Question 11

You have an Azure Active Directory (Azure AD) tenant that contains the groups shown in the following table.

For which groups can you create an access review?
  • Question 12

    You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
    You need to ensure that User1 can create access reviews for groups, and that User2 can review the history report for all the completed access reviews. The solution must use the principle of least privilege.
    Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content NOTE: Each correct selection is worth one point.

    Question 13

    Your network contains an on-premises Active Directory domain named contoso.com that syncs with a Microsoft Entra tenant by using Microsoft Entra Connect. The domain contains the users shown in the following table.

    From Active Directory Users and Computers, you add the following user
    * Name: User3
    * UPN: [email protected]
    * Proxy addresses: smtp: [email protected], smtp: [email protected]
    From Active Directory Users and Computers, you update the proxyAddresses attribute for each user as shown in the following table.

    You trigger a manual synchronization.
    Which sync status will Microsoft Entra Connect sync return for each user? To answer, drag the appropriate status to the correct users. Each status may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    Question 14

    You have a Microsoft 365 subscription that contains the users shown in the following table.

    From the tenan1, you configure a naming policy for groups.
    Which users are affected by the naming policy?
  • Question 15

    You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table.

    Which objects can you add as eligible in Azure Privileged identity Management (PIM) for an Azure AD role?