Microsoft Identity & Access Management Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Identity & Access Management flashcards as text
What does SSPR 'writeback' enable in a hybrid Azure AD environment?
Answer: Allowing password changes made in Azure AD to sync back to on-premises Active Directory
Password writeback ensures that when a user resets their password in Azure AD, the change is also applied to their on-premises AD account.
Which authentication method in Azure AD is considered the most phishing-resistant?
Answer: FIDO2 security keys
FIDO2 security keys use public-key cryptography bound to the specific site, making them immune to phishing attacks.
In Azure AD, what is a 'sign-in risk policy' within Identity Protection?
Answer: A Conditional Access policy that triggers additional verification when a sign-in is detected as risky
Sign-in risk policies evaluate the risk of each authentication attempt and can require MFA or block access based on the detected risk level.
What is 'Pass-through Authentication' (PTA) in Azure AD Connect, and how does it differ from PHS?
Answer: PTA validates passwords against on-premises AD in real time; PHS syncs password hashes to the cloud
PTA agents on-premises validate each user's password directly against on-premises AD at sign-in time, without storing any password data in Azure AD.
Which Azure AD feature allows an organization to define and enforce terms of use that users must accept before accessing resources?
Answer: Conditional Access โ Terms of Use
Conditional Access can include a Terms of Use policy that requires users to read and accept legal terms before gaining access.
What is the 'principle of least privilege' as it applies to Azure AD role assignments?
Answer: Giving users only the minimum permissions necessary to perform their job functions
Least privilege means users receive only the specific permissions they need, reducing the potential damage from compromised accounts.
Which capability does Azure AD Multi-Tenant Organization (MTO) provide?
Answer: Enabling seamless collaboration between multiple Azure AD tenants within the same organization
Multi-Tenant Organization allows companies with multiple Azure AD tenants (e.g., after mergers) to enable seamless cross-tenant access and collaboration.