TechNuggets Academy

Implement authentication and access management

Free Microsoft Certified: Identity and Access Administrator Associate practice — 6 questions on Implement authentication and access management, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Implement authentication and access management
A security team wants to eliminate standing access to the Global Administrator role. They require that: (1) no one holds the role permanently, (2) activation requires approval from a designated security officer, (3) Azure AD (Entra) MFA must be performed at the moment of activation, and (4) activations automatically expire after 8 hours. Which PIM configuration satisfies ALL of these requirements?
Eligible assignments require explicit activation (removing standing access). PIM role settings let you require approval by a specific approver, require Entra MFA at activation time, and cap the activation duration (e.g., 8 hours) — all four requirements map directly to PIM role activation settings, not Access Reviews or Conditional Access.
Question 2 of 6 · Implement authentication and access management
An organization creates a custom Conditional Access authentication strength that must exclude SMS, voice call, and Microsoft Authenticator push notifications, allowing only credentials resistant to phishing. Which built-in authentication strength already meets this requirement without customization?
The built-in 'Phishing-resistant MFA' authentication strength only includes FIDO2 security keys, Windows Hello for Business, and certificate-based authentication (smart card) — none of which are vulnerable to phishing via SMS/voice/push interception, satisfying the requirement out of the box.
Question 3 of 6 · Implement authentication and access management
Microsoft Entra ID Protection flags a user with 'High' user risk due to a leaked credentials detection. A Conditional Access user risk policy is configured to require a secure password change for high-risk users, but the affected user has never registered for SSPR and cannot complete the remediation. What should the administrator do FIRST?
Best practice is to verify identity through an out-of-band channel (e.g., phone call to a known number, manager confirmation) before taking any remediation action, then have the user register authentication methods so they can complete the required secure password change, and only then dismiss the risk after confirming legitimate access — this avoids both a security bypass and a permanent lockout.
Question 4 of 6 · Implement authentication and access management
A company has hybrid Azure AD joined Windows devices and wants to deploy Windows Hello for Business without standing up or maintaining an on-premises PKI, and without requiring Windows Server 2016+ domain controllers for key trust. Which deployment model should they choose?
Hybrid Cloud Trust is the newest, simplest deployment model — it requires no on-premises PKI and no specific domain controller version, relying instead on Azure AD Kerberos for authentication against on-premises resources, making it ideal when minimizing infrastructure dependencies.
Question 5 of 6 · Implement authentication and access management
A company onboards external contractors who use only personal Android and iOS phones (no Windows devices, no hardware security keys) and wants them to authenticate without ever entering a password. Which authentication method should the administrator enable and enforce via the Authentication Methods policy?
Microsoft Authenticator passwordless phone sign-in works on both iOS and Android without requiring any password entry or specialized hardware, making it the correct persistent passwordless method for mobile-only contractors.
Question 6 of 6 · Implement authentication and access management
An administrator is asked to explain the core benefit of Continuous Access Evaluation (CAE) compared to traditional Conditional Access session enforcement based purely on token lifetime. Which statement correctly describes this benefit?
CAE enables supported services to receive near real-time signals (critical events like account disable/password reset/high user risk, and some Conditional Access policy changes) and revoke or re-evaluate access immediately, rather than relying solely on the token's original lifetime — closing the gap between a revocation event and enforcement.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →