Microsoft 365 Copilot AB-900 Privileged Identity Management App Registrations Practice Test

 

Skills 1.3 • 15 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on privileged identity management app registrations and enterprise applications through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

The IT team at Coho Winery wants to require time-bound or approval-based activation for sensitive Entra roles. Which Microsoft 365 capability should it use? The team will validate the result immediately after the change.

  1. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  2. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  3. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  4. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: A

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

B: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

C: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

D: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 2

While handling a admin-center audit, the SharePoint administrator needs to distinguish an application definition from its service principal instance in the tenant. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  2. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  5. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity

Correct answer: A

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

B: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

D: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

E: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 3

During a licensing change at Adventure Works, the Microsoft 365 administrator must reduce standing administrative privilege while preserving emergency access workflows. Which Microsoft 365 action or concept most directly satisfies the requirement? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  2. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  3. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  4. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  5. Use the Exchange admin center to configure the required mailbox or distribution group

Correct answer: D

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

B: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

C: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

D: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

E: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 4

Which Microsoft 365 concept is the strongest match for the following need at Blue Yonder Airlines: identify where an application identity is defined versus where the tenant manages the enterprise application instance? The choice should follow normal Microsoft 365 administrative practice.

  1. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  2. Use the Exchange admin center to configure the required mailbox or distribution group
  3. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  4. Use Microsoft Entra ID for cloud identity, authentication, and access management
  5. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control

Correct answer: A

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

B: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

C: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

D: Microsoft Entra ID is the identity and access service that underpins Microsoft 365 users, groups, authentication, and access controls. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

E: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 5

A support case at Relecloud says administrators must make a privileged role eligible and activated only when an administrator needs it. Which option is the best fit? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use the Exchange admin center to configure the required mailbox or distribution group
  2. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  3. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  4. Review Microsoft Entra sign-in information and the relevant Conditional Access, MFA, or risk details for the affected attempt
  5. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement

Correct answer: B

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

B: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

C: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

D: Microsoft Entra sign-in data exposes the authentication result, Conditional Access evaluation, and risk information needed for targeted troubleshooting. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

E: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 6

For a tenant cleanup at Lamna Healthcare, which Microsoft 365 approach correctly addresses the need to configure tenant-specific access and SSO for an application that already has an app registration? The team needs a direct administrative answer, not a broad redesign.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  3. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  4. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  5. Use Identity Secure Score to review identity-security recommendations and track posture improvements

Correct answer: B

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

B: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

C: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

D: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

E: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 7

The compliance administrator at Proseware is asked to require time-bound or approval-based activation for sensitive Entra roles. What is the most appropriate next step? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  2. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  3. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  4. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  5. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control

Correct answer: A

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

B: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

C: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

D: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

E: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 8

Which Microsoft 365 concept is the strongest match for the following need at Lucerne Publishing: distinguish an application definition from its service principal instance in the tenant? The solution should preserve least privilege and existing governance where possible.

  1. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  2. Use the Microsoft 365 admin center to review the tenant domain names and organization settings
  3. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  4. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  5. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control

Correct answer: D

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

B: The Microsoft 365 admin center provides tenant-level configuration, including domains and organization settings. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

C: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

D: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

E: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 9

An administrator reviewing new-user onboarding for City Power & Light must reduce standing administrative privilege while preserving emergency access workflows. Which Microsoft 365 control or object should be used? The team wants the smallest change that directly addresses the requirement.

  1. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  2. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  3. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  4. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  5. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach

Correct answer: C

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

B: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

C: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

D: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

E: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 10

A design review at Northwind Traders identifies one specific goal: identify where an application identity is defined versus where the tenant manages the enterprise application instance. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature
  2. Assign the least-privileged SharePoint site role or permission level that satisfies the user requirement
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  5. Evaluate authorization after authentication to determine what the identity is allowed to access or do

Correct answer: C

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

B: SharePoint site roles and permissions should be scoped to the content and actions the user actually needs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

D: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

E: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify where an application identity is defined versus where the tenant manages the enterprise application instance.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 11

The IT team at Fourth Coffee wants to make a privileged role eligible and activated only when an administrator needs it. Which Microsoft 365 capability should it use? The team will validate the result immediately after the change.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  5. Use the Exchange admin center to configure the required mailbox or distribution group

Correct answer: D

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

B: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

D: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

E: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to make a privileged role eligible and activated only when an administrator needs it.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 12

Which Microsoft 365 concept is the strongest match for the following need at Alpine Ski House: configure tenant-specific access and SSO for an application that already has an app registration? No unrelated tenant settings should be changed.

  1. Use the Teams admin center and configure the relevant team, channel, or Teams policy
  2. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach
  3. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO
  4. Use the Exchange admin center to configure the required mailbox or distribution group
  5. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials

Correct answer: C

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: Teams administration covers collaboration objects and policies that govern Teams behavior and access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

B: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

C: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

D: Mailboxes and distribution groups are Exchange Online recipient objects and are administered through Exchange management experiences. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

E: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to configure tenant-specific access and SSO for an application that already has an app registration.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 13

During a security review at Contoso, the service desk lead must require time-bound or approval-based activation for sensitive Entra roles. Which Microsoft 365 action or concept most directly satisfies the requirement? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use single sign-on so an authenticated user can access multiple integrated applications without repeatedly entering credentials
  3. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  4. Use a user object for an individual identity and a group when access or policy should be assigned to a collection of identities
  5. Assign the appropriate Microsoft 365 license to the user or eligible group that needs the feature

Correct answer: C

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

B: SSO improves usability and can centralize authentication while maintaining application authorization decisions. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

C: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

D: Users represent individual identities; groups provide a scalable target for access, licensing, and policy assignments where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

E: Feature access depends on the services included in the assigned license. Group-based licensing can simplify assignment for changing groups of users. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to require time-bound or approval-based activation for sensitive Entra roles.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Question 14

Litware is preparing a compliance assessment. The team needs to distinguish an application definition from its service principal instance in the tenant. What should the Copilot administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use a Microsoft Entra Conditional Access policy that evaluates the relevant conditions and applies the required access control
  2. Use Microsoft security threat-protection and threat-intelligence capabilities to detect, investigate, and understand malicious activity
  3. Evaluate authorization after authentication to determine what the identity is allowed to access or do
  4. Use Identity Secure Score to review identity-security recommendations and track posture improvements
  5. Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO

Correct answer: E

Why: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Option review:

A: Conditional Access evaluates signals and applies controls such as MFA, compliant device requirements, or blocking access. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

B: Threat protection and intelligence provide detections, context, and indicators that help security teams investigate and respond to attacks. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

C: Authentication establishes identity; authorization evaluates permissions, roles, policies, and resource access for that identity. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

D: Identity Secure Score summarizes identity security posture and provides recommended actions; it is not a guarantee that the tenant is secure. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to distinguish an application definition from its service principal instance in the tenant.

E: An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration. This directly addresses the stated requirement.

Learning point: Use an app registration for the application identity definition and the enterprise application service principal for tenant-specific access, assignments, consent, and SSO. An app registration creates or represents the application object; an enterprise application is the tenant service principal used for local access and sign-in configuration.

Question 15

A support case at Trey Research says administrators must reduce standing administrative privilege while preserving emergency access workflows. Which option is the best fit? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use an appropriate Microsoft Entra authentication method, such as passwordless or multifactor authentication, to verify the user identity
  2. Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation
  3. Use SharePoint administration and the appropriate site, library, or folder object for the requirement
  4. Review the appropriate Microsoft 365 or Microsoft Entra audit log for the recorded user or administrator activity
  5. Apply Zero Trust by verifying explicitly, using least-privilege access, and assuming breach

Correct answer: B

Why: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

Option review:

A: Authentication methods are mechanisms used to prove identity during sign-in; they are distinct from authorization. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

B: PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits. This directly addresses the stated requirement.

C: SharePoint content is organized into sites, libraries, folders, and items; choosing the correct scope avoids applying a control too broadly or too narrowly. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

D: Audit logs record supported administrative and user actions and are the correct starting point for who-did-what-and-when investigations. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

E: Zero Trust treats every access request as something to verify and limits privileges and impact if compromise occurs. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to reduce standing administrative privilege while preserving emergency access workflows.

Learning point: Use Microsoft Entra Privileged Identity Management to provide eligible, time-bound, and governed privileged-role activation. PIM reduces standing privilege by governing when privileged roles are activated and can enforce approval, MFA, justification, and time limits.

Popular posts

img