← All AZ-305 Flashcard Decks

Azure Identity and Access Management Design Flashcards

6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Azure Identity and Access Management Design flashcards as text
  1. A company needs to allow users from a partner organization to access Azure resources without creating new accounts. Which Azure AD feature should you recommend?

    Answer: Azure AD B2B collaboration

    Azure AD B2B collaboration lets you invite external users from partner organizations to access your Azure resources using their existing identities.

  2. Your organization requires that administrative actions on Azure resources be performed only after a second approval is obtained. Which Azure feature fulfills this requirement?

    Answer: Privileged Identity Management (PIM) with approval workflows

    PIM approval workflows require a designated approver to authorize role activation before an admin can perform privileged actions.

  3. You need to enforce that all users signing in from outside the corporate network must use MFA. Which solution should you design?

    Answer: Conditional Access policies with location-based conditions

    Conditional Access policies can target named locations to require MFA only when users authenticate from outside trusted IP ranges.

  4. A solution requires managing access to hundreds of Azure resources for groups of users whose membership changes frequently. Which approach minimizes administrative overhead?

    Answer: Use Azure AD groups with RBAC role assignments

    Assigning RBAC roles to Azure AD groups means you only manage group membership rather than updating individual role assignments as users change.

  5. Your organization runs a legacy application that uses LDAP for authentication. You want to migrate it to Azure without rewriting the app. Which service should you use?

    Answer: Azure Active Directory Domain Services (Azure AD DS)

    Azure AD DS provides managed domain services including LDAP, Kerberos, and NTLM so legacy apps can authenticate without code changes.

  6. You need to design a solution where service-to-service authentication happens without storing credentials in code or configuration files. Which approach is recommended?

    Answer: Use Azure Managed Identities

    Managed Identities eliminate the need to manage credentials by providing Azure resources with an automatically managed identity in Azure AD.