Microsoft MS-102 Identity Protection Conditional Access And MFA Practice Test
MS-102 skills 2.3 | 35 original questions
This MS-102 practice set focuses on identity protection conditional access and mfa through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
The security operations analyst at Southridge Video is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to validate Identity Protection behavior and user impact before applying risk remediation tenant-wide. The team will validate the change with 9 pilot groups before expanding it to 32 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
Option review:
A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
B: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q001: Pilot risk-based access controls with a scoped group before broad enforcement – Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk.
Question 2
Adventure Works is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to plan a consistent response to risky identities and risky authentication attempts. The design should minimize manual per-user administration where a scoped central control exists. The initial rollout covers 22 locations and approximately 490 managed identities or devices. Which administrative choice should be recommended?
Correct answer: B
Why: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
Option review:
A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
C: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q002: Define how user risk and sign-in risk will trigger remediation actions – Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy.
Question 3
Adventure Works is standardizing administration after several teams used inconsistent procedures. The next migration wave is blocked until the team can validate Identity Protection behavior and user impact before applying risk remediation tenant-wide. The team must preserve a clear audit trail for the administrative decision. The team will validate the change with 12 pilot groups before expanding it to 66 users. Which administrative choice should be recommended?
Correct answer: C
Why: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
Option review:
A: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q003: Pilot risk-based access controls with a scoped group before broad enforcement – Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk.
Question 4
A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. The organization is replacing a manual process. The replacement must plan a consistent response to risky identities and risky authentication attempts while remaining centrally manageable. The affected scope contains 83 users across 2 administrative groups. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which control should the team use?
Correct answer: D
Why: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
Option review:
A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q004: Define how user risk and sign-in risk will trigger remediation actions – Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy.
Question 5
The governance lead at Coho Winery is designing the next phase of the Microsoft 365 rollout. Security and operations teams agree on the target state: validate Identity Protection behavior and user impact before applying risk remediation tenant-wide. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 15 locations and approximately 90 managed identities or devices. Which approach most directly addresses the requirement?
Correct answer: E
Why: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
Option review:
A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
Learning point: MS102-T11-Q005: Pilot risk-based access controls with a scoped group before broad enforcement – Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk.
Question 6
Proseware Logistics has completed a pilot and must now choose the production administration approach. A controlled pilot must demonstrate how to plan a consistent response to risky identities and risky authentication attempts. The solution should use a native Microsoft control that matches the stated requirement. The control owner requires a review after 26 days and evidence from 5 representative cases. What is the most appropriate next step?
Correct answer: A
Why: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
Option review:
A: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. It directly addresses the stated requirement.
B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q006: Define how user risk and sign-in risk will trigger remediation actions – Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy.
Question 7
Graphic Design Institute has completed a pilot and must now choose the production administration approach. The existing configuration works for normal operations but fails the new requirement to validate Identity Protection behavior and user impact before applying risk remediation tenant-wide. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 43 related tickets from 18 business units, so the team wants a targeted fix. What should the administrator configure first?
Correct answer: B
Why: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
Option review:
A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. It directly addresses the stated requirement.
C: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q007: Pilot risk-based access controls with a scoped group before broad enforcement – Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk.
Question 8
Wide World Importers has completed a pilot and must now choose the production administration approach. A post-incident action item requires the tenant to review detected user or sign-in risk and the evidence behind the detection. The affected scope contains 60 users across 8 administrative groups. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which approach most directly addresses the requirement?
Correct answer: C
Why: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
Option review:
A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q008: Use the Risky users and Risky sign-ins views to investigate identity risk – Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation.
Question 9
An incident review at Wingtip Services produces a single administrative requirement for the messaging administrator. The next migration wave is blocked until the team can update the user risk state after validating that the account is compromised. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 77 related tickets from 21 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
Option review:
A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q009: Confirm user compromise only when investigation supports that conclusion – Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection.
Question 10
During a tenant review at Fourth Coffee, the compliance administrator identifies one unresolved requirement. The organization is replacing a manual process. The replacement must review detected user or sign-in risk and the evidence behind the detection while remaining centrally manageable. The control owner requires a review after 94 days and evidence from 11 representative cases. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which action should the administrator take?
Correct answer: E
Why: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
Option review:
A: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
Learning point: MS102-T11-Q010: Use the Risky users and Risky sign-ins views to investigate identity risk – Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation.
Question 11
Trey Research is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The next migration wave is blocked until the team can update the user risk state after validating that the account is compromised. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 20 days and evidence from 24 representative cases. Which approach most directly addresses the requirement?
Correct answer: A
Why: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
Option review:
A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q011: Confirm user compromise only when investigation supports that conclusion – Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection.
Question 12
Humongous Insurance is migrating a business process to Microsoft 365 and wants the narrowest supported solution. An internal assessment finds the control technically functional but unable to review detected user or sign-in risk and the evidence behind the detection. The team will validate the change with 14 pilot groups before expanding it to 37 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: B
Why: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
Option review:
A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q012: Use the Risky users and Risky sign-ins views to investigate identity risk – Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation.
Question 13
VanArsdel Media is preparing a change requested by the security operations analyst. A post-incident action item requires the tenant to update the user risk state after validating that the account is compromised. The team will validate the change with 4 pilot groups before expanding it to 54 users. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?
Correct answer: C
Why: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
Option review:
A: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. It directly addresses the stated requirement.
D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q013: Confirm user compromise only when investigation supports that conclusion – Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection.
Question 14
A quarterly control review at Wide World Importers identifies a gap that must be corrected before the next audit. The organization is replacing a manual process. The replacement must review detected user or sign-in risk and the evidence behind the detection while remaining centrally manageable. The team will validate the change with 17 pilot groups before expanding it to 71 users. The design should minimize manual per-user administration where a scoped central control exists. What is the most appropriate next step?
Correct answer: D
Why: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
Option review:
A: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. It directly addresses the stated requirement.
E: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q014: Use the Risky users and Risky sign-ins views to investigate identity risk – Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation.
Question 15
A quarterly control review at Lucerne Publishing identifies a gap that must be corrected before the next audit. The change advisory board wants the smallest supported control that can evaluate how the policy would apply before enforcing it against users. The team will validate the change with 7 pilot groups before expanding it to 88 users. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: E
Why: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
Option review:
A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
Learning point: MS102-T11-Q015: Start a new Conditional Access policy in report-only mode – Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users.
Question 16
Coho Winery has completed a pilot and must now choose the production administration approach. A production change is approved only if it can preserve a controlled recovery path if a Conditional Access configuration causes lockout. The architecture board will reject a choice that solves a different problem from the one stated. The team will validate the change with 20 pilot groups before expanding it to 14 users. What should the administrator configure first?
Correct answer: A
Why: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
Option review:
A: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q016: Exclude emergency access accounts from policies that could block all administrators – Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path.
Question 17
The operations team at Fabrikam Health needs to resolve an issue without granting broader permissions than necessary. A controlled pilot must demonstrate how to evaluate how the policy would apply before enforcing it against users. The team must preserve a clear audit trail for the administrative decision. The initial rollout covers 10 locations and approximately 310 managed identities or devices. Which administrative choice should be recommended?
Correct answer: B
Why: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
Option review:
A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
C: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q017: Start a new Conditional Access policy in report-only mode – Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users.
Question 18
The service desk lead at Contoso Retail is designing the next phase of the Microsoft 365 rollout. Audit evidence shows that the current process cannot reliably preserve a controlled recovery path if a Conditional Access configuration causes lockout. The design should minimize manual per-user administration where a scoped central control exists. The team will validate the change with 23 pilot groups before expanding it to 48 users. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
Option review:
A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q018: Exclude emergency access accounts from policies that could block all administrators – Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path.
Question 19
An incident review at Blue Yonder Airlines produces a single administrative requirement for the identity administrator. A post-incident action item requires the tenant to evaluate how the policy would apply before enforcing it against users. The initial rollout covers 13 locations and approximately 650 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?
Correct answer: D
Why: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
Option review:
A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q019: Start a new Conditional Access policy in report-only mode – Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users.
Question 20
An incident review at Humongous Insurance produces a single administrative requirement for the security operations analyst. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to preserve a controlled recovery path if a Conditional Access configuration causes lockout. The response must address the cause described in the scenario rather than simply suppressing the symptom. The service desk has 82 related tickets from 3 business units, so the team wants a targeted fix. Which action should the administrator take?
Correct answer: E
Why: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
Option review:
A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. It directly addresses the stated requirement.
Learning point: MS102-T11-Q020: Exclude emergency access accounts from policies that could block all administrators – Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path.
Question 21
VanArsdel Media is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A post-incident action item requires the tenant to evaluate how the policy would apply before enforcing it against users. The affected scope contains 8 users across 16 administrative groups. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
Option review:
A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. It directly addresses the stated requirement.
B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q021: Start a new Conditional Access policy in report-only mode – Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users.
Question 22
During a tenant review at Margie Travel, the tenant administrator identifies one unresolved requirement. The change advisory board wants the smallest supported control that can enforce access based on signals such as user, application, location, device, or risk. The control owner requires a review after 25 days and evidence from 6 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?
Correct answer: B
Why: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
Option review:
A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q022: Configure Conditional Access conditions and grant controls for the required scenario – Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements.
Question 23
VanArsdel Media is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The current workaround is too manual. The replacement should apply a consistent identity control across scoped cloud apps. The team will validate the change with 19 pilot groups before expanding it to 42 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which control should the team use?
Correct answer: C
Why: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
Option review:
A: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q023: Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement – Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope.
Question 24
During a tenant review at Proseware Logistics, the hybrid identity engineer identifies one unresolved requirement. Security and operations teams agree on the target state: enforce access based on signals such as user, application, location, device, or risk. The team must preserve a clear audit trail for the administrative decision. The affected scope contains 59 users across 9 administrative groups. Which control should the team use?
Correct answer: D
Why: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
Option review:
A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
E: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q024: Configure Conditional Access conditions and grant controls for the required scenario – Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements.
Question 25
An incident review at Litware Financial produces a single administrative requirement for the tenant administrator. A post-incident action item requires the tenant to apply a consistent identity control across scoped cloud apps. The affected scope contains 76 users across 22 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?
Correct answer: E
Why: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
Option review:
A: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
Learning point: MS102-T11-Q025: Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement – Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope.
Question 26
Blue Yonder Airlines is preparing a change requested by the Microsoft 365 administrator. The next migration wave is blocked until the team can enforce access based on signals such as user, application, location, device, or risk. The change must be repeatable and supportable after the project team leaves. The affected scope contains 93 users across 12 administrative groups. Which administrative choice should be recommended?
Correct answer: A
Why: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
Option review:
A: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q026: Configure Conditional Access conditions and grant controls for the required scenario – Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements.
Question 27
VanArsdel Media is preparing a change requested by the governance lead. The service owner wants a supportable design that will apply a consistent identity control across scoped cloud apps. The architecture board will reject a choice that solves a different problem from the one stated. The service desk has 19 related tickets from 2 business units, so the team wants a targeted fix. What is the most appropriate next step?
Correct answer: B
Why: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
Option review:
A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. It directly addresses the stated requirement.
C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q027: Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement – Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope.
Question 28
During a tenant review at Datum Dynamics, the compliance administrator identifies one unresolved requirement. The existing configuration works for normal operations but fails the new requirement to enforce access based on signals such as user, application, location, device, or risk. The change must be repeatable and supportable after the project team leaves. The team will validate the change with 15 pilot groups before expanding it to 36 users. Which action should the administrator take?
Correct answer: C
Why: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
Option review:
A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. It directly addresses the stated requirement.
D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q028: Configure Conditional Access conditions and grant controls for the required scenario – Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements.
Question 29
An incident review at Blue Yonder Airlines produces a single administrative requirement for the identity administrator. The project board will approve the next step only if it can enforce MFA for the selected users, applications, and conditions. The control owner requires a review after 53 days and evidence from 5 representative cases. The architecture board will reject a choice that solves a different problem from the one stated. Which action should the administrator take?
Correct answer: D
Why: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
Option review:
A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
E: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q029: Require multifactor authentication with a Conditional Access grant control – A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope.
Question 30
City Power & Light has completed a pilot and must now choose the production administration approach. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to require a defined set of acceptable authentication method combinations rather than any MFA method. The initial rollout covers 18 locations and approximately 700 managed identities or devices. The change must be repeatable and supportable after the project team leaves. What should the administrator configure first?
Correct answer: E
Why: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
Option review:
A: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
Learning point: MS102-T11-Q030: Use an authentication strength in Conditional Access when a specific strength of MFA is required – Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient.
Question 31
The operations team at Blue Yonder Airlines needs to resolve an issue without granting broader permissions than necessary. The implementation review is focused on one outcome: enforce MFA for the selected users, applications, and conditions. The control owner requires a review after 87 days and evidence from 8 representative cases. The team does not want to redesign unrelated workloads. Which action should the administrator take?
Correct answer: A
Why: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
Option review:
A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q031: Require multifactor authentication with a Conditional Access grant control – A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope.
Question 32
The governance lead at Northwind Traders is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: require a defined set of acceptable authentication method combinations rather than any MFA method. The team will validate the change with 21 pilot groups before expanding it to 13 users. The solution should use a native Microsoft control that matches the stated requirement. Which approach most directly addresses the requirement?
Correct answer: B
Why: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
Option review:
A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q032: Use an authentication strength in Conditional Access when a specific strength of MFA is required – Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient.
Question 33
The security operations analyst at Datum Dynamics is designing the next phase of the Microsoft 365 rollout. The existing configuration works for normal operations but fails the new requirement to enforce MFA for the selected users, applications, and conditions. The solution should use a native Microsoft control that matches the stated requirement. The control owner requires a review after 30 days and evidence from 11 representative cases. Which option best satisfies the requirement?
Correct answer: C
Why: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
Option review:
A: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
D: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q033: Require multifactor authentication with a Conditional Access grant control – A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope.
Question 34
The tenant administrator at Margie Travel is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: require a defined set of acceptable authentication method combinations rather than any MFA method. The affected scope contains 47 users across 24 administrative groups. The solution should use a native Microsoft control that matches the stated requirement. Which administrative choice should be recommended?
Correct answer: D
Why: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
Option review:
A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. It directly addresses the stated requirement.
E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T11-Q034: Use an authentication strength in Conditional Access when a specific strength of MFA is required – Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient.
Question 35
During a tenant review at Wide World Importers, the governance lead identifies one unresolved requirement. Administrators have confirmed the present design does not enforce MFA for the selected users, applications, and conditions. The control owner requires a review after 64 days and evidence from 14 representative cases. The solution should use a native Microsoft control that matches the stated requirement. Which administrative choice should be recommended?
Correct answer: E
Why: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
Option review:
A: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. It directly addresses the stated requirement.
Learning point: MS102-T11-Q035: Require multifactor authentication with a Conditional Access grant control – A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope.
Popular posts
Recent Posts
