Microsoft SC-300 Tenant Configuration Roles and Delegated Administration Practice Test
Topic 01 covers tenant configuration, roles, and delegated administration for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
A subscription operations team must assign and remove Microsoft 365 licenses for existing Entra users. Its members must not receive general user creation, password-reset, or application-management authority. Which built-in role best matches this standing directory assignment?
Correct Answer: A
Correct Answer
Answer A is correct because this role manages product license assignments without giving the broader user and application administration capabilities that the team does not require.
Incorrect Answers
Answer B is incorrect because this role manages applications and related configuration. Application administration does not provide the narrowly scoped licensing function requested for this team.
Answer C is incorrect because billing administration addresses purchases and subscription billing. It is not the directory role specifically intended for assigning licenses to existing users under this requirement.
Answer D is incorrect because this role can manage licensing, but also grants broader user administration. Meeting the licensing requirement does not justify those additional standing permissions.
Answer E is incorrect because group administration would allow changes to group objects and memberships. The requested direct licensing work does not require that broader group-management responsibility.
Question 2
An engineer must update the basic properties and credentials of one app registration, without administering other registrations. Licensing and role-assignment authority are already in place. Which TWO configuration steps implement this delegation? Choose TWO.
Correct Answers: C, E
Correct Answers
Answer C is correct because the role definition expresses the two permitted operations. Both permissions are supported for custom app-registration roles, so broader application administration is unnecessary.
Answer E is correct because the assignment binds the defined operations to this engineer and this registration. A role definition alone gives no principal access.
Incorrect Answers
Answer A is incorrect because Azure subscription ownership governs Azure resource management. It does not establish the requested app-registration permission scope in Microsoft Entra.
Answer B is incorrect because a department attribute does not narrow a directory-scoped role assignment. The engineer would receive the role’s operations across its applicable tenant resources.
Answer D is incorrect because this grants administration across applications and exceeds the one-registration boundary, even though it would enable the requested updates.
Answer F is incorrect because a definition describes permissions but does not attach them to the engineer. The missing assignment would leave the requested access ungranted.
Question 3
One custom Entra role allows basic-property and credential updates. Priya holds it at registration A, and Lee holds the same definition at registration B. A new policy requires Priya to retain basic-property updates but lose credential updates; Lee must retain both. Neither user has another applicable grant or ownership. Which change meets both requirements?
Correct Answer: B
Correct Answer
Answer B is correct because a separate narrower definition changes Priya’s allowed actions without changing Lee’s shared definition. Replacing, rather than supplementing, Priya’s old assignment removes her credential-update grant.
Incorrect Answers
Answer A is incorrect because Priya’s assignment is already limited to A. Recreating that scope would not remove one of the definition’s allowed actions.
Answer C is incorrect because both assignments refer to that definition. Removing its credential action would also remove Lee’s required capability on B.
Answer D is incorrect because the added role does not subtract actions from the existing grant. Priya would still have credential-update authority through the original assignment.
Answer E is incorrect because this removes credential updates but also removes the required basic-property updates. The replacement must retain the permitted operation.
Question 4
A role designer selects an action listed in a built-in Entra role but cannot add it to a custom role. The action is not in Microsoft’s supported custom-role permission set. The tenant has the required licenses. Which response addresses the limitation?
Correct Answer: D
Correct Answer
Answer D is correct because custom roles accept only actions enabled for custom use. A built-in role’s possession of an action does not make that action available in custom definitions.
Incorrect Answers
Answer A is incorrect because the documented creation process can clone custom-role baselines, not built-in roles. Cloning would not bypass the supported-action limitation.
Answer B is incorrect because Azure resource ownership does not expand the Microsoft Entra custom permission catalog. The failure concerns a directory role definition.
Answer C is incorrect because scope determines where valid permissions apply. It does not change which actions Microsoft allows in a custom role definition.
Answer E is incorrect because using an API does not expand the supported custom-role permission catalog. The definition must still contain actions enabled for custom use.
Question 5
New regional support staff need password-reset authority for designated cloud-only, nonprivileged users in one tenant. They have ordinary member access and no administrative assignments. Central administrators must retain their existing tenant-wide authority over these users. Which configuration provides the regional delegation?
Correct Answer: B
Correct Answer
Answer B is correct because the supported users define the management scope and the staff receive the role at that scope. A regular AU preserves the existing tenant-wide administrators’ authority.
Incorrect Answers
Answer A is incorrect because membership selects managed objects; it does not grant the staff password-reset authority. An applicable role assignment is still required.
Answer C is incorrect because a filtered list does not constrain the role’s authorization scope. The staff would receive support authority beyond the designated region.
Answer D is incorrect because restricted management would prevent those tenant-wide grants from authorizing protected operations without additional scoped assignments. That conflicts with preserving central administration as configured.
Answer E is incorrect because the AU must contain the users whose passwords they manage. Placing only the administrators in it selects the wrong target objects.
Question 6
A helpdesk administrator has only an AU-scoped User Administrator assignment for the Sales unit. In a directory client, the administrator can still read basic information about a user outside Sales but cannot edit that user. No broader administrator role is assigned. What best explains these results?
Correct Answer: E
Correct Answer
Answer E is correct because administrative units scope management operations; they do not establish a directory visibility boundary. Reading an outside object therefore does not prove the AU-scoped role is ineffective.
Incorrect Answers
Answer A is incorrect because membership in a separate security group does not automatically place the user in the AU or extend the administrator’s assignment. Read visibility alone does not establish management authority.
Answer B is incorrect because read and write authority can have different sources. The failed outside-unit update is consistent with management scope remaining limited.
Answer C is incorrect because AU-scoped roles affect management authorization, including supported APIs. The inability to update the outside user is an authorization boundary, not merely a view filter.
Answer D is incorrect because the administrator’s object membership is not a tenant-wide grant. Default member reads can coexist with limited AU-scoped management.
Question 7
A regular administrative unit uses assigned membership and contains FieldSupport, an ordinary, non-role-assignable security group with assigned membership. None of the group’s users are direct AU members. An administrator has a supported User Administrator assignment scoped only to that AU. Which TWO statements correctly guide delegation? Choose TWO.
Correct Answers: D, F
Correct Answers
Answer D is correct because adding the group places that object within scope. Supported group-management operations can therefore be authorized by the AU-scoped assignment.
Answer F is correct because group membership does not transitively make each user an AU member. The user objects require their own AU inclusion for user-property administration.
Incorrect Answers
Answer A is incorrect because the supported scope includes the group object’s properties as well as membership. The distinction is between the group and its member users, not between these two group operations.
Answer B is incorrect because ownership of the group is not an AU-scoped role assignment. Owners do not gain authority over the administrative unit merely through this membership.
Answer C is incorrect because the single-type restriction belongs to dynamic AUs. An assigned-membership AU can contain groups and directly included users.
Answer E is incorrect because Microsoft distinguishes management of a group from management of its member objects. The proposed inheritance would expand authority beyond actual AU membership.
Question 8
A university delegates user management for each school through regular administrative units. A school administrator asks to change the tenant’s primary domain only for that school by using the AU-scoped role. Which explanation should the identity team provide?
Correct Answer: A
Correct Answer
Answer A is correct because administrative units scope supported object management. They do not partition organization-level domain configuration into separate settings for each school.
Incorrect Answers
Answer B is incorrect because a group’s address does not define the tenant’s primary domain. Changing the group cannot establish an independent school-level domain setting.
Answer C is incorrect because the management interface does not change the property’s tenant-wide scope. An API call cannot create an AU-level primary domain.
Answer D is incorrect because AUs cannot be nested, and nesting would not create another tenant’s domain configuration even if it were available.
Answer E is incorrect because domain configuration is organization-wide; an AU assignment cannot create a school-specific version of that property. Supported delegated object management does not partition domain settings.
Question 9
A dynamic-user administrative unit includes users whose department is Finance. An administrator cannot manually add a new Finance contractor. The contractor’s department attribute is blank, and the unit’s processing state is On. The rule must remain the authoritative source of membership. What should the administrator do?
Correct Answer: C
Correct Answer
Answer C is correct because the dynamic rule determines membership, and the missing attribute explains exclusion. Correcting that input preserves the required rule-controlled membership model.
Incorrect Answers
Answer A is incorrect because the stated AU rule evaluates the user’s department. Membership in a separately named group does not satisfy that condition.
Answer B is incorrect because a role assignment grants management authority; it does not populate the missing department attribute or make this user satisfy the membership rule.
Answer D is incorrect because direct membership changes are disabled for dynamic AUs. Broader privileges do not replace the dynamic engine’s ownership of membership.
Answer E is incorrect because pausing evaluation does not turn dynamic membership into assigned membership. It would also stop the required ongoing rule processing.
Question 10
An administrator adds Morgan’s user object to the Research AU, which also contains the cloud-only, nonprivileged users Morgan will support. Morgan still cannot reset their passwords. Morgan has no assigned directory role. What additional configuration is required?
Correct Answer: A
Correct Answer
Answer A is correct because AU membership describes which objects can be managed; it is not an administrative grant. The role assignment supplies the missing management authority.
Incorrect Answers
Answer B is incorrect because a read role may expose directory information, but it does not grant the password-reset operation. The needed supported management role must be scoped appropriately.
Answer C is incorrect because device administration does not authorize user password resets. The scope is relevant, but the role’s operation set does not match the task.
Answer D is incorrect because group ownership can permit management of that group’s membership and properties, but not password resets for its member user objects.
Answer E is incorrect because the role would be scoped to the wrong target objects. Morgan needs an appropriate assignment over the Research users whose passwords require support.
Question 11
An identity team wants rule-driven delegation for both employees and their Windows devices. It proposes one dynamic AU whose rule combines user.department and device.deviceOSType. Which configuration meets the rule-driven requirement using supported AU membership models?
Correct Answer: D
Correct Answer
Answer D is correct because a dynamic AU supports one object type. Separate units preserve automatic membership while allowing supported rules for users and devices.
Incorrect Answers
Answer A is incorrect because dynamic group-object membership for AUs is unsupported, and group membership does not transitively place member objects into AU scope.
Answer B is incorrect because AUs cannot be nested. This design would not produce the requested combined rule-driven scope.
Answer C is incorrect because assigned AUs support mixed object types, but this option abandons the specified rule-driven maintenance requirement.
Answer E is incorrect because dynamic membership owns membership changes and does not support this mixed manual-device extension. The proposal would not satisfy both rule-driven populations.
Question 12
A tenant-scoped User Administrator can edit most users but receives a restricted-management error for an executive. The executive belongs to a restricted management AU. The administrator has no role scoped to that AU, and the task is to update the executive’s jobTitle property. What is the least disruptive correction?
Correct Answer: C
Correct Answer
Answer C is correct because restricted management requires an explicit assignment at that scope. The correction authorizes the supported update while retaining the executive’s protected placement.
Incorrect Answers
Answer A is incorrect because a regular AU assignment does not overcome restricted-management protection. The required explicit scope is the restricted AU.
Answer B is incorrect because that setting is fixed when the AU is created. The proposed toggle is unavailable and would also remove the intended protection rather than delegate safely.
Answer D is incorrect because a tenant-wide Global Administrator grant does not itself bypass restricted management. That role can arrange a scoped assignment, but the proposed direct retry still lacks one.
Answer E is incorrect because broad Graph permissions do not automatically bypass restricted AUs. Applications also need the appropriate Entra role assignment at restricted scope.
Question 13
Sam has tenant-scoped User Administrator and a Helpdesk Administrator assignment scoped to the West AU. The team expects the narrower assignment to prevent Sam from editing users in East, but East users remain editable. The users are not in restricted AUs. What should be changed?
Correct Answer: D
Correct Answer
Answer D is correct because the tenant-wide role continues to authorize its supported actions. Adding a narrower assignment does not act as a deny against a broader existing grant.
Incorrect Answers
Answer A is incorrect because where Sam’s own user object resides does not narrow the tenant-scoped permissions assigned to Sam.
Answer B is incorrect because changing how the AU population is maintained does not subtract the tenant-wide permissions already granted to Sam.
Answer C is incorrect because assignment creation order does not establish a restrictive precedence rule. Both applicable grants are evaluated.
Answer E is incorrect because another limited grant does not cancel a broader grant. The excess authority must be removed at its source.
Question 14
A support operator can reset authentication methods for ordinary users but cannot reset the methods of a Global Administrator. Neither target belongs to a restricted management AU. The operator has Authentication Administrator at tenant scope and no other role. Which standing role is designed for the required authentication-method administration of privileged users?
Correct Answer: B
Correct Answer
Answer B is correct because this role can manage authentication methods for administrative as well as nonadministrative users. The privileged target is the material difference from the operator’s current scope of authority.
Incorrect Answers
Answer A is incorrect because this role does not provide unrestricted authentication-method administration for Global Administrators. Changing to it would not meet the privileged-target requirement.
Answer C is incorrect because helpdesk password support has target-role restrictions. It does not supply the broad privileged-user authentication-method authority required here.
Answer D is incorrect because this role manages authentication policies and settings. It is not the replacement for administering an individual privileged user’s authentication methods.
Answer E is incorrect because application configuration authority does not grant privileged-user authentication-method reset capability. The failed operation concerns a user credential.
Question 15
A former Groups Administrator can still edit one non-role-assignable, assigned-membership security group after role removal has taken effect. The user is both a member and an owner of that group, has no other administrative grant, and uses a fresh session. The group is outside restricted AUs. The user must retain group membership but lose membership-management authority. What should an administrator remove?
Correct Answer: C
Correct Answer
Answer C is correct because ownership is the remaining management grant. Removing it while retaining ordinary membership meets both constraints.
Incorrect Answers
Answer A is incorrect because the fresh-session evidence rules out reliance on the removed role. Another session can still exercise the ownership grant.
Answer B is incorrect because ordinary membership is not the identified administrative grant. This would remove required access while preserving the ownership path.
Answer D is incorrect because the scenario establishes that role removal is effective and no other role applies. Repeating it does not remove object ownership.
Answer E is incorrect because a creation restriction does not remove ownership of an existing group. The current management path would remain.
Question 16
A signed-in operator has sufficient directory authority to read the intended tenant settings. A custom client receives an authorization failure because its delegated token lacks the Microsoft Graph permission required for that endpoint. The token’s audience and sign-in are correct. What should be corrected?
Correct Answer: C
Correct Answer
Answer C is correct because delegated calls must be permitted by both the user’s authority and the client’s granted delegated permission. The missing client permission is the identified gap.
Incorrect Answers
Answer A is incorrect because consent grants belong to the client making the request. Authorizing another client does not change the token issued to this custom application.
Answer B is incorrect because the user’s authority is already sufficient. A stronger directory role does not add an absent delegated permission to this client’s token.
Answer D is incorrect because object membership does not repair a missing delegated scope. The diagnosed failure lies in the client token’s permission grant.
Answer E is incorrect because the role is already effective and the token explicitly lacks the permission. Reusing that token cannot supply a missing delegated scope.
Question 17
A new custom domain must be verified in Entra before any mail-flow changes are approved. The administrator has the verification TXT value supplied by Entra and access to the domain’s authoritative DNS. Which action proves ownership while preserving current mail routing?
Correct Answer: B
Correct Answer
Answer B is correct because Entra can verify ownership using the supplied TXT record. This avoids changing the MX records that direct production email.
Incorrect Answers
Answer A is incorrect because a custom domain must be verified before it can be selected as a primary domain. This would not establish DNS ownership.
Answer C is incorrect because the ownership record must match the value issued for this domain. A value from another domain does not supply the requested proof.
Answer D is incorrect because an SPF record describes permitted mail senders. It is not the supplied Entra ownership-verification TXT value and does not satisfy this verification step.
Answer E is incorrect because an MX change affects production mail routing, which is not authorized. The supplied verification TXT can establish ownership without replacing that route.
Question 18
A verified, managed custom domain is made the tenant’s primary domain. New user creation offers that domain by default, but existing users retain their previous UPNs. The migration plan requires existing UPNs to remain unchanged until a later window. What should the administrator conclude?
Correct Answer: C
Correct Answer
Answer C is correct because the primary domain supplies the default for new users. Changing it does not automatically rename existing users, so the later UPN migration remains a separate action.
Incorrect Answers
Answer A is incorrect because automatic renaming is not part of this setting’s behavior. The default shown for new users supports that the change succeeded.
Answer B is incorrect because the scenario’s verified managed domain is suitable. Federation is not required to make it primary and is not a remedy for unchanged UPNs.
Answer D is incorrect because sign-in does not perform a UPN migration. Existing identifiers remain until they are explicitly changed.
Answer E is incorrect because primary selection changes the default for new user creation. It does not schedule an existing-user rename, so a separate migration remains necessary.
Question 19
An unused custom domain cannot be deleted. The signed-in domain administrator uses the initial onmicrosoft.com domain, and the domain being removed is not primary. The remaining references are a user’s proxy address and an application’s app ID URI. Which TWO changes directly remove these documented dependency types? Choose TWO.
Correct Answers: C, D
Correct Answers
Answer C is correct because an app ID URI containing the custom domain is another documented dependency. The application must be adjusted through a controlled change before deletion.
Answer D is correct because a user proxy address containing the domain is a deletion dependency. Removing or updating that reference addresses one identified blocker.
Incorrect Answers
Answer A is incorrect because permission grants and the app ID URI are separate properties. Removing grants would affect authorization but leave the domain dependency.
Answer B is incorrect because the administrator already has domain-management authority and uses a retained sign-in domain. More privilege does not remove object dependencies.
Answer E is incorrect because each relevant user address is a separate dependency. Changing only the UPN would leave the explicitly identified proxy-address reference.
Answer F is incorrect because removing DNS evidence does not remove references stored in directory objects. It can complicate domain administration without fixing these dependencies.
Question 20
A company verifies a custom domain in its Microsoft 365 production tenant. A separate Entra test tenant then rejects verification of the same domain. The correct TXT record is publicly resolvable, and production must keep using the domain. What is the appropriate configuration decision?
Correct Answer: E
Correct Answer
Answer E is correct because the same domain cannot be verified in both tenants concurrently. A separate domain meets the current test requirement without disrupting production.
Incorrect Answers
Answer A is incorrect because provisioning users between tenants does not merge verified-domain ownership. The domain still cannot be simultaneously verified in both tenants.
Answer B is incorrect because primary-domain selection does not override another tenant’s verified-domain association. The contested custom domain is still unavailable for concurrent verification.
Answer C is incorrect because B2B access does not merge tenant domain registrations. Collaboration and verified-domain ownership are different configuration boundaries.
Answer D is incorrect because an additional TXT record cannot remove the one-tenant verification constraint. Production’s existing association remains.
Question 21
A tenant has default company branding with an English helpdesk message and logo. French-browser users need a French helpdesk message; other browser languages must keep English. French pages must also inherit future changes to the default logo without separate uploads. Which configuration meets these requirements?
Correct Answer: E
Correct Answer
Answer E is correct because language-specific branding overrides the elements that are customized. Elements left unchanged use the defaults, so the existing logo can remain shared.
Incorrect Answers
Answer A is incorrect because the username hint is a different field. This would leave the helpdesk message in English rather than localizing the requested element.
Answer B is incorrect because this changes the default experience for other users as well. It does not target the requested browser-language population.
Answer C is incorrect because language selection chooses configured branding; it does not supply a translated custom message. A French configuration containing that text is needed.
Answer D is incorrect because a separate logo override can match today but does not preserve inheritance when the default logo changes. Leave the logo element unmodified for fallback.
Question 22
On September 17, 2026, a branding administrator plans a first custom CSS deployment. The tenant was created in December 2025 and has never used custom CSS. Licensing and the Organizational Branding Administrator assignment are in place. Under Microsoft’s current availability rules, which deployment plan is supported?
Correct Answer: E
Correct Answer
Answer E is correct because the tenant predates January 6, 2026 but had no existing CSS use. After July 21, 2026 it cannot start using custom CSS; supported branding controls remain the applicable approach.
Incorrect Answers
Answer A is incorrect because the pre-January creation date alone is insufficient. After July 21, 2026, an older tenant without existing CSS use cannot begin using it.
Answer B is incorrect because newer tenants are also subject to the documented restriction. Creating another tenant would not provide the proposed CSS capability.
Answer C is incorrect because switching management interfaces does not make an ineligible tenant eligible. The documented restriction concerns tenant availability.
Answer D is incorrect because a language-specific entry is still company branding in the same tenant. It does not bypass the restriction on beginning CSS use.
Question 23
Company branding appears when employees authenticate with work accounts. A B2B guest instead authenticates with a personal Microsoft account and sees the personal-account sign-in experience. The guest has entered the personal account identifier and reached its credential page. The tenant’s default logo works in the same browser for work accounts. What is the most appropriate diagnosis?
Correct Answer: D
Correct Answer
Answer D is correct because Microsoft documents this account-type boundary. The guest’s personal-account authentication does not by itself indicate a failed tenant branding deployment.
Incorrect Answers
Answer A is incorrect because the same logo already appears for work accounts. Reuploading it does not change the personal-account authentication surface.
Answer B is incorrect because branding behavior is not a reliable invitation-redemption test. The stated personal account type already explains the different authentication experience.
Answer C is incorrect because work accounts display the default logo in the same browser. Missing localized branding does not explain the stated account-type difference.
Answer E is incorrect because the scenario places the user on the personal account’s credential page after entering the identifier. The observation is explained by the account-type boundary.
Question 24
A branding administrator replaces the footer’s default Terms of Use text with the organization’s legal notice. A project manager claims that every subsequent sign-in now proves the user accepted the notice. No Conditional Access terms-of-use configuration was deployed. Which TWO conclusions are justified? Choose TWO.
Correct Answers: B, F
Correct Answers
Answer B is correct because that feature presents the terms as an access requirement and maintains acceptance records. Editing branding alone does not configure it.
Answer F is correct because presentation of the notice supplies no acceptance event. Successful authentication after that change does not establish that the user accepted it.
Incorrect Answers
Answer A is incorrect because the described branding change does not create acceptance tracking. Successful authentication cannot be treated as that evidence.
Answer C is incorrect because the administrator’s configuration event concerns publication of the notice. It is not an individual user’s acceptance event.
Answer D is incorrect because moving the notice between branding fields changes its location, not its authorization semantics. An acceptance policy still needs separate configuration.
Answer E is incorrect because viewing a URL does not exercise the terms-of-use acceptance workflow. A branding notice alone cannot provide the required per-user acceptance evidence.
Question 25
An administrator sets Users can register applications to No. An ordinary member can no longer register an app, but a developer with Application Developer still can. The setting has taken effect and both users have new sessions. The developer has no broader directory role. What explains the difference?
Correct Answer: A
Correct Answer
Answer A is correct because the setting restricts ordinary member defaults. The developer’s explicit role provides the capability, so the two outcomes are consistent.
Incorrect Answers
Answer B is incorrect because both sessions are new and the setting is effective. The persistent difference follows the explicit role grant rather than an old session.
Answer C is incorrect because the decisive evidence is the Application Developer role, which expressly permits registration. Ownership of another app is not the stated basis for unrestricted creation.
Answer D is incorrect because admin consent authorizes application permissions; it is not a general exemption from member defaults. The explicit Application Developer role explains registration here.
Answer E is incorrect because the ordinary member’s failed registration is consistent with the intended member-default restriction. Treating it as a guest-only setting would misdiagnose the behavior.
Question 26
A security administrator enables Restrict access to Microsoft Entra administration portal for nonadministrators. A member user can still retrieve directory information through a permitted Microsoft Graph client using a fresh delegated token. The administrator expected the switch to remove directory-read permissions. Which correction should be made to that assessment?
Correct Answer: D
Correct Answer
Answer D is correct because Microsoft explicitly warns that this switch is not a security boundary. It does not replace controls governing the user’s and client’s directory access.
Incorrect Answers
Answer A is incorrect because the scenario explicitly identifies a delegated token. Permitted user-and-client authority can support a Graph read despite portal friction.
Answer B is incorrect because the switch is not an API read/write permission filter. It limits parts of the portal experience rather than defining Graph operation permissions.
Answer C is incorrect because preventing future consent is different from evaluating or revoking existing grants and user permissions. It does not make the portal switch a directory-read boundary.
Answer E is incorrect because the token is fresh, and the setting does not revoke underlying directory reads. Another sign-in would not make it an API authorization control.
Question 27
The device administrator limits Users may join devices to Microsoft Entra ID to a selected onboarding group. A user outside that group cannot perform an interactive Entra join on a Windows laptop. Existing domain-joined devices continue becoming hybrid joined through the organization’s configured process. Which TWO conclusions are correct? Choose TWO.
Correct Answers: B, C
Correct Answers
Answer B is correct because the caller is outside the permitted population for the relevant interactive join operation. This is the expected boundary of that setting.
Answer C is correct because the documented setting does not apply to Microsoft Entra hybrid joined devices. Their continued hybrid join does not demonstrate that the user-driven restriction failed.
Incorrect Answers
Answer A is incorrect because the setting controls eligibility for the specified join operation. It does not itself define who can subsequently sign in to every joined device.
Answer D is incorrect because hybrid join is not controlled by this user-driven join setting. Applying that expectation would conflate different device identity processes.
Answer E is incorrect because device registration has a separate tenant setting. Targeting user-driven Entra join does not automatically rewrite registration eligibility.
Answer F is incorrect because join eligibility is separate from local administrator configuration. This setting does not grant that tenant-wide device-administrator capability.
Question 28
A tenant’s Group.Unified settings have EnableGroupCreation=false and GroupCreationAllowedGroupId set to the Creators security group’s ID. Separately, defaultUserRolePermissions.allowedToCreateSecurityGroups=false. Alex is an ordinary member, a direct member of Creators, and has no administrative role. Required licensing is present and the settings are effective. Which TWO creation outcomes should the administrator expect? Choose TWO.
Correct Answers: C, E
Correct Answers
Answer C is correct because security-group creation is controlled separately. The Microsoft 365 creator exception does not override allowedToCreateSecurityGroups=false.
Answer E is correct because GroupCreationAllowedGroupId identifies the members allowed to create Microsoft 365 groups despite EnableGroupCreation=false. The scenario requires the narrower Microsoft Entra behavior described in the stem.
Incorrect Answers
Answer A is incorrect because the allowed-group setting exists to provide that exception when ordinary Microsoft 365 group creation is disabled.
Answer B is incorrect because this creator exception uses membership in the configured security group. It does not require that group to carry an Entra directory role.
Answer D is incorrect because the exception group’s type does not change which creation policy it belongs to. Its ID is configured in the Microsoft 365 group settings.
Answer F is incorrect because that change affects ordinary Microsoft 365 group creation. It does not change the separate security-group creation permission.
Popular posts
Recent Posts
