Microsoft 365 Copilot AB-900 Zero Trust Authorization And Authentication Methods Practice Test

 

Skills 1.2 • 30 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on zero trust authorization and authentication methods through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

The service desk lead at Relecloud is asked to limit the blast radius of a compromised account. What is the most appropriate next step? The team wants the smallest change that directly addresses the requirement.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: A

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 2

Lamna Healthcare has validated the surrounding services. The remaining requirement is to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which choice is correct? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Use Microsoft Entra ID for cloud identity, authentication, and access management
  3. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Use Identity Secure Score to review identity-security recommendations and track posture improvements

Correct answer: D

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

E: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 3

An administrator reviewing identity hardening effort for Proseware must strengthen sign-in by requiring an additional factor. Which Microsoft 365 control or object should be used? The team will validate the result immediately after the change.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: E

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 4

Which Microsoft 365 concept is the strongest match for the following need at Lucerne Publishing: limit the blast radius of a compromised account? No unrelated tenant settings should be changed.

  1. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  2. Use Microsoft Entra ID for cloud identity, authentication, and access management
  3. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: D

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 5

The IT team at City Power & Light wants to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which Microsoft 365 capability should it use? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  2. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity

Correct answer: D

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

E: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 6

While handling a service desk escalation, the SharePoint administrator needs to strengthen sign-in by requiring an additional factor. Which answer most directly addresses the stated need? The choice should follow normal Microsoft 365 administrative practice.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  4. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  5. Use the Exchange admin center to configure the required mailbox or distribution group

Correct answer: D

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

E: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 7

During a production readiness check at Fourth Coffee, the Microsoft 365 administrator must limit the blast radius of a compromised account. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use Microsoft Entra ID for cloud identity, authentication, and access management
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: D

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 8

Which Microsoft 365 concept is the strongest match for the following need at Alpine Ski House: explain why successful sign-in does not automatically grant access to every Microsoft 365 resource? The team needs a direct administrative answer, not a broad redesign.

  1. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Use the Exchange admin center to configure the required mailbox or distribution group
  4. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  5. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities

Correct answer: B

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

C: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 9

A support case at Contoso says administrators must strengthen sign-in by requiring an additional factor. Which option is the best fit? The administrator wants an action that is easy to audit later.

  1. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  4. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  5. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity

Correct answer: B

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

C: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 10

For a agent governance review at Litware, which Microsoft 365 approach correctly addresses the need to limit the blast radius of a compromised account? The solution should preserve least privilege and existing governance where possible.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  4. Use Microsoft Entra ID for cloud identity, authentication, and access management
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: A

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 11

The compliance administrator at Trey Research is asked to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. What is the most appropriate next step? The team wants the smallest change that directly addresses the requirement.

  1. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  2. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: C

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

D: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 12

Which Microsoft 365 concept is the strongest match for the following need at Consolidated Messenger: strengthen sign-in by requiring an additional factor? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: D

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 13

An administrator reviewing licensing change for Woodgrove Bank must limit the blast radius of a compromised account. Which Microsoft 365 control or object should be used? The team will validate the result immediately after the change.

  1. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  2. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  3. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  4. Use the Exchange admin center to configure the required mailbox or distribution group
  5. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity

Correct answer: B

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

C: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

E: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 14

A design review at Wide World Importers identifies one specific goal: explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which option best matches that goal? No unrelated tenant settings should be changed.

  1. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  2. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: C

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 15

The IT team at Southridge Video wants to strengthen sign-in by requiring an additional factor. Which Microsoft 365 capability should it use? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  2. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: E

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 16

Which Microsoft 365 concept is the strongest match for the following need at Fabrikam: limit the blast radius of a compromised account? The choice should follow normal Microsoft 365 administrative practice.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use Microsoft Entra ID for cloud identity, authentication, and access management
  3. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities

Correct answer: D

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

E: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 17

During a Copilot adoption project at Wingtip Toys, the service desk lead must explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use the Exchange admin center to configure the required mailbox or distribution group
  2. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  3. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads
  4. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  5. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials

Correct answer: B

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

C: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 18

VanArsdel is preparing a identity hardening effort. The team needs to strengthen sign-in by requiring an additional factor. What should the Copilot administrator choose? The team needs a direct administrative answer, not a broad redesign.

  1. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  2. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  3. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  4. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: D

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 19

A support case at Bellows College says administrators must limit the blast radius of a compromised account. Which option is the best fit? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Entra ID for cloud identity, authentication, and access management
  2. Use the Exchange admin center to configure the required mailbox or distribution group
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: D

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 20

Which Microsoft 365 concept is the strongest match for the following need at Tailspin Toys: explain why successful sign-in does not automatically grant access to every Microsoft 365 resource? The solution should preserve least privilege and existing governance where possible.

  1. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  2. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Use the Teams admin center and configure the relevant team, channel, or Teams policy

Correct answer: D

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

E: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 21

The identity administrator at Coho Winery is asked to strengthen sign-in by requiring an additional factor. What is the most appropriate next step? The team wants the smallest change that directly addresses the requirement.

  1. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Use the Exchange admin center to configure the required mailbox or distribution group
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: B

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

C: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 22

Humongous Insurance has validated the surrounding services. The remaining requirement is to limit the blast radius of a compromised account. Which choice is correct? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Use Microsoft Entra ID for cloud identity, authentication, and access management
  5. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach

Correct answer: E

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

E: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 23

An administrator reviewing security review for Adventure Works must explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which Microsoft 365 control or object should be used? The team will validate the result immediately after the change.

  1. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  2. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  3. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: E

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 24

Which Microsoft 365 concept is the strongest match for the following need at Blue Yonder Airlines: strengthen sign-in by requiring an additional factor? No unrelated tenant settings should be changed.

  1. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities

Correct answer: B

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 25

The IT team at Relecloud wants to limit the blast radius of a compromised account. Which Microsoft 365 capability should it use? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use Microsoft Entra ID for cloud identity, authentication, and access management
  2. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  3. Use the Exchange admin center to configure the required mailbox or distribution group
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: D

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

C: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 26

While handling a data protection review, the Copilot administrator needs to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which answer most directly addresses the stated need? The choice should follow normal Microsoft 365 administrative practice.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use the Exchange admin center to configure the required mailbox or distribution group
  3. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Use Identity Secure Score to review identity-security recommendations and track posture improvements

Correct answer: D

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

B: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

E: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 27

During a admin-center audit at Proseware, the compliance administrator must strengthen sign-in by requiring an additional factor. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Use Microsoft Defender XDR to correlate alerts and investigate incidents across supported Microsoft security workloads

Correct answer: C

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

C: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Defender XDR provides cross-domain detection, incident correlation, investigation, and response across Microsoft security signals. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Question 28

Which Microsoft 365 concept is the strongest match for the following need at Lucerne Publishing: limit the blast radius of a compromised account? The team needs a direct administrative answer, not a broad redesign.

  1. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  2. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  5. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation

Correct answer: B

Why: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

Option review:

A: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

B: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This directly addresses the stated requirement.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

D: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

E: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to limit the blast radius of a compromised account.

Learning point: Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach. Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs.

Question 29

A support case at City Power & Light says administrators must explain why successful sign-in does not automatically grant access to every Microsoft 365 resource. Which option is the best fit? The administrator wants an action that is easy to audit later.

  1. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  2. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: A

Why: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

Option review:

A: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This directly addresses the stated requirement.

B: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explain why successful sign-in does not automatically grant access to every Microsoft 365 resource.

Learning point: Evaluate authorization after authentication to determine what the identity is allowed to access or do. Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity.

Question 30

For a pilot rollout at Northwind Traders, which Microsoft 365 approach correctly addresses the need to strengthen sign-in by requiring an additional factor? The solution should preserve least privilege and existing governance where possible.

  1. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Use the Exchange admin center to configure the required mailbox or distribution group
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: B

Why: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

Option review:

A: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This directly addresses the stated requirement.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

D: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to strengthen sign-in by requiring an additional factor.

Learning point: Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity. Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization.

Popular posts

img