification and role assignments are distinct properties. The update does not by itself assign an administrative role.

Answer B is incorrect because authentication can remain external after the relationship classification changes. The observed sign-in is compatible with the new UserType.

Answer C is incorrect because external members are supported. Member is not a universal statement about credential storage or authentication location.

Answer E is incorrect because Microsoft documents external members. Deleting a valid external account would unnecessarily disrupt the intended collaboration.

 

Question 11

A redeemed B2B guest cannot authenticate because the password for their home organization’s account has expired. The resource tenant’s guest object uses ExternalAzureAD and has no local credential. What is the appropriate recovery path?

  1. Have the user complete credential recovery with the home organization, then retry resource access
  2. Give the resource-tenant operator Authentication Administrator and retry a local reset
  3. Reset redemption and ask the user to retry the same expired home credential
  4. Create a new password on the existing guest’s resource-tenant object
  5. Disable and re-enable the local guest without changing the home credential

Correct Answer: A

 

Correct Answer

Answer A is correct because the home identity provider owns the credential used for this guest’s authentication. Resource-tenant authorization changes cannot repair an expired home password.

Incorrect Answers

Answer B is incorrect because a resource directory role does not transfer administration of the partner’s password store. The credential still belongs to the home provider.

Answer C is incorrect because a redemption reset can rebind identities, but it does not change the password state at the home provider. The identified credential problem remains.

Answer D is incorrect because the scenario explicitly has no local credential for this external authentication relationship. This is not the home provider’s password-reset mechanism.

Answer E is incorrect because local account enablement and home password validity are different conditions. Toggling the guest cannot make the expired home password valid.

 

Question 12

An app-only automation tries to reset redemption for a guest that has a directory role assignment. The API does not permit the reset for that target. The role assignment is legitimate and must remain. Which response follows the documented operation boundary?

  1. Use an appropriately authorized supported delegated-administrator reset process
  2. Create a second guest and leave the original role-bearing identity unchanged
  3. Grant the automation a broader Graph application permission and retry app-only
  4. Convert the guest to Member while retaining the app-only invocation
  5. Remove the role permanently and treat the lost authority as part of the reset

Correct Answer: A

 

Correct Answer

Answer A is correct because Microsoft documents that app-only redemption reset cannot be used when the target has role assignments. A supported delegated path addresses the operation without removing required access.

Incorrect Answers

Answer B is incorrect because a duplicate identity does not rebind the existing role-bearing guest. It also abandons continuity of the target object.

Answer C is incorrect because a broader application grant does not remove the documented app-only target restriction. The invocation model remains unsupported for this target.

Answer D is incorrect because UserType is not the documented condition causing the restriction. The target still has a directory role assignment.

Answer E is incorrect because the scenario requires that legitimate assignment to remain. Permanently removing it would violate the operational constraint.

 

Question 13

A user from HomeTenant accesses an application hosted in ResourceTenant. ResourceTenant permits the user’s organization through inbound B2B collaboration settings, and the application assignment is valid. HomeTenant’s outbound policy blocks access to ResourceTenant. Which policy change is needed for the approved access path?

  1. Add the user to a second resource application group without changing cross-tenant policy
  2. Permit the intended access in HomeTenant’s outbound settings for ResourceTenant
  3. Permit ResourceTenant in HomeTenant’s inbound settings
  4. Enable automatic invitation redemption in ResourceTenant only
  5. Permit HomeTenant in ResourceTenant’s outbound settings

Correct Answer: B

 

Correct Answer

Answer B is correct because the home tenant governs its users’ outbound access to external organizations. The resource tenant’s inbound allowance cannot override the home tenant’s block.

Incorrect Answers

Answer A is incorrect because the application assignment is already valid. An additional assignment cannot override the stated outbound block.

Answer C is incorrect because the requested journey is outbound from HomeTenant. Its inbound setting concerns external users accessing HomeTenant’s resources.

Answer D is incorrect because automatic redemption addresses the consent experience. It does not override an explicit cross-tenant access denial.

Answer E is incorrect because that direction governs ResourceTenant users accessing HomeTenant resources. It does not authorize the HomeTenant user’s outbound journey.

 

Question 14

A resource tenant blocks external access by default. An administrator adds a partner to Organizational settings and expects the act of adding it to allow one partner group to one internal application. The new organization’s settings still show Inherited from default. What should the administrator configure?

  1. Enable MFA trust and assume it grants the application access
  2. Customize only the partner’s inbound user scope while leaving its application scope blocked
  3. Customize that partner’s inbound user/group and application scope
  4. Allow all organizations in the default inbound policy
  5. Configure only a resource-tenant outbound exception for the partner

Correct Answer: C

 

Correct Answer

Answer C is correct because adding an organization initially inherits defaults. An organization-specific inbound configuration is needed to create the intended narrow exception.

Incorrect Answers

Answer A is incorrect because trust determines which authentication claims can be accepted. It does not supply the missing inbound access allowance.

Answer B is incorrect because both relevant user and resource scopes must permit the journey. A user-only exception is incomplete while the intended application remains blocked.

Answer D is incorrect because this would create a much broader exception than the one partner, group and application specified.

Answer E is incorrect because the requested path involves partner users entering the resource tenant. An outbound exception in the resource tenant addresses the opposite direction.

 

Question 15

A resource tenant requires MFA for ordinary B2B collaborators. A trusted partner’s users already satisfy MFA in their home Entra tenant, and the resource tenant wants to accept that evidence while keeping its MFA requirement. These users are not using GDAP. Which configuration addresses the requirement?

  1. Set the resource tenant’s outbound MFA trust for its own employees
  2. Enable only trust for compliant device claims
  3. Enable automatic invitation redemption and leave MFA trust unchanged
  4. Enable inbound trust of MFA claims for that partner organization
  5. Exclude the partner users from every MFA Conditional Access policy

Correct Answer: D

 

Correct Answer

Answer D is correct because this allows the resource tenant’s policy to accept the partner’s home-tenant MFA claim. It preserves the MFA requirement while changing which evidence can satisfy it.

Incorrect Answers

Answer A is incorrect because the partner users are entering the resource tenant. The relevant decision is the resource tenant’s inbound trust of the partner’s claims.

Answer B is incorrect because device compliance and MFA are different claim categories. Trusting the device does not enable acceptance of the home MFA claim.

Answer C is incorrect because automatic redemption suppresses a consent prompt in a supported bilateral setup. It is not the setting that establishes MFA-claim trust.

Answer E is incorrect because that removes the stated MFA requirement rather than accepting verified home-tenant evidence under it.

 

Question 16

A resource application’s Conditional Access policy requires a compliant device. Partner users arrive with valid home-tenant compliant-device claims, but the resource tenant does not trust those claims. Security approves trusting compliance from this partner only. Which configuration directly addresses the missing trust?

  1. Remove the compliant-device control from the application’s policy
  2. Enable inbound Trust compliant devices for the partner organization
  3. Set all partners to trusted in the default inbound settings
  4. Enable Trust Microsoft Entra hybrid joined devices only
  5. Enable MFA trust only

Correct Answer: B

 

Correct Answer

Answer B is correct because this is the documented setting for accepting the partner’s compliance claims. Organization-specific scope limits trust to the approved partner.

Incorrect Answers

Answer A is incorrect because this would weaken the required access condition. The approved change is to trust the partner’s evidence, not eliminate the requirement.

Answer C is incorrect because this broadens the trust relationship beyond the organization approved by security. A partner-specific setting is sufficient.

Answer D is incorrect because hybrid join and compliance are distinct claims. Trusting hybrid join alone does not satisfy a policy that specifically requires compliance.

Answer E is incorrect because MFA establishes a different aspect of authentication. It does not make a home-tenant compliant-device claim trusted.

 

Question 17

An organization is configuring one-way synchronization of internal user accounts from SourceTenant to TargetTenant within the same Microsoft cloud. Licensing and administrator permissions are ready, but no synchronization configuration or consent settings exist. Which THREE setup actions belong to the documented user-synchronization workflow? Choose THREE.

  1. Allow inbound user synchronization from SourceTenant in TargetTenant
  2. Create the synchronization configuration in SourceTenant for TargetTenant
  3. Allow inbound synchronization into SourceTenant and omit the target’s inbound permission
  4. Enable automatic redemption for the relationship on source outbound and target inbound settings
  5. Create only a TargetTenant configuration that provisions its users back to SourceTenant
  6. Replace user provisioning with B2B direct connect settings only

Correct Answers: A, B, D

 

Correct Answers

Answer A is correct because the target must permit the source organization to synchronize users into it. Source-side configuration alone does not grant that inbound permission.

Answer B is correct because the source controls which of its identities are provisioned into the target. Creating the source-side configuration establishes the intended direction.

Answer D is correct because the documented setup requires this bilateral relationship setting. Configuring only one side does not satisfy the workflow’s automatic-consent requirements.

Incorrect Answers

Answer C is incorrect because the permission is required where users will be created. Granting it in the source does not authorize provisioning into the target.

Answer E is incorrect because that creates the opposite direction and does not implement SourceTenant-to-TargetTenant provisioning. The scenario requires the narrower Microsoft Entra behavior described in the stem.

Answer F is incorrect because direct connect and cross-tenant user synchronization are distinct mechanisms. Direct connect alone does not create the requested synchronized user population.

 

Question 18

A cross-tenant synchronization administrator changes the default matching attribute to an email-based attribute. The validation log reports schemaInvalid and identifies the matching-attribute change as unsupported. The documented matching attribute, alternativeSecurityIds using AltSecIdFromNetId, was previously unchanged. Which correction addresses this failure?

  1. Recreate the synchronization configuration with the same custom matching attributes
  2. Add a second custom matching attribute alongside the email attribute
  3. Restore the supported fixed matching attribute and remove the added matching change
  4. Normalize the email mapping to lowercase while retaining it as the matching attribute
  5. Change the existing target users’ mail values to match the new source expression

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft documents that this matching attribute cannot be changed or supplemented. The error follows the unsupported matching-schema modification.

Incorrect Answers

Answer A is incorrect because recreating the job does not change its supported schema. Carrying forward the rejected matching changes reproduces the defect.

Answer B is incorrect because the documentation also excludes adding matching attributes. Expanding the unsupported configuration does not resolve schemaInvalid.

Answer D is incorrect because normalization might help supported value comparisons, but it does not make this service-controlled matching field replaceable. The schema restriction remains.

Answer E is incorrect because editing target data does not make the unsupported matching-schema definition valid. The service rejects the configuration before such matching can solve it.

 

Question 19

A source tenant’s cross-tenant synchronization configuration includes internal employees and an externally authenticated B2B guest. The team expects the guest to be copied onward simply because it changed the guest’s UserType to Member. The external identity provider is unchanged. What should the administrator conclude?

  1. Adding another synchronization group automatically converts the external identity into an internal one
  2. Any Member value guarantees the user is an internal identity supported for synchronization
  3. Assign the same external identity to a second synchronization configuration
  4. The relationship label does not make that external identity a supported internal synchronization source
  5. Change the target UserType mapping to Member while leaving the source identity external

Correct Answer: D

 

Correct Answer

Answer D is correct because cross-tenant synchronization supports internal users, not external users. UserType and identity origin are independent, so the label change does not establish eligibility.

Incorrect Answers

Answer A is incorrect because group assignment selects candidate objects. It does not change their identity-provider relationship or supported source type.

Answer B is incorrect because Microsoft distinguishes external members from internal users. UserType alone does not prove the source authentication origin.

Answer C is incorrect because another assignment or job does not change the user’s external origin. The unsupported source identity type remains.

Answer E is incorrect because a target relationship label does not convert the source’s authentication origin. Eligibility must be established for the source identity itself.

 

Question 20

A cross-tenant synchronization relationship is being retired. Scope is Sync only assigned users and groups, and all previously provisioned users must be deprovisioned from the target before the relationship is removed. Which TWO actions support that sequence? Choose TWO.

  1. Unassign the source users and groups from the synchronization configuration
  2. Remove the target’s inbound permission immediately after submitting the first unassignment
  3. Keep the target’s inbound synchronization permission enabled until deprovisioning completes
  4. Block all source provisioning traffic before unassigning users
  5. Leave every user assigned and disable only automatic invitation redemption
  6. Delete the synchronization policy first and assume all target guests are deleted automatically

Correct Answers: A, C

 

Correct Answers

Answer A is correct because this removes the configured provisioning population and triggers deprovisioning in subsequent cycles. It is different from merely severing the relationship.

Answer C is correct because the service needs the relationship to process the removals. Microsoft explicitly requires retaining this permission until the cleanup finishes.

Incorrect Answers

Answer B is incorrect because submission is not proof of completed deprovisioning. Removing permission prematurely can interrupt remaining cleanup work.

Answer D is incorrect because preventing the service from operating can stop the requested cleanup from propagating. It reverses the needed sequence.

Answer E is incorrect because that change does not remove the provisioning scope or instruct the service to deprovision the users.

Answer F is incorrect because severing the relationship does not itself change previously managed target users. This can leave the population in place.

 

Question 21

A partner uses a WS-Fed identity provider. Its users have addresses in partner.example, but its passive authentication endpoint is https://login.partner-host.example/adfs, outside that email domain. The federation setup requires proof linking the domains. What should the partner configure?

  1. Change the resource tenant’s primary domain to partner.example
  2. Create an MX record pointing partner.example mail to the resource tenant
  3. Replace the issuer URI with partner.example while omitting the DNS association
  4. Configure the partner metadata URL and omit the required DNS TXT association
  5. Publish the documented DirectFedAuthUrl TXT record under partner.example pointing to the authentication URL

Correct Answer: E

 

Correct Answer

Answer E is correct because Microsoft requires this DNS association when the passive endpoint is outside the target domain. It links the partner’s email domain to the separate authentication endpoint.

Incorrect Answers

Answer A is incorrect because the resource tenant does not need to take ownership of the partner’s email namespace. This would not provide the partner-side federation association.

Answer B is incorrect because mail routing is not the documented federation endpoint proof. Changing MX would affect email without supplying the required TXT association.

Answer C is incorrect because the issuer must identify the actual identity provider. Changing it to mimic the email domain does not provide the documented endpoint-domain proof and can introduce a trust mismatch.

Answer D is incorrect because metadata supplies provider configuration and signing information. It is not a substitute for the documented DNS association when the passive endpoint is outside the email domain.

 

Question 22

A partner configures a new SAML federation in 2026. Its IdP expects the old global issuer value urn:federation:MicrosoftOnline, but the request from Entra uses a tenant-specific issuer endpoint. Sign-in fails at the partner’s relying-party validation. What should be corrected?

  1. Change the assertion’s NameID format while retaining the global issuer expectation
  2. Update the new federation’s relying-party expectations to the documented tenant-specific endpoint
  3. Change the assertion-consumer URL while retaining the global issuer expectation
  4. Renew the signing certificate while preserving the old relying-party issuer expectation
  5. Change the invited user’s UserType from Guest to Member

Correct Answer: B

 

Correct Answer

Answer B is correct because Microsoft recommends the tenanted endpoint for new federations and documents failure when a new setup expects the old global issuer. The validation mismatch is at the partner IdP.

Incorrect Answers

Answer A is incorrect because NameID formatting concerns the represented identity. It does not correct the relying party’s mismatch with the tenant-specific request issuer.

Answer C is incorrect because response destination and request issuer are different trust settings. Adjusting the destination does not resolve the identified issuer validation failure.

Answer D is incorrect because a new signing certificate does not make the old global issuer expectation match the tenant-specific request. The diagnosed trust setting still needs correction.

Answer E is incorrect because the local relationship classification does not change the SAML request issuer expected by the external IdP.

 

Question 23

A domain-based external SAML federation receives a correctly signed assertion but rejects it with AADSTS5000819, indicating that the email claim is missing or does not match the external realm. The setup is not using a domainless federation feature. What should the administrator verify first?

  1. Replace the working signing certificate before inspecting claims
  2. Verify that the IdP sends the required email claim with a domain matching this federation configuration
  3. Change only the invitation’s post-acceptance redirect URL
  4. Reset invitation redemption without changing the IdP’s email claim
  5. Treat a valid signature as sufficient and ignore the realm mismatch

Correct Answer: B

 

Correct Answer

Answer B is correct because the error specifically identifies the identity claim or its domain alignment. A valid signature alone does not prove that the assertion contains the required identity information.

Incorrect Answers

Answer A is incorrect because the assertion’s signature is already verified. Changing the certificate does not address the stated missing or mismatched email claim.

Answer C is incorrect because navigation after redemption is not the source of the assertion’s email claim. The IdP claim configuration still needs verification.

Answer D is incorrect because rebinding the guest does not add a missing claim or align its domain in the external assertion. The IdP configuration would continue producing the same failure.

Answer E is incorrect because signature validation establishes integrity and issuer trust, not that every required claim and domain condition is satisfied.

 

Question 24

A partner rotates its SAML/WS-Fed signing certificate before the old certificate expires. The resource tenant has a metadata URL configured, but sign-ins fail after the early rotation. The partner confirms the new certificate. What should the administrator do under the documented renewal behavior?

  1. Wait until the old certificate expires and assume all earlier rotations refresh automatically
  2. Remove the metadata URL and retain the old signing certificate
  3. Change the assertion audience while retaining the old signing certificate
  4. Update the signing certificate in the federation configuration manually
  5. Reset every guest’s redemption status before updating the trust certificate

Correct Answer: D

 

Correct Answer

Answer D is correct because Microsoft documents that early rotation can require a manual update even when a metadata URL exists. The confirmed new certificate addresses the changed trust material.

Incorrect Answers

Answer A is incorrect because the documentation explicitly distinguishes early rotation from automatic renewal at expiration. Waiting prolongs the present outage.

Answer B is incorrect because removing metadata does not make the old certificate validate assertions signed by the new key. It also removes future automatic-renewal assistance.

Answer C is incorrect because audience validation and signature-key validation are distinct. Altering the audience does not allow the old configured key to validate assertions signed after rotation.

Answer E is incorrect because redemption rebinding does not make the configured old signing key validate the partner’s new signatures. The trust configuration needs correction.

img