← Microsoft 365 Certified: Administrator Expert
AZURE · objective · 29% of the exam
Implement and manage Microsoft Entra identity and access — Microsoft 365 Certified: Administrator Expert
The official AZURE documentation our Implement and manage Microsoft Entra identity and access practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Microsoft — How to Use Conditions in Conditional Access Policies - Microsoft Entra ID | Microsoft Learn
configure a policy with a Device platforms condition that includes any device, excludes supported device platforms, and sets Grant control to Block access.
-
Microsoft — Build Conditional Access policies in Microsoft Entra - Microsoft Entra ID | Microsoft Learn
all applicable policies must be satisfied. For example, if one policy requires multifactor authentication and another requires a compliant device, you must complete MFA, and
-
Microsoft — How to manage groups - Microsoft Entra | Microsoft Learn
Group type. You can't change the type of group after it's been created. To change the Group type , you must delete the group and
-
Microsoft — Learn About Groups, Group Membership, and Access - Microsoft Entra | Microsoft Learn
You can create a dynamic group for either devices or users, but not for both. You can't create a device group based on the device
-
Microsoft — Manage users and groups assignment to an application - Microsoft Entra ID | Microsoft Learn
When you assign a group to an application, only users in the group have access. The assignment doesn't cascade to nested groups.
-
Microsoft — Plan Your Microsoft Entra Conditional Access Deployment - Microsoft Entra ID | Microsoft Learn
Microsoft Entra ID P2 is required to include Microsoft Entra ID Protection risk in Conditional Access policies.
-
Microsoft — Users, groups, licensing, and roles in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn
Microsoft Entra users who join a licensed group are automatically assigned the appropriate licenses. When users leave the group, Microsoft Entra ID removes their license
-
Microsoft — Microsoft Entra Conditional Access: Zero Trust Policy Engine - Microsoft Entra ID | Microsoft Learn
Conditional Access policies are enforced after first-factor authentication is completed. Conditional Access isn't intended to be an organization's frontline defense for scenarios like denial-of-service (DoS)