Microsoft Identity & Access Management Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Identity & Access Management flashcards as text
Which Azure AD feature allows users to reset their own passwords without contacting IT support?
Answer: Self-Service Password Reset (SSPR)
SSPR lets users reset or unlock their passwords without IT helpdesk involvement, reducing support costs.
What is the primary purpose of Azure AD Privileged Identity Management (PIM)?
Answer: Provide just-in-time privileged access to reduce standing permissions
PIM provides just-in-time (JIT) privileged access so admin roles are only active when needed, reducing attack surface.
Which identity type in Azure AD represents an application that needs to authenticate to access Azure resources?
Answer: Service principal
A service principal is the identity representation of an application in Azure AD, used for app-to-resource authentication.
What does Azure AD External Identities B2C primarily enable?
Answer: Allowing customers to sign in to consumer-facing apps using social or local accounts
Azure AD B2C is a customer identity solution that lets end users authenticate with social providers or custom accounts.
Which Azure AD feature automatically detects and remediates risky sign-ins using machine learning?
Answer: Identity Protection
Azure AD Identity Protection uses ML to detect anomalous sign-ins and can automatically block or require MFA for risky logins.
What is the difference between authentication and authorization in identity management?
Answer: Authentication verifies who you are; authorization determines what you can access
Authentication (AuthN) confirms identity, while authorization (AuthZ) determines what resources that identity can access.
Which protocol does Azure AD use for modern token-based authorization between applications?
Answer: OAuth 2.0
OAuth 2.0 is the industry-standard authorization protocol used by Azure AD for delegating access between apps and APIs.