Your company adds a custom domain name, contoso.com, in the Microsoft 365 admin center. What is the default DNS record type recommended by Microsoft to verify ownership with your domain registrar without impacting existing email routing?
- A TXT record containing the MS=ms verification code (Correct)
- An MX record pointing directly to mail.protection.outlook.com
- A CNAME record pointing autodiscover to outlook.office.com
- An SRV record for SIP federation
Explanation: Microsoft 365 verifies domain ownership primarily via a TXT record containing an MS=ms######## verification string. This record does not affect live email traffic or routing.
You must assign administrative privileges to a helpdesk engineer who only needs to reset passwords for non-administrative users and create helpdesk support requests. Which built-in Microsoft Entra administrative role follows the principle of least privilege?
- Helpdesk Administrator (Correct)
- Global Administrator
- User Administrator
- Privileged Authentication Administrator
Explanation: The Helpdesk Administrator role allows resetting passwords for non-administrators and submitting Microsoft support requests without granting broader administrative capabilities.
You are configuring Microsoft 365 Apps deployment via Microsoft Intune. You need to ensure devices receive monthly feature updates as soon as they are validated and released to the general public, without waiting for semi-annual cycles. Which update channel should you configure?
- Current Channel (Correct)
- Semi-Annual Enterprise Channel
- Beta Channel
- Monthly Enterprise Channel (Preview)
Explanation: Current Channel delivers new Office features to users as soon as they are ready for the general public, typically on a monthly schedule.
An organization wants to monitor service health notifications in Microsoft 365 proactively. You must send incident status and maintenance notices to an external IT email address. What feature in the Microsoft 365 admin center should you configure?
- Service Health email notifications under Preferences in admin center (Correct)
- Windows Event Forwarding to a Syslog server
- Network Performance Monitor in Azure Monitor
- Defender for Cloud Apps governance log export
Explanation: Under Health > Service health > Preferences in the Microsoft 365 admin center, administrators can configure email notifications for incidents and advisories for up to two external email addresses.
You need to enable users in your tenant to collaborate seamlessly in Microsoft Teams shared channels with an external partner organization using their existing corporate credentials. What must you configure in Microsoft Entra External ID?
- B2B direct connect configured via Cross-Tenant Access Settings (Correct)
- Microsoft Entra Application Proxy with Kerberos delegation
- Active Directory Federation Services (AD FS) federated trust
- Azure AD Domain Services forest trust
Explanation: B2B direct connect powers Teams Shared Channels across tenants. It requires configuring mutual inbound and outbound trust within Cross-Tenant Access Settings in both organizations.
You need to ensure that members of the Global Administrator role must explicitly provide a business justification and undergo time-limited activation that automatically expires after 4 hours. Which feature must you deploy?
- Privileged Identity Management (PIM) role activation policies (Correct)
- Entra ID Conditional Access session lifetime controls
- Microsoft 365 Customer Lockbox requests
- Microsoft Purview Privileged Access Management (PAM)
Explanation: Microsoft Entra Privileged Identity Management (PIM) allows role assignments to be configured as eligible, requiring justification, approval, MFA, and time-limited activation.
During an email migration phase, MX records point to Exchange Online Protection. You must prevent contoso.com from being considered an open relay while forwarding unresolved cloud recipients back to on-premises servers. How should the Accepted Domain be configured in Exchange Online?
- Internal Relay (Correct)
- Authoritative
- External Relay
- Non-authoritative Transit
Explanation: An Internal Relay accepted domain informs Exchange Online that recipients can exist in the cloud or on-premises, forwarding unresolvable cloud recipients via outbound connectors.
A company purchases the domain fabrikam.com. You need to configure autodiscover for newly migrated Outlook clients. Which DNS CNAME record target must be configured at the external DNS hosting provider?
- autodiscover.outlook.com (Correct)
- mail.protection.outlook.com
- smtp.office365.com
- clientconfig.microsoftonline.com
Explanation: For Outlook client service discovery, Microsoft 365 requires a CNAME record where autodiscover.<customdomain> points directly to autodiscover.outlook.com.
You need to identify which users in your organization have been assigned active administrative roles in Microsoft 365 without navigating the Azure portal. Which section of the Microsoft 365 admin center provides this consolidated view?
- Roles > Role assignments in the Microsoft 365 admin center (Correct)
- Settings > Domains
- Users > Guest users
- Health > Service health
Explanation: In the Microsoft 365 admin center under Roles > Role assignments, administrators can inspect all active and eligible role assignments across workloads.
You are planning the rollout of Microsoft 365 Apps for Enterprise to 5,000 branch office laptops with constrained WAN links. You want devices to share downloaded chunks locally across peer devices on the same subnet. Which technology should you enable?
- Delivery Optimization (DO) (Correct)
- BranchCache in Hosted Cache mode only
- Background Intelligent Transfer Service (BITS) throttling
- DirectAccess network tunnels
Explanation: Delivery Optimization (DO) is a cloud-managed peer-to-peer distribution technology built into Windows that allows peer clients on the same subnet to share Click-to-Run update binaries.
You manage licensing and need to assign Microsoft 365 E5 licenses automatically to employees in the Sales department whenever a new user is provisioned with department set to "Sales". What should you implement?
- Group-based licensing assigned to a dynamic user security group (Correct)
- A daily PowerShell script using the deprecated MSOnline module
- Exchange Online recipient mail flow transport rules
- Microsoft Purview information barrier policies
Explanation: Group-based licensing in Microsoft Entra ID combined with dynamic user membership groups automatically manages license provisioning based on user profile attributes.
Your company requires that employees must not be allowed to install third-party applications from the Teams app store unless approved by IT. Where should you configure this restriction?
- Teams admin center > Teams apps > Permission policies (Correct)
- Exchange admin center > Mobile device access policies
- Microsoft Entra Enterprise applications > User settings
- Microsoft Intune > Device compliance policies
Explanation: In the Microsoft Teams admin center under Teams apps > Permission policies (or app-centric management), administrators can block third-party applications tenant-wide.
An administrator needs to run a diagnostic on an executive mailbox that is failing to receive inbound messages. Which self-service capability inside the Microsoft 365 admin center provides guided automated checks?
- Integrated "Need Help?" diagnostics in the Microsoft 365 admin center (Correct)
- Microsoft Remote Connectivity Analyzer utility only
- Event Viewer on the local client machine
- Office 365 Performance Benchmark Analyzer
Explanation: The "Need Help?" self-service support pane in the Microsoft 365 admin center runs automated diagnostic tests directly against mail flow, tenant DNS, and recipient configurations.
You want to implement administrative units (AUs) in Microsoft Entra ID so regional helpdesk technicians can reset passwords only for staff in Chicago. What is a key constraint regarding administrative unit scope?
- Administrative units delegate permissions over scoped users, groups, and devices (Correct)
- Administrative units can only delegate Global Administrator permissions
- Administrative units automatically mirror on-premises Active Directory OUs
- Administrative units cannot contain Microsoft Entra security groups
Explanation: Administrative units allow scoping roles (like Helpdesk or User Administrator) strictly to users, groups, or devices placed explicitly inside that AU container.
You are reviewing Microsoft Secure Score recommendations. What is the primary security risk associated with keeping legacy authentication protocols (such as POP3 and IMAP4) enabled in Exchange Online?
- Legacy authentication cannot enforce Multi-Factor Authentication (MFA) (Correct)
- Legacy authentication doubles the required bandwidth for mail routing
- Legacy authentication disables TLS encryption over the wire
- Legacy authentication forces accounts to possess Global Admin rights
Explanation: Legacy protocols cannot enforce Multi-Factor Authentication (MFA) or modern Conditional Access policies, making them vulnerable to credential stuffing attacks.
Your organization plans to customize branding for the Microsoft 365 web sign-in experience, including logos, banners, and text hints. Where is Company Branding configured?
- Microsoft Entra admin center under Company branding (Correct)
- Microsoft 365 admin center under Support requests
- Microsoft Endpoint Manager under Autopilot profiles
- SharePoint Central Administration portal
Explanation: Company branding is configured directly within the Microsoft Entra admin center under Identity > User experiences > Company branding.
A compliance officer requires full visibility into tenant-wide administrative actions (e.g., mailbox creation, role assignments, transport rule modifications). Which log repository stores this activity?
- Microsoft Purview Unified Audit Log (Correct)
- Exchange Message Trace logs only
- Microsoft Intune Device Configuration logs
- Windows Application Event Logs
Explanation: The Microsoft Purview Unified Audit Log aggregates administrative and user activity records across Exchange, SharePoint, OneDrive, Entra ID, and Teams.
You need to deploy the Office Deployment Tool (ODT) to customize an installation that excludes Microsoft Access and includes Visio. Which configuration file type does ODT consume?
- An XML configuration file (configuration.xml) (Correct)
- A JSON parameters template file
- A PowerShell .psd1 manifest file
- A compiled .reg registry script
Explanation: The Office Deployment Tool (ODT) consumes an XML configuration file (configuration.xml) that defines architecture, update channels, and excluded apps.
Executive leadership mandates that employees must not be allowed to share files or folders with unauthenticated anonymous external users using "Anyone" links. Which setting must you configure in the SharePoint admin center?
- Set external sharing to "New and existing guests" or "Existing guests" (Correct)
- Block TCP port 443 on the corporate boundary firewall
- Enable Information Rights Management on every library manually
- Delete all external guest user accounts from Microsoft Entra ID
Explanation: In the SharePoint admin center under Policies > Sharing, reduce the external sharing slider to "New and existing guests" or "Existing guests only" to block anonymous links.
Where in the Microsoft 365 admin center can an administrator confirm the status, last sync timestamp, and health alerts of directory synchronization?
- Settings > Directory sync status in the Microsoft 365 admin center (Correct)
- Billing > Licenses blade
- Reports > Usage blade
- Security & Privacy > Sharing blade
Explanation: In the Microsoft 365 admin center dashboard under Settings > Directory sync status, administrators can inspect synchronization health.
You are configuring data residency settings and need to determine where your organization customer data is stored at rest. Where can this information be verified?
- Settings > Org settings > Organization profile > Data location (Correct)
- Compliance > Audit log retention policies
- Azure Portal > Subscriptions > Resource groups
- Intune > Tenant status > Connector status
Explanation: In the Microsoft 365 admin center under Settings > Org settings > Organization profile > Data location, administrators can view customer data residency.
You need to delegate authority to manage Microsoft Defender XDR security alerts and safe attachments without granting user management or billing permissions. Which built-in role should you assign?
- Security Administrator (Correct)
- Billing Administrator
- Compliance Administrator
- Application Administrator
Explanation: The Security Administrator role grants comprehensive permissions to configure security policies, view alerts, and manage quarantine without user or billing administration rights.
Your company requires read-only visibility for external financial auditors to review subscription billing invoices and license counts. Which role provides read-only access across admin settings including billing?
- Global Reader (Correct)
- User Administrator
- Security Operator
- Exchange Recipient Administrator
Explanation: The Global Reader role provides read-only access to all tenant administration settings, reports, and billing details without allowing modifications.
When adding a domain to Microsoft 365, which DNS record must be created to ensure that external recipient servers verify that emails originating from your tenant are authorized?
- A TXT record specifying "v=spf1 include:spf.protection.outlook.com -all" (Correct)
- A CNAME record for smtp.protection.outlook.com
- A PTR record pointing to the local router IP
- An A record pointing directly to 127.0.0.1
Explanation: A TXT record containing the SPF string "v=spf1 include:spf.protection.outlook.com -all" designates authorized outbound sending servers for the domain.
You need to automatically notify designated IT staff whenever an administrator role assignment changes in your tenant. Which feature inside Microsoft Entra PIM facilitates these alert notifications?
- Microsoft Entra PIM Security Alerts and notification settings (Correct)
- Exchange Online Transport Rules
- Microsoft Purview Data Lifecycle Management
- Intune Endpoint Security baseline alerts
Explanation: Microsoft Entra PIM Security Alerts and notification settings automatically trigger email notifications to designated mailboxes when privileged roles are assigned or activated.
You are managing release preferences for your organization. You want IT staff to test new Microsoft 365 features early while leaving general staff on standard release. Where is this configured?
- Targeted release for selected users under Release preferences (Correct)
- Semi-Annual Enterprise Channel deployment via GPO
- Security Defaults toggle in Microsoft Entra ID
- Disabling Exchange Online transport rules
Explanation: In the Microsoft 365 admin center under Settings > Org settings > Organization profile > Release preferences, configure "Targeted release for selected users".
Your company is enabling Microsoft 365 Backup for high-speed recovery against ransomware. Which workloads can be natively backed up using the Microsoft 365 Backup service?
- SharePoint Online sites, OneDrive accounts, and Exchange Online mailboxes (Correct)
- Azure SQL databases and on-premises Hyper-V hosts
- Physical workstation hard drives and BIOS firmware
- Third-party Salesforce databases only
Explanation: Microsoft 365 Backup natively protects SharePoint Online site collections, OneDrive accounts, and Exchange Online mailboxes within the tenant boundary.
You are configuring Microsoft Entra Connect. You need to enable users to sign in using their on-premises passwords, while enabling Microsoft Entra Identity Protection to detect leaked credentials on the dark web. Which authentication method should you choose?
- Password Hash Synchronization (PHS) (Correct)
- Pass-through Authentication (PTA) with agent clustering
- Active Directory Federation Services (AD FS)
- Direct LDAP Synchronization over TLS
Explanation: Password Hash Synchronization (PHS) syncs password hashes to Microsoft Entra ID, allowing Identity Protection to cross-reference credentials against leaked dark-web dumps.
Your company requires that all remote workers accessing Exchange Online from unmanaged mobile devices must complete MFA and use client apps supporting Intune app protection. Which feature enforces this?
- Conditional Access requiring MFA and approved client apps or app protection (Correct)
- Exchange Online Mailbox Retention Policies
- SharePoint Online storage quota rules
- Windows Firewall inbound port filtering
Explanation: Microsoft Entra Conditional Access enforces Grant controls requiring Multi-Factor Authentication and "Require approved client app" or "Require app protection policy".
You want to enforce an automated self-service password reset whenever Microsoft Entra ID detects that a user account has an elevated "High" user risk. Which policy configuration accomplishes this?
- User Risk Policy requiring MFA and password change (Correct)
- Sign-in Risk Policy configured to block domain controllers
- Exchange Online anti-malware quarantine notification
- Intune device compliance wipe command
Explanation: In Microsoft Entra Identity Protection, a User Risk Policy configured for high risk can enforce MFA and a secure password reset to remediate the compromised credential.
You are deploying Self-Service Password Reset (SSPR) for synchronized hybrid users. You must ensure password changes made in the cloud portal apply immediately on-premises. What component must be enabled in Microsoft Entra Connect?
- Password Writeback in Microsoft Entra Connect (Correct)
- Kerberos Constrained Delegation
- AD FS Relying Party Trust claims rules
- Azure Network Watcher packet capture
Explanation: Password Writeback in Microsoft Entra Connect synchronizes password changes initiated in the cloud back to on-premises Active Directory Domain Services in real time.
An organization wants to eliminate passwords for Windows 11 corporate devices joined to Microsoft Entra ID using biometric verification or a PIN bound to hardware TPM chips. Which technology provides this?
- Windows Hello for Business (Correct)
- NTLMv2 authentication
- Virtual Smart Cards over RDP
- SMS text verification codes
Explanation: Windows Hello for Business provides strong two-factor authentication by binding cryptographic key pairs to hardware TPM chips alongside biometric or PIN verification.
You are planning the migration from Microsoft Entra Connect to Microsoft Entra Cloud Sync. What is an architectural characteristic of Microsoft Entra Cloud Sync compared to traditional Entra Connect Sync?
- Cloud Sync uses lightweight agents and executes sync logic in the cloud (Correct)
- Cloud Sync requires dedicated SQL Server Enterprise instances on-premises
- Cloud Sync does not support synchronizing to Microsoft Entra ID
- Cloud Sync requires inbound open TCP port 443 into on-premises firewalls
Explanation: Microsoft Entra Cloud Sync uses lightweight agents installed on-premises while executing the synchronization engine and mapping logic directly in the Microsoft cloud.
You configure a Conditional Access policy requiring MFA for all administrative portals. You need to ensure emergency access break-glass accounts are not locked out if an MFA outage occurs. What is the best practice?
- Designate emergency access break-glass accounts excluded from policies (Correct)
- Disable MFA tenant-wide during weekend hours
- Share the Global Administrator password across all helpdesk staff
- Configure all admin accounts to use simple predictable passwords
Explanation: Create at least two emergency access break-glass accounts, exclude them explicitly from all Conditional Access policies, and monitor their sign-in activity continuously.
You configure a Conditional Access policy to prevent users on unmanaged web browsers from downloading sensitive documents from SharePoint, while still allowing online viewing. Which session control should you select?
- Session control: Use app-enforced restrictions or Defender for Cloud Apps (Correct)
- DNS sinkholing on client workstations
- Exchange Online OWA mailbox policy disabling all attachments
- Disabling TLS 1.3 across the tenant
Explanation: Use Conditional Access Session controls configured with "Use app-enforced restrictions" or route sessions through Defender for Cloud Apps to block file downloads on unmanaged devices.
You need to configure a mechanism where managers are prompted quarterly to certify that external guest users still require access to sensitive project groups, revoking access if denied. Which feature fulfills this requirement?
- Microsoft Entra Access Reviews (Correct)
- Service Health advisories
- Microsoft Purview Information Barriers
- Microsoft Defender for Identity honeypot accounts
Explanation: Microsoft Entra Access Reviews enables recurring reviews of group memberships and application assignments, automatically revoking access if not reaffirmed.
In Microsoft Entra ID, what is the effect of setting "Users can register applications" to "No" under User Settings?
- Only users with administrative roles can register custom applications (Correct)
- Users can install unlicensed copies of Microsoft Office on personal PCs
- Users can promote their own accounts to Domain Administrator
- Users can purchase enterprise Azure subscriptions without payment cards
Explanation: Only users with designated administrative roles (such as Application Administrator or Application Developer) can register custom enterprise applications and APIs.
You want to defend against MFA fatigue attacks (MFA push spamming) by forcing users to enter digits displayed on the sign-in screen into their Authenticator app. Which feature must you enable?
- Number Matching in Microsoft Authenticator (Correct)
- Voice call verification fallback
- Standard 6-digit TOTP rolling codes
- Email verification links
Explanation: Number Matching in Microsoft Authenticator requires users to enter the specific two-digit code displayed on the login screen before approving the authentication prompt.
Your company has an on-premises web application using Windows Integrated Authentication (Kerberos). You need to publish it securely to remote workers without a VPN. What should you implement in Microsoft Entra ID?
- Microsoft Entra Application Proxy with Kerberos Constrained Delegation (Correct)
- Point-to-Site VPN with SSTP
- Direct RDP port forwarding over port 3389
- Network Address Translation (NAT) pool in Azure Virtual WAN
Explanation: Microsoft Entra Application Proxy with Kerberos Constrained Delegation (KCD) publishes on-premises web applications securely to external users without deploying a VPN.
You need to create a security group in Microsoft Entra ID that dynamically includes all full-time members whose Department equals "Engineering". What syntax should you use in the dynamic membership rule editor?
- (user.department -eq "Engineering") and (user.userType -eq "Member") (Correct)
- SELECT * FROM users WHERE department = 'Engineering'
- department: "Engineering", type: "Member"
- user.department LIKE "%Engineering%" OR user.type == "Admin"
Explanation: The dynamic membership syntax is: (user.department -eq "Engineering") and (user.userType -eq "Member"), ensuring external guests and other departments are filtered out.
An administrator is configuring hybrid device joining using Microsoft Entra Connect. Which object must be configured with a Service Connection Point (SCP) in on-premises Active Directory?
- A Service Connection Point (SCP) in the Active Directory Configuration partition (Correct)
- An MX record in public DNS
- A Group Policy Preference mapped drive
- A schema extension adding custom attributes
Explanation: A Service Connection Point (SCP) in the Active Directory Configuration partition under CN=Services stores tenant registration parameters for hybrid domain joining.
You want to implement Entra ID Terms of Use that external vendors must accept prior to accessing internal SharePoint sites. Which service enforces that users see and consent to the document?
- Conditional Access Grant controls with Terms of Use selected (Correct)
- SharePoint site theme settings
- Exchange Online transport disclaimer rules
- Microsoft 365 admin center partner agreements
Explanation: Terms of Use documents uploaded into Microsoft Entra ID are enforced via Conditional Access Grant controls requiring users to consent before accessing cloud apps.
You are auditing sign-in activity in Microsoft Entra ID. You need to investigate non-interactive sign-in events for automated service principals. Where can this data be filtered in the portal?
- Microsoft Entra ID > Monitoring > Sign-in logs (Service principal sign-ins) (Correct)
- Windows Event Viewer on domain controllers
- Office 365 Security & Compliance spam filter logs
- Azure Cost Management cost analysis blades
Explanation: Under Microsoft Entra ID > Monitoring > Sign-in logs, the "Service principal sign-ins" tab provides logs of non-interactive authentication events for service principals.
Your organization wants to prevent users from selecting easily guessable passwords across both cloud and on-premises Active Directory. What should you deploy?
- Microsoft Entra Password Protection on-premises agent and proxy (Correct)
- Default Domain Controller GPO password complexity flag only
- Windows BitLocker PIN enforcement
- Microsoft Purview Customer Key
Explanation: Microsoft Entra Password Protection deployed with DC agents and proxies validates password changes against global and custom banned lists in real time.
You need to delegate permissions so that a contractor can invite external B2B guest users into your tenant without granting full User Administrator permissions. Which role should you assign?
- Guest Inviter role (Correct)
- Global Administrator role
- Directory Synchronization Accounts role
- Compliance Administrator role
Explanation: The Guest Inviter role allows users to invite external B2B guests without granting broader permissions to modify user accounts or manage group memberships.
In Microsoft Entra Connect, what is the default synchronization frequency of the scheduler for delta synchronization cycles?
- Every 30 minutes (Correct)
- Every 5 minutes
- Every 2 hours
- Once every 24 hours at midnight
Explanation: The default delta synchronization cycle in Microsoft Entra Connect runs automatically every 30 minutes, inspectable via Get-ADSyncScheduler.
You are configuring FIDO2 security keys for passwordless authentication in Microsoft Entra ID. Where do you enable and manage this authentication method?
- Protection > Authentication methods > Policies in Microsoft Entra admin center (Correct)
- Exchange admin center under Mail flow > Connectors
- SharePoint admin center under Access control
- Microsoft Defender portal under Asset inventory
Explanation: Under Protection > Authentication methods > Policies in the Microsoft Entra admin center, administrators can enable and target FIDO2 security keys.
You need to configure Conditional Access to enforce MFA only when a user sign-in session originates from an untrusted network outside corporate IP boundaries. What must you define first in Microsoft Entra ID?
- Named Locations defined by trusted IP address ranges (Correct)
- Active Directory Sites and Services subnets
- DNS forward lookup zones
- Virtual Private Network adapter MAC addresses
Explanation: Named Locations defined by trusted public IP CIDR ranges allow Conditional Access policies to evaluate whether traffic originates inside or outside corporate networks.
A user reports receiving MFA prompts every single time they open Outlook or Teams on corporate laptops. What setting in Conditional Access controls how often a user must re-authenticate?
- Conditional Access Session control: Sign-in frequency (Correct)
- Kerberos ticket lifetime GPO
- Exchange Online ActiveSync device wipe countdown
- SharePoint site collection storage limit
Explanation: Conditional Access Session Lifetime controls (specifically Sign-in frequency) determine how often users are prompted to re-authenticate and complete MFA challenges.
You are implementing Entitlement Management in Microsoft Entra ID. What is the container object that packages access packages, resource catalogs, and access policies for assignment to users?
- Access Package (Correct)
- Security Baseline
- Administrative Unit
- Management Group
Explanation: In Microsoft Entra Entitlement Management, an Access Package is the container that bundles access to groups, Teams, SharePoint sites, and enterprise applications with approval policies.