Microsoft SC-300 Enterprise Applications SSO Consent and App Proxy Practice Test

 

Topic 10 covers enterprise applications, sso, consent, and app proxy for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

Testing of an enterprise-application integration is successful except for this condition: enforcement of user assignment for the restricted application. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Assign app access through supported group membership at the narrowest required scope in enterprise application and Application Proxy.
  2. Configure identifier and reply url against vendor metadata in enterprise application and Application Proxy and verify the effective result.
  3. Enable user assignment required on the enterprise application and assign only the authorized users/groups.
  4. Assign the least-privilege application-administration role that supports the required operation.
  5. Choose Microsoft Entra preauthentication when Entra controls must apply before access, or passthrough only when the stated requirement explicitly needs backend authentication without Entra preauthentication.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides the required setting for user assignment requirement for restricted application. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is assignment of app access through supported group membership. The scenario instead requires the required setting for user assignment requirement for restricted application, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is correct configuration of identifier and reply URL against vendor metadata. The scenario instead requires the required setting for user assignment requirement for restricted application, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate Cloud Application Administrator with App Proxy constraint. The scenario instead requires the required setting for user assignment requirement for restricted application, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate preauthentication versus passthrough for requirement. The scenario instead requires the required setting for user assignment requirement for restricted application, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 2

The organization wants the least-disruptive correction to an enterprise application requesting delegated API permissions. It must provide: resolution of tenant user-consent default versus application need. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Map only the claims the SaaS application requires and verify they match the vendor’s account-matching rules.
  2. Configure the Application Proxy SSO method that matches the backend protocol and identity requirements.
  3. Apply the tenant user-consent policy that permits only the intended low-risk delegated permissions or requires admin approval.
  4. Delegate application ownership for single-app administration through the narrowest supported enterprise application and Application Proxy role or ownership scope.
  5. Map users or groups to correct application role to the exact identity or application attribute required by the target.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides resolution of tenant user-consent default versus application need. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is mapping of claims to SaaS account matching requirement. The scenario instead requires resolution of tenant user-consent default versus application need, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is correct configuration of single sign-on for supported backend protocol. The scenario instead requires resolution of tenant user-consent default versus application need, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is delegate application ownership for single-app administration. The scenario instead requires resolution of tenant user-consent default versus application need, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is mapping of users or groups to correct application role. The scenario instead requires resolution of tenant user-consent default versus application need, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 3

A design review of an enterprise-application integration identifies one remaining requirement: correct configuration of app visibility without confusing authorization. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Classify application for access-management reporting requirement using the supported enterprise application and Application Proxy metadata and reporting fields.
  2. Correct the Application Proxy internal/external URL configuration so the connector can reach the backend and users address the published endpoint.
  3. Configure application visibility separately from authorization; hiding an app does not grant or revoke access.
  4. Coordinate the enterprise-app signing certificate rollover with the SaaS provider before the old certificate expires.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to distinguish application management from high-privilege consent authority.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides correct configuration of app visibility without confusing authorization. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is classify application for access-management reporting requirement. The scenario instead requires correct configuration of app visibility without confusing authorization, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of internal URL versus external URL mismatch. The scenario instead requires correct configuration of app visibility without confusing authorization, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is a controlled plan for signing-certificate rollover with vendor coordination. The scenario instead requires correct configuration of app visibility without confusing authorization, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between application management and high-privilege consent authority. The scenario instead requires correct configuration of app visibility without confusing authorization, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 4

Current evidence from an enterprise-application integration shows that this requirement is not yet met: diagnosis of disabled application sign-in versus user assignment. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?

  1. Use Microsoft Entra Application Proxy with correctly placed connectors and the required preauthentication/SSO settings for the on-premises web app.
  2. Place Application Proxy connectors in a connector group that can reach the application and provide the required availability.
  3. Configure automated provisioning separately from federation/SSO because account lifecycle and authentication are distinct.
  4. Check the enterprise application’s enabled-for-users-to-sign-in state separately from user/group assignment.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose assignment present but app authorization missing.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides diagnosis of disabled application sign-in versus user assignment. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate Application Proxy for on-premises web publishing. The scenario instead requires diagnosis of disabled application sign-in versus user assignment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is resolution of connector-group placement and availability issue. The scenario instead requires diagnosis of disabled application sign-in versus user assignment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between provisioning and federation sign-in. The scenario instead requires diagnosis of disabled application sign-in versus user assignment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of assignment present but app authorization missing. The scenario instead requires diagnosis of disabled application sign-in versus user assignment, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 5

Before expanding an enterprise-application integration, the administrator must satisfy this condition: the appropriate Application Administrator for required app operation. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Deploy connector with internal resource reachability with the enterprise application and Application Proxy topology required for reachability and availability.
  2. Configure the SaaS federation using the protocol and metadata the application supports, such as SAML when the vendor requires SAML.
  3. Use the admin-consent workflow for permissions that users are not allowed to consent to themselves.
  4. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose sso failure from assertion or token evidence.
  5. Assign the least-privilege application-administration role that supports the required operation.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides the appropriate Application Administrator for required app operation. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is deployment of connector with internal resource reachability. The scenario instead requires the appropriate Application Administrator for required app operation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate SAML versus OIDC integration for SaaS capability. The scenario instead requires the appropriate Application Administrator for required app operation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate delegated user consent versus admin consent. The scenario instead requires the appropriate Application Administrator for required app operation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is diagnosis of SSO failure from assertion or token evidence. The scenario instead requires the appropriate Application Administrator for required app operation, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 6

The administrator is preparing an enterprise-application integration for production. The required condition is: the appropriate Cloud Application Administrator with App Proxy constraint. General network connectivity outside the identity path is already verified. Choose TWO actions that together implement and verify the requirement.

  1. Configure identifier and reply url against vendor metadata in enterprise application and Application Proxy and verify the effective result.
  2. Assign app access through supported group membership at the narrowest required scope in enterprise application and Application Proxy.
  3. Choose Microsoft Entra preauthentication when Entra controls must apply before access, or passthrough only when the stated requirement explicitly needs backend authentication without Entra preauthentication.
  4. Assign the least-privilege application-administration role that supports the required operation.
  5. Validate the enterprise application assignment/SSO result with a pilot user and inspect the application sign-in evidence.
  6. Limit user consent to verified low-risk permissions to the scope required by the scenario in enterprise application and Application Proxy.

Correct Answers: D, E

 

Correct Answers

Answer D is correct because This action directly provides the appropriate Cloud Application Administrator with App Proxy constraint at the correct Microsoft Entra control boundary.

Answer E is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is correct configuration of identifier and reply URL against vendor metadata. It does not implement or verify the appropriate Cloud Application Administrator with App Proxy constraint in this scenario.

Answer B is incorrect because This action is appropriate when the requirement is assignment of app access through supported group membership. It does not implement or verify the appropriate Cloud Application Administrator with App Proxy constraint in this scenario.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate preauthentication versus passthrough for requirement. It does not implement or verify the appropriate Cloud Application Administrator with App Proxy constraint in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is limitation of user consent to verified low-risk permissions. It does not implement or verify the appropriate Cloud Application Administrator with App Proxy constraint in this scenario.

 

Question 7

A production issue involving an enterprise-application integration has been narrowed to this requirement: delegate application ownership for single-app administration. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?

  1. Map users or groups to correct application role to the exact identity or application attribute required by the target.
  2. Map only the claims the SaaS application requires and verify they match the vendor’s account-matching rules.
  3. Configure the Application Proxy SSO method that matches the backend protocol and identity requirements.
  4. Delegate application ownership for single-app administration through the narrowest supported enterprise application and Application Proxy role or ownership scope.
  5. Process admin-consent request with least privilege through the supported enterprise application and Application Proxy workflow.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides delegate application ownership for single-app administration. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is mapping of users or groups to correct application role. The scenario instead requires delegate application ownership for single-app administration, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is mapping of claims to SaaS account matching requirement. The scenario instead requires delegate application ownership for single-app administration, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is correct configuration of single sign-on for supported backend protocol. The scenario instead requires delegate application ownership for single-app administration, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is processing of admin-consent request with least privilege. The scenario instead requires delegate application ownership for single-app administration, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 8

The security review of an enterprise application requesting delegated API permissions focuses on one acceptance criterion: a clear distinction between application management and high-privilege consent authority. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Classify application for access-management reporting requirement using the supported enterprise application and Application Proxy metadata and reporting fields.
  2. Revoke grant after changed business requirement through enterprise application and Application Proxy and verify whether any separate application session remains.
  3. Coordinate the enterprise-app signing certificate rollover with the SaaS provider before the old certificate expires.
  4. Correct the Application Proxy internal/external URL configuration so the connector can reach the backend and users address the published endpoint.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to distinguish application management from high-privilege consent authority.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides a clear distinction between application management and high-privilege consent authority. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is classify application for access-management reporting requirement. The scenario instead requires a clear distinction between application management and high-privilege consent authority, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is revocation of grant after changed business requirement. The scenario instead requires a clear distinction between application management and high-privilege consent authority, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a controlled plan for signing-certificate rollover with vendor coordination. The scenario instead requires a clear distinction between application management and high-privilege consent authority, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is diagnosis of internal URL versus external URL mismatch. The scenario instead requires a clear distinction between application management and high-privilege consent authority, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 9

The team is validating an on-premises web application being published through Application Proxy. The decisive requirement is: the appropriate Application Proxy for on-premises web publishing. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Place Application Proxy connectors in a connector group that can reach the application and provide the required availability.
  2. Configure automated provisioning separately from federation/SSO because account lifecycle and authentication are distinct.
  3. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose assignment present but app authorization missing.
  4. Create collection for business-function application discovery in enterprise application and Application Proxy with the required scope and ownership.
  5. Use Microsoft Entra Application Proxy with correctly placed connectors and the required preauthentication/SSO settings for the on-premises web app.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides the appropriate Application Proxy for on-premises web publishing. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is resolution of connector-group placement and availability issue. The scenario instead requires the appropriate Application Proxy for on-premises web publishing, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between provisioning and federation sign-in. The scenario instead requires the appropriate Application Proxy for on-premises web publishing, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is diagnosis of assignment present but app authorization missing. The scenario instead requires the appropriate Application Proxy for on-premises web publishing, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is creation of collection for business-function application discovery. The scenario instead requires the appropriate Application Proxy for on-premises web publishing, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 10

Operations staff investigating an enterprise-application integration have isolated the issue to: deployment of connector with internal resource reachability. The current population and assignment scope must be preserved. Which action best satisfies the requirement?

  1. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose sso failure from assertion or token evidence.
  2. Assign collection audience without granting underlying app access at the narrowest required scope in enterprise application and Application Proxy.
  3. Use the admin-consent workflow for permissions that users are not allowed to consent to themselves.
  4. Configure the SaaS federation using the protocol and metadata the application supports, such as SAML when the vendor requires SAML.
  5. Deploy connector with internal resource reachability with the enterprise application and Application Proxy topology required for reachability and availability.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides deployment of connector with internal resource reachability. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of SSO failure from assertion or token evidence. The scenario instead requires deployment of connector with internal resource reachability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is assignment of collection audience without granting underlying app access. The scenario instead requires deployment of connector with internal resource reachability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate delegated user consent versus admin consent. The scenario instead requires deployment of connector with internal resource reachability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate SAML versus OIDC integration for SaaS capability. The scenario instead requires deployment of connector with internal resource reachability, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 11

The administrator must correct an enterprise-application integration without changing adjacent controls. The target condition is: the appropriate preauthentication versus passthrough for requirement. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Choose Microsoft Entra preauthentication when Entra controls must apply before access, or passthrough only when the stated requirement explicitly needs backend authentication without Entra preauthentication.
  2. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose missing app from user collection view.
  3. Configure identifier and reply url against vendor metadata in enterprise application and Application Proxy and verify the effective result.
  4. Assign app access through supported group membership at the narrowest required scope in enterprise application and Application Proxy.
  5. Limit user consent to verified low-risk permissions to the scope required by the scenario in enterprise application and Application Proxy.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides the appropriate preauthentication versus passthrough for requirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of missing app from user collection view. The scenario instead requires the appropriate preauthentication versus passthrough for requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is correct configuration of identifier and reply URL against vendor metadata. The scenario instead requires the appropriate preauthentication versus passthrough for requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is assignment of app access through supported group membership. The scenario instead requires the appropriate preauthentication versus passthrough for requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is limitation of user consent to verified low-risk permissions. The scenario instead requires the appropriate preauthentication versus passthrough for requirement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 12

An audit of an enterprise-application integration identifies this control gap: correct configuration of single sign-on for supported backend protocol. The change will be piloted before broader enforcement. Choose TWO actions that together implement and verify the requirement.

  1. Map only the claims the SaaS application requires and verify they match the vendor’s account-matching rules.
  2. Configure the Application Proxy SSO method that matches the backend protocol and identity requirements.
  3. Reorganize collections while preserving app assignments without changing the underlying application assignments.
  4. Process admin-consent request with least privilege through the supported enterprise application and Application Proxy workflow.
  5. Validate the enterprise application assignment/SSO result with a pilot user and inspect the application sign-in evidence.
  6. Map users or groups to correct application role to the exact identity or application attribute required by the target.

Correct Answers: B, E

 

Correct Answers

Answer B is correct because This action directly provides correct configuration of single sign-on for supported backend protocol at the correct Microsoft Entra control boundary.

Answer E is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is mapping of claims to SaaS account matching requirement. It does not implement or verify correct configuration of single sign-on for supported backend protocol in this scenario.

Answer C is incorrect because This action is appropriate when the requirement is reorganize collections while preserving app assignments. It does not implement or verify correct configuration of single sign-on for supported backend protocol in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is processing of admin-consent request with least privilege. It does not implement or verify correct configuration of single sign-on for supported backend protocol in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is mapping of users or groups to correct application role. It does not implement or verify correct configuration of single sign-on for supported backend protocol in this scenario.

 

Question 13

The documented success criterion for an enterprise-application integration is: diagnosis of internal URL versus external URL mismatch. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Classify application for access-management reporting requirement using the supported enterprise application and Application Proxy metadata and reporting fields.
  2. Correct the Application Proxy internal/external URL configuration so the connector can reach the backend and users address the published endpoint.
  3. Enable user assignment required on the enterprise application and assign only the authorized users/groups.
  4. Revoke grant after changed business requirement through enterprise application and Application Proxy and verify whether any separate application session remains.
  5. Coordinate the enterprise-app signing certificate rollover with the SaaS provider before the old certificate expires.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides diagnosis of internal URL versus external URL mismatch. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is classify application for access-management reporting requirement. The scenario instead requires diagnosis of internal URL versus external URL mismatch, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the required setting for user assignment requirement for restricted application. The scenario instead requires diagnosis of internal URL versus external URL mismatch, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is revocation of grant after changed business requirement. The scenario instead requires diagnosis of internal URL versus external URL mismatch, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a controlled plan for signing-certificate rollover with vendor coordination. The scenario instead requires diagnosis of internal URL versus external URL mismatch, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 14

The current configuration of an enterprise-application integration is otherwise acceptable. The unresolved requirement is: resolution of connector-group placement and availability issue. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?

  1. Apply the tenant user-consent policy that permits only the intended low-risk delegated permissions or requires admin approval.
  2. Place Application Proxy connectors in a connector group that can reach the application and provide the required availability.
  3. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose assignment present but app authorization missing.
  4. Configure automated provisioning separately from federation/SSO because account lifecycle and authentication are distinct.
  5. Create collection for business-function application discovery in enterprise application and Application Proxy with the required scope and ownership.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides resolution of connector-group placement and availability issue. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is resolution of tenant user-consent default versus application need. The scenario instead requires resolution of connector-group placement and availability issue, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is diagnosis of assignment present but app authorization missing. The scenario instead requires resolution of connector-group placement and availability issue, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between provisioning and federation sign-in. The scenario instead requires resolution of connector-group placement and availability issue, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is creation of collection for business-function application discovery. The scenario instead requires resolution of connector-group placement and availability issue, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 15

A troubleshooting review of a SaaS application that supplies SAML federation metadata confirms that the next action must address: the appropriate SAML versus OIDC integration for SaaS capability. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Assign collection audience without granting underlying app access at the narrowest required scope in enterprise application and Application Proxy.
  2. Use the admin-consent workflow for permissions that users are not allowed to consent to themselves.
  3. Configure the SaaS federation using the protocol and metadata the application supports, such as SAML when the vendor requires SAML.
  4. Configure application visibility separately from authorization; hiding an app does not grant or revoke access.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose sso failure from assertion or token evidence.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides the appropriate SAML versus OIDC integration for SaaS capability. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is assignment of collection audience without granting underlying app access. The scenario instead requires the appropriate SAML versus OIDC integration for SaaS capability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate delegated user consent versus admin consent. The scenario instead requires the appropriate SAML versus OIDC integration for SaaS capability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is correct configuration of app visibility without confusing authorization. The scenario instead requires the appropriate SAML versus OIDC integration for SaaS capability, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of SSO failure from assertion or token evidence. The scenario instead requires the appropriate SAML versus OIDC integration for SaaS capability, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 16

A staged rollout of an enterprise-application integration cannot proceed until the team can demonstrate: correct configuration of identifier and reply URL against vendor metadata. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Check the enterprise application’s enabled-for-users-to-sign-in state separately from user/group assignment.
  2. Assign app access through supported group membership at the narrowest required scope in enterprise application and Application Proxy.
  3. Limit user consent to verified low-risk permissions to the scope required by the scenario in enterprise application and Application Proxy.
  4. Configure identifier and reply url against vendor metadata in enterprise application and Application Proxy and verify the effective result.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose missing app from user collection view.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides correct configuration of identifier and reply URL against vendor metadata. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of disabled application sign-in versus user assignment. The scenario instead requires correct configuration of identifier and reply URL against vendor metadata, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is assignment of app access through supported group membership. The scenario instead requires correct configuration of identifier and reply URL against vendor metadata, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is limitation of user consent to verified low-risk permissions. The scenario instead requires correct configuration of identifier and reply URL against vendor metadata, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of missing app from user collection view. The scenario instead requires correct configuration of identifier and reply URL against vendor metadata, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 17

The team compares supported controls for an enterprise-application integration. The deciding condition is: mapping of claims to SaaS account matching requirement. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?

  1. Process admin-consent request with least privilege through the supported enterprise application and Application Proxy workflow.
  2. Assign the least-privilege application-administration role that supports the required operation.
  3. Map users or groups to correct application role to the exact identity or application attribute required by the target.
  4. Reorganize collections while preserving app assignments without changing the underlying application assignments.
  5. Map only the claims the SaaS application requires and verify they match the vendor’s account-matching rules.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides mapping of claims to SaaS account matching requirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is processing of admin-consent request with least privilege. The scenario instead requires mapping of claims to SaaS account matching requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate Application Administrator for required app operation. The scenario instead requires mapping of claims to SaaS account matching requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is mapping of users or groups to correct application role. The scenario instead requires mapping of claims to SaaS account matching requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is reorganize collections while preserving app assignments. The scenario instead requires mapping of claims to SaaS account matching requirement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 18

The identity architect is reviewing an enterprise-application integration. The required outcome is: a controlled plan for signing-certificate rollover with vendor coordination. The administrator must verify the effective result from Microsoft Entra evidence. Choose TWO actions that together implement and verify the requirement.

  1. Coordinate the enterprise-app signing certificate rollover with the SaaS provider before the old certificate expires.
  2. Revoke grant after changed business requirement through enterprise application and Application Proxy and verify whether any separate application session remains.
  3. Enable user assignment required on the enterprise application and assign only the authorized users/groups.
  4. Assign the least-privilege application-administration role that supports the required operation.
  5. Validate the enterprise application assignment/SSO result with a pilot user and inspect the application sign-in evidence.
  6. Classify application for access-management reporting requirement using the supported enterprise application and Application Proxy metadata and reporting fields.

Correct Answers: A, E

 

Correct Answers

Answer A is correct because This action directly provides a controlled plan for signing-certificate rollover with vendor coordination at the correct Microsoft Entra control boundary.

Answer E is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is revocation of grant after changed business requirement. It does not implement or verify a controlled plan for signing-certificate rollover with vendor coordination in this scenario.

Answer C is incorrect because This action is appropriate when the requirement is the required setting for user assignment requirement for restricted application. It does not implement or verify a controlled plan for signing-certificate rollover with vendor coordination in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate Cloud Application Administrator with App Proxy constraint. It does not implement or verify a controlled plan for signing-certificate rollover with vendor coordination in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is classify application for access-management reporting requirement. It does not implement or verify a controlled plan for signing-certificate rollover with vendor coordination in this scenario.

 

Question 19

The change owner has limited the remediation for a SaaS application with automated account provisioning to this outcome: a clear distinction between provisioning and federation sign-in. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Configure automated provisioning separately from federation/SSO because account lifecycle and authentication are distinct.
  2. Delegate application ownership for single-app administration through the narrowest supported enterprise application and Application Proxy role or ownership scope.
  3. Create collection for business-function application discovery in enterprise application and Application Proxy with the required scope and ownership.
  4. Apply the tenant user-consent policy that permits only the intended low-risk delegated permissions or requires admin approval.
  5. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose assignment present but app authorization missing.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides a clear distinction between provisioning and federation sign-in. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is delegate application ownership for single-app administration. The scenario instead requires a clear distinction between provisioning and federation sign-in, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is creation of collection for business-function application discovery. The scenario instead requires a clear distinction between provisioning and federation sign-in, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is resolution of tenant user-consent default versus application need. The scenario instead requires a clear distinction between provisioning and federation sign-in, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of assignment present but app authorization missing. The scenario instead requires a clear distinction between provisioning and federation sign-in, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 20

A change request for an enterprise-application integration will be accepted only when the following is true: diagnosis of SSO failure from assertion or token evidence. The current population and assignment scope must be preserved. Which action best satisfies the requirement?

  1. Assign collection audience without granting underlying app access at the narrowest required scope in enterprise application and Application Proxy.
  2. Use the admin-consent workflow for permissions that users are not allowed to consent to themselves.
  3. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to distinguish application management from high-privilege consent authority.
  4. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose sso failure from assertion or token evidence.
  5. Configure application visibility separately from authorization; hiding an app does not grant or revoke access.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides diagnosis of SSO failure from assertion or token evidence. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is assignment of collection audience without granting underlying app access. The scenario instead requires diagnosis of SSO failure from assertion or token evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate delegated user consent versus admin consent. The scenario instead requires diagnosis of SSO failure from assertion or token evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between application management and high-privilege consent authority. The scenario instead requires diagnosis of SSO failure from assertion or token evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is correct configuration of app visibility without confusing authorization. The scenario instead requires diagnosis of SSO failure from assertion or token evidence, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 21

The implementation of an enterprise-application integration is complete except for this requirement: assignment of app access through supported group membership. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose missing app from user collection view.
  2. Use Microsoft Entra Application Proxy with correctly placed connectors and the required preauthentication/SSO settings for the on-premises web app.
  3. Assign app access through supported group membership at the narrowest required scope in enterprise application and Application Proxy.
  4. Check the enterprise application’s enabled-for-users-to-sign-in state separately from user/group assignment.
  5. Limit user consent to verified low-risk permissions to the scope required by the scenario in enterprise application and Application Proxy.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides assignment of app access through supported group membership. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of missing app from user collection view. The scenario instead requires assignment of app access through supported group membership, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate Application Proxy for on-premises web publishing. The scenario instead requires assignment of app access through supported group membership, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is diagnosis of disabled application sign-in versus user assignment. The scenario instead requires assignment of app access through supported group membership, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is limitation of user consent to verified low-risk permissions. The scenario instead requires assignment of app access through supported group membership, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 22

The support team has ruled out unrelated causes in an enterprise-application integration. The remaining issue is: mapping of users or groups to correct application role. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Deploy connector with internal resource reachability with the enterprise application and Application Proxy topology required for reachability and availability.
  2. Reorganize collections while preserving app assignments without changing the underlying application assignments.
  3. Assign the least-privilege application-administration role that supports the required operation.
  4. Map users or groups to correct application role to the exact identity or application attribute required by the target.
  5. Process admin-consent request with least privilege through the supported enterprise application and Application Proxy workflow.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides mapping of users or groups to correct application role. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is deployment of connector with internal resource reachability. The scenario instead requires mapping of users or groups to correct application role, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is reorganize collections while preserving app assignments. The scenario instead requires mapping of users or groups to correct application role, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate Application Administrator for required app operation. The scenario instead requires mapping of users or groups to correct application role, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is processing of admin-consent request with least privilege. The scenario instead requires mapping of users or groups to correct application role, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 23

A readiness check of an enterprise-application integration leaves one unresolved condition: classify application for access-management reporting requirement. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Revoke grant after changed business requirement through enterprise application and Application Proxy and verify whether any separate application session remains.
  2. Classify application for access-management reporting requirement using the supported enterprise application and Application Proxy metadata and reporting fields.
  3. Enable user assignment required on the enterprise application and assign only the authorized users/groups.
  4. Choose Microsoft Entra preauthentication when Entra controls must apply before access, or passthrough only when the stated requirement explicitly needs backend authentication without Entra preauthentication.
  5. Assign the least-privilege application-administration role that supports the required operation.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides classify application for access-management reporting requirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is revocation of grant after changed business requirement. The scenario instead requires classify application for access-management reporting requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the required setting for user assignment requirement for restricted application. The scenario instead requires classify application for access-management reporting requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate preauthentication versus passthrough for requirement. The scenario instead requires classify application for access-management reporting requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate Cloud Application Administrator with App Proxy constraint. The scenario instead requires classify application for access-management reporting requirement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 24

Testing of an enterprise-application integration is successful except for this condition: diagnosis of assignment present but app authorization missing. The correction must address the named control boundary rather than reset unrelated tenant settings. Choose TWO actions that together implement and verify the requirement.

  1. Create collection for business-function application discovery in enterprise application and Application Proxy with the required scope and ownership.
  2. Apply the tenant user-consent policy that permits only the intended low-risk delegated permissions or requires admin approval.
  3. Configure the Application Proxy SSO method that matches the backend protocol and identity requirements.
  4. Validate the enterprise application assignment/SSO result with a pilot user and inspect the application sign-in evidence.
  5. Delegate application ownership for single-app administration through the narrowest supported enterprise application and Application Proxy role or ownership scope.
  6. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose assignment present but app authorization missing.

Correct Answers: D, F

 

Correct Answers

Answer D is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Answer F is correct because This action directly provides diagnosis of assignment present but app authorization missing at the correct Microsoft Entra control boundary.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is creation of collection for business-function application discovery. It does not implement or verify diagnosis of assignment present but app authorization missing in this scenario.

Answer B is incorrect because This action is appropriate when the requirement is resolution of tenant user-consent default versus application need. It does not implement or verify diagnosis of assignment present but app authorization missing in this scenario.

Answer C is incorrect because This action is appropriate when the requirement is correct configuration of single sign-on for supported backend protocol. It does not implement or verify diagnosis of assignment present but app authorization missing in this scenario.

Answer E is incorrect because This action is appropriate when the requirement is delegate application ownership for single-app administration. It does not implement or verify diagnosis of assignment present but app authorization missing in this scenario.

 

Question 25

The organization wants the least-disruptive correction to an enterprise application requesting delegated API permissions. It must provide: the appropriate delegated user consent versus admin consent. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to distinguish application management from high-privilege consent authority.
  2. Assign collection audience without granting underlying app access at the narrowest required scope in enterprise application and Application Proxy.
  3. Use the admin-consent workflow for permissions that users are not allowed to consent to themselves.
  4. Correct the Application Proxy internal/external URL configuration so the connector can reach the backend and users address the published endpoint.
  5. Configure application visibility separately from authorization; hiding an app does not grant or revoke access.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides the appropriate delegated user consent versus admin consent. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between application management and high-privilege consent authority. The scenario instead requires the appropriate delegated user consent versus admin consent, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is assignment of collection audience without granting underlying app access. The scenario instead requires the appropriate delegated user consent versus admin consent, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is diagnosis of internal URL versus external URL mismatch. The scenario instead requires the appropriate delegated user consent versus admin consent, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is correct configuration of app visibility without confusing authorization. The scenario instead requires the appropriate delegated user consent versus admin consent, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 26

A design review of an enterprise application requesting delegated API permissions identifies one remaining requirement: limitation of user consent to verified low-risk permissions. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Place Application Proxy connectors in a connector group that can reach the application and provide the required availability.
  2. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose missing app from user collection view.
  3. Limit user consent to verified low-risk permissions to the scope required by the scenario in enterprise application and Application Proxy.
  4. Use Microsoft Entra Application Proxy with correctly placed connectors and the required preauthentication/SSO settings for the on-premises web app.
  5. Check the enterprise application’s enabled-for-users-to-sign-in state separately from user/group assignment.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides limitation of user consent to verified low-risk permissions. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is resolution of connector-group placement and availability issue. The scenario instead requires limitation of user consent to verified low-risk permissions, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of missing app from user collection view. The scenario instead requires limitation of user consent to verified low-risk permissions, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate Application Proxy for on-premises web publishing. The scenario instead requires limitation of user consent to verified low-risk permissions, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of disabled application sign-in versus user assignment. The scenario instead requires limitation of user consent to verified low-risk permissions, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 27

Current evidence from an enterprise application requesting delegated API permissions shows that this requirement is not yet met: processing of admin-consent request with least privilege. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?

  1. Deploy connector with internal resource reachability with the enterprise application and Application Proxy topology required for reachability and availability.
  2. Assign the least-privilege application-administration role that supports the required operation.
  3. Process admin-consent request with least privilege through the supported enterprise application and Application Proxy workflow.
  4. Reorganize collections while preserving app assignments without changing the underlying application assignments.
  5. Configure the SaaS federation using the protocol and metadata the application supports, such as SAML when the vendor requires SAML.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides processing of admin-consent request with least privilege. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is deployment of connector with internal resource reachability. The scenario instead requires processing of admin-consent request with least privilege, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate Application Administrator for required app operation. The scenario instead requires processing of admin-consent request with least privilege, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is reorganize collections while preserving app assignments. The scenario instead requires processing of admin-consent request with least privilege, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate SAML versus OIDC integration for SaaS capability. The scenario instead requires processing of admin-consent request with least privilege, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 28

Before expanding an enterprise-application integration, the administrator must satisfy this condition: revocation of grant after changed business requirement. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Assign the least-privilege application-administration role that supports the required operation.
  2. Configure identifier and reply url against vendor metadata in enterprise application and Application Proxy and verify the effective result.
  3. Enable user assignment required on the enterprise application and assign only the authorized users/groups.
  4. Choose Microsoft Entra preauthentication when Entra controls must apply before access, or passthrough only when the stated requirement explicitly needs backend authentication without Entra preauthentication.
  5. Revoke grant after changed business requirement through enterprise application and Application Proxy and verify whether any separate application session remains.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides revocation of grant after changed business requirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate Cloud Application Administrator with App Proxy constraint. The scenario instead requires revocation of grant after changed business requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is correct configuration of identifier and reply URL against vendor metadata. The scenario instead requires revocation of grant after changed business requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the required setting for user assignment requirement for restricted application. The scenario instead requires revocation of grant after changed business requirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate preauthentication versus passthrough for requirement. The scenario instead requires revocation of grant after changed business requirement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 29

The administrator is preparing a My Apps application collection for one business function for production. The required condition is: creation of collection for business-function application discovery. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Create collection for business-function application discovery in enterprise application and Application Proxy with the required scope and ownership.
  2. Apply the tenant user-consent policy that permits only the intended low-risk delegated permissions or requires admin approval.
  3. Map only the claims the SaaS application requires and verify they match the vendor’s account-matching rules.
  4. Delegate application ownership for single-app administration through the narrowest supported enterprise application and Application Proxy role or ownership scope.
  5. Configure the Application Proxy SSO method that matches the backend protocol and identity requirements.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides creation of collection for business-function application discovery. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is resolution of tenant user-consent default versus application need. The scenario instead requires creation of collection for business-function application discovery, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is mapping of claims to SaaS account matching requirement. The scenario instead requires creation of collection for business-function application discovery, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is delegate application ownership for single-app administration. The scenario instead requires creation of collection for business-function application discovery, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is correct configuration of single sign-on for supported backend protocol. The scenario instead requires creation of collection for business-function application discovery, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 30

A production issue involving a My Apps application collection for one business function has been narrowed to this requirement: assignment of collection audience without granting underlying app access. The current population and assignment scope must be preserved. Choose TWO actions that together implement and verify the requirement.

  1. Configure application visibility separately from authorization; hiding an app does not grant or revoke access.
  2. Correct the Application Proxy internal/external URL configuration so the connector can reach the backend and users address the published endpoint.
  3. Validate the enterprise application assignment/SSO result with a pilot user and inspect the application sign-in evidence.
  4. Coordinate the enterprise-app signing certificate rollover with the SaaS provider before the old certificate expires.
  5. Assign collection audience without granting underlying app access at the narrowest required scope in enterprise application and Application Proxy.
  6. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to distinguish application management from high-privilege consent authority.

Correct Answers: C, E

 

Correct Answers

Answer C is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Answer E is correct because This action directly provides assignment of collection audience without granting underlying app access at the correct Microsoft Entra control boundary.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is correct configuration of app visibility without confusing authorization. It does not implement or verify assignment of collection audience without granting underlying app access in this scenario.

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of internal URL versus external URL mismatch. It does not implement or verify assignment of collection audience without granting underlying app access in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is a controlled plan for signing-certificate rollover with vendor coordination. It does not implement or verify assignment of collection audience without granting underlying app access in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is a clear distinction between application management and high-privilege consent authority. It does not implement or verify assignment of collection audience without granting underlying app access in this scenario.

 

Question 31

The security review of a My Apps application collection for one business function focuses on one acceptance criterion: diagnosis of missing app from user collection view. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Check the enterprise application’s enabled-for-users-to-sign-in state separately from user/group assignment.
  2. Use Microsoft Entra Application Proxy with correctly placed connectors and the required preauthentication/SSO settings for the on-premises web app.
  3. Place Application Proxy connectors in a connector group that can reach the application and provide the required availability.
  4. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose missing app from user collection view.
  5. Configure automated provisioning separately from federation/SSO because account lifecycle and authentication are distinct.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides diagnosis of missing app from user collection view. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of disabled application sign-in versus user assignment. The scenario instead requires diagnosis of missing app from user collection view, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate Application Proxy for on-premises web publishing. The scenario instead requires diagnosis of missing app from user collection view, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is resolution of connector-group placement and availability issue. The scenario instead requires diagnosis of missing app from user collection view, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between provisioning and federation sign-in. The scenario instead requires diagnosis of missing app from user collection view, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 32

The team is validating a My Apps application collection for one business function. The decisive requirement is: reorganize collections while preserving app assignments. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Assign the least-privilege application-administration role that supports the required operation.
  2. Configure the SaaS federation using the protocol and metadata the application supports, such as SAML when the vendor requires SAML.
  3. Deploy connector with internal resource reachability with the enterprise application and Application Proxy topology required for reachability and availability.
  4. Use enterprise-application settings, connector health, provisioning status, and sign-in logs to diagnose sso failure from assertion or token evidence.
  5. Reorganize collections while preserving app assignments without changing the underlying application assignments.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides reorganize collections while preserving app assignments. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate Application Administrator for required app operation. The scenario instead requires reorganize collections while preserving app assignments, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate SAML versus OIDC integration for SaaS capability. The scenario instead requires reorganize collections while preserving app assignments, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is deployment of connector with internal resource reachability. The scenario instead requires reorganize collections while preserving app assignments, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is diagnosis of SSO failure from assertion or token evidence. The scenario instead requires reorganize collections while preserving app assignments, so this option would solve an adjacent identity problem rather than the documented gap.

img