Question 316

You have a Microsoft 365 tenant.
All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user-owned and are only registered in Azure AD.
You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer from downloading or syncing files. Other users must NOT be restricted.
Which policy type should you create?
  • Question 317

    You have a custom cloud app named App1 that is registered in Azure Active Directory (Azure AD).
    App1 is configured as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.

    Question 318

    You need to identify which roles to use for managing role assignments. The solution must meet the delegation requirements.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 319

    Hotspot Question
    You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

    You plan to implement Azure AD Identity Protection.
    Which users can configure the user risk policy, and which users can view the risky users report?
    To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 320

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have a Microsoft 365 tenant.
    All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services.
    Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.
    You need to block the users automatically when they report an MFA request that they did not initiate.
    Solution: From the Azure portal, you configure the Account lockout settings for multi-factor authentication (MFA).
    Does this meet the goal?