✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Implement and manage user identities
A company has helpdesk staff in three regional offices. The Global Administrator wants each regional helpdesk team to be able to reset passwords and manage licenses only for the users in their own region, without granting rights over users in other regions. Which feature should be configured to scope these administrative rights?
Administrative units let you scope Microsoft Entra role assignments (such as Helpdesk Administrator or User Administrator) to a defined subset of users, groups, or devices, restricting an admin's permissions to only members of that AU.
Question 2 of 12 · Implement authentication and access management
A manufacturing company has shared kiosk workstations on the factory floor. Multiple workers use the same physical device throughout the day, and each worker needs to sign in with a passwordless credential that they can carry with them between kiosks. Which authentication method should the identity administrator deploy?
FIDO2 security keys are portable external hardware credentials that are not bound to a single device, making them ideal for shared-kiosk scenarios where multiple workers need passwordless sign-in on the same shared workstation.
Question 3 of 12 · Plan and implement workload identities
A company runs a GitHub Actions pipeline that must authenticate to Microsoft Entra ID to deploy resources to Azure. The security team requires that no client secrets or certificates be stored anywhere in the pipeline configuration. Which solution BEST meets this requirement?
Federated credentials (workload identity federation) let GitHub Actions exchange its OIDC token for a Microsoft Entra access token, eliminating the need to store any secret or certificate.
Question 4 of 12 · Plan and automate identity governance
A company wants employees to request access to a bundle of resources (a group, a Teams team, and a SharePoint site) through a single self-service request, requiring approval from the resource owner in stage one and the requestor's manager in stage two. Which Microsoft Entra ID Governance capability BEST meets this requirement?
Access packages in a catalog bundle multiple resource types (groups, Teams, SharePoint sites, apps) for self-service request, and entitlement management supports two-stage approval policies (e.g., owner then manager).
Question 5 of 12 · Implement and manage user identities
A manufacturing company wants to give employees at a partner supplier organization access to a shared SharePoint site using the partner employees' existing corporate credentials, without the company having to create or manage separate accounts for them. Which feature should be used?
Microsoft Entra B2B collaboration is designed for inviting external business partners as guest users who authenticate with their own organization's existing identity, giving them access to internal resources without the resource tenant creating or managing full accounts for them.
Question 6 of 12 · Implement authentication and access management
A company requires users signing in from unmanaged devices to reauthenticate every hour, while users on Microsoft Entra hybrid joined compliant devices should not be interrupted. Which Conditional Access session control configuration meets this requirement?
Sign-in frequency lets administrators force reauthentication after a specified time interval, and scoping the policy with a device filter condition allows it to apply only to unmanaged/non-compliant devices while compliant devices remain unaffected.
Question 7 of 12 · Plan and implement workload identities
An organization has 20 Azure Virtual Machines across multiple resource groups that all need identical access to a Key Vault. The identity must be manageable independently of any single VM's lifecycle and reused across all 20 VMs. Which identity type should be configured?
User-assigned managed identities exist as standalone Azure resources independent of any VM's lifecycle and can be assigned to multiple resources simultaneously, which fits the sharing requirement.
Question 8 of 12 · Plan and automate identity governance
An organization wants new hires to automatically be added to the correct groups and receive a welcome email on their employee hire date, without any manual administrator intervention. Which capability should they configure?
Lifecycle workflows can trigger on the employeeHireDate attribute and the built-in 'Onboard employee' template includes tasks like adding users to groups and sending a welcome email, fully automated.
Question 9 of 12 · Implement and manage user identities
An organization implements Microsoft Entra Connect with password hash synchronization. Assuming default settings are unchanged, how frequently does the sync engine synchronize changes from on-premises Active Directory to Microsoft Entra ID?
The default Microsoft Entra Connect sync cycle runs every 30 minutes; this scheduler value is directly tested on the exam and can be changed with Set-ADSyncScheduler if a different interval is required.
Question 10 of 12 · Implement authentication and access management
A security team wants every activation of the eligible Global Administrator role in Microsoft Entra PIM to require multifactor authentication, approval from a designated approver, and a justification comment from the requesting user. Which single set of role settings satisfies this requirement?
These four settings all live under the role's Activation tab in PIM role settings and together enforce MFA, an approval workflow, and mandatory justification text every time a user activates the eligible Global Administrator assignment.
Question 11 of 12 · Plan and implement workload identities
A backend daemon service runs unattended with no signed-in user and needs to read directory data through Microsoft Graph. Which permission type must be configured on the app registration, and what additional step is required?
A daemon with no signed-in user must use application permissions, which grant the app its own identity-based access; because there is no user to consent, an administrator must explicitly grant admin consent.
Question 12 of 12 · Plan and automate identity governance
An access review for a group is configured with 'If reviewers don't respond' set to 'No change' and auto-apply results is enabled. A reviewer does not respond before the review ends. What happens to the user's group membership?
'No change' is a valid fallback decision for non-responses, and with auto-apply enabled that decision is applied automatically when the review ends, requiring no manual action.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $165 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 4 domains: Implement and manage user identities (20-25%), Implement authentication and access management (25-30%), Plan and implement workload identities (20-25%), Plan and automate identity governance (20-25%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.