Free Microsoft Certified: Identity and Access Administrator Associate practice — 6 questions on Implement and manage user identities, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Implement and manage user identities
Contoso currently uses federated authentication (AD FS) for all 50,000 users. IT wants to migrate to Microsoft Entra Connect with Password Hash Sync and evaluate the impact on a pilot group of 200 users in the Sales department before cutting the entire directory over, without modifying the existing federation trust. What should they configure?
Staged Rollout lets admins enable cloud authentication features (PHS, PTA, Seamless SSO) for a specific security group of users while the domain remains federated for everyone else, providing a safe pilot before full cutover.
Question 2 of 6 · Implement and manage user identities
Fabrikam wants to collaborate with users from partner organization Adatum inside a Microsoft Teams shared channel. Adatum users must authenticate with their own Adatum credentials, and no guest user object should be created in Fabrikam's tenant. Both organizations must configure mutual cross-tenant trust settings for this to work. Which capability should be used?
B2B direct connect establishes a mutual, two-way trust relationship between two Microsoft Entra tenants specifically for scenarios like Teams shared channels, and it does not create a guest object in either tenant's directory.
Question 3 of 6 · Implement and manage user identities
Contoso's identity admin must ensure that Global Administrators cannot reset passwords or edit profile attributes for the CEO and board members' accounts, even though those admins retain their tenant-wide role elsewhere. Only members of the role-assignable 'Executive Support' group should be able to manage these specific accounts. What should be configured?
A restricted management administrative unit prevents even Global Administrators (unless explicitly assigned a role on that unit) from managing its members, while a scoped role assignment to Executive Support grants exactly the least-privilege management needed.
Question 4 of 6 · Implement and manage user identities
An organization wants users to reset their on-premises Active Directory password through Microsoft Entra self-service password reset (SSPR), with the new password written back to on-premises AD in near real time. Which combination is required to make this work?
Password writeback requires enabling the writeback feature in Microsoft Entra Connect, a Microsoft Entra ID P1 (or P2) license for SSPR writeback, and SSPR itself configured and enabled for the relevant users.
Question 5 of 6 · Implement and manage user identities
After configuring Microsoft Entra Connect with Password Hash Sync, synchronization fails for two on-premises user accounts with the error 'Attribute proxyAddresses or userPrincipalName must be unique across the directory.' Investigation shows both AD accounts were accidentally assigned the same email-based value during a migration. Which Microsoft Entra Connect feature automatically appends a temporary suffix to one of the conflicting values so synchronization can proceed while the source data issue is fixed?
Duplicate Attribute Resiliency (DAR) automatically detects duplicate proxyAddresses or userPrincipalName values and appends a temporary suffix to one of them, allowing sync to continue until an administrator corrects the source data in AD.
Question 6 of 6 · Implement and manage user identities
A user is a member of two groups: one assigns a Microsoft 365 E3 license (which includes Intune and EMS service plans), and another assigns a standalone Enterprise Mobility + Security E3 license whose service plans conflict with plans already granted by the M365 E3 license. The Microsoft Entra admin center shows a licensing 'Problem' status for the user. What is the recommended way to resolve the conflict while keeping the user in both groups for other purposes, such as Conditional Access targeting?
Group-based licensing allows admins to disable individual service plans within a group's license assignment via 'Assign options,' resolving the duplicate/conflicting plan while preserving the group memberships needed for other purposes.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.