Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Microsoft SC-300 - Microsoft Identity and Access Administrator

Page: 3 / 5
Total 356 questions

You have a Microsoft 365 subscription.

You configure a Global Secure Access security profile named SecurityProfilel.

You need to create a Conditional Access policy named CAPolicyl that will use SecurityProfilel.

Which two settings should you configure to ensure that CAPolicyl uses SecurityProfilel? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft 365 subscription.

You need to ensure that users can grant enterprise applications access to their profile. The solution must ensure that the users can consent only to the User. Read and profile delegated permissions.

What should you configure first?

A.

Security defaults

B.

Admin consent settings

C.

Permission classifications

D.

Identity Protection settings

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.

You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.

You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.

Solution: You configure password writeback.

Does this meet the goal?

A.

Yes

B.

No

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You need to ensure that user authentication always occurs by validating passwords against the AD DS domain. What should you configure, and what should you use? To answer, select the appropriate options in the answer area. NOTE: Each coned selection is worth one point.

You have a Microsoft Entra tenant that contains the identities shown in the following table.

Group1 has the following configurations:

• Owners: User1, User4

• Members: User1, Managed2, Gioup2

You create an access review that has the following settings:

• Name: Review1

• Review scope: Select Teams + Groups

• Group: Group1

• Scope: All users

• Select reviewers: Group owner(s)

The Fallback reviewers: setting is NOT configured.

You have an Azure Active Directory (Azure AD) tenant that contains the following objects:

A device named Device1

Users named User1, User2, User3, User4, and User5

Groups named Group1, Group2, Group3, Group4, and Group5

The groups are configured as shown in the following table.

To which groups can you assign a Microsoft Office 365 Enterprise E5 license directly?

A.

Group1 and Group4 only

B.

Group1, Group2, Group3, Group4, and Group5

C.

Group1 and Group2 only

D.

Group1 only

E.

Group1, Group2, Group4, and Group5 only

You have an Azure Active Directory (Azure AD) tenant that has Security defaults disabled.

You are creating a conditional access policy as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE:Each correct selection is worth one point.

You have a Microsoft Entra ID P2 tenant named contoso.com that contains a registered app named App1. On January 1, App1 was deleted. You need to restore Appl.

What is the last day on which you can restore Appl1?

A.

January 14

B.

January 30

C.

March 30

D.

June 30

You have an Azure AD tenant that contains the users shown in The following table.

You enable self-service password reset (SSPR) for all the users and configure SSPR to require security questions as the only authentication method.

Which users must use security questions when resetting their password?

A.

User4 only

B.

User3and User4only

C.

User1 and User4only

D.

User1, User3, and User4 only

E.

User1, User2, User3. and User4

You need to meet the technical requirements for the probability that user identifies were compromised.

What should the users do first, and what should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.