exam questions

Exam AZ-103 All Questions

View all questions & answers for the AZ-103 exam

Exam AZ-103 topic 5 question 24 discussion

Actual exam question from Microsoft's AZ-103
Question #: 24
Topic #: 5
[All AZ-103 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com that contains the users shown in the following table.

You enable password reset for contoso.onmicrosoft.com as shown in the Password Reset exhibit. (Click the Password Reset tab.)

You configure the authentication methods for password reset as shown in the Authentication Methods exhibit. (Click the Authentication Methods tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Two methods are required.

Box 2: No -
Self-service password reset is only enabled for Group2, and User1 is not a member of Group2.

Box 3: Yes -
As a User Administrator User3 can add security questions to the reset process.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/quickstart-sspr https://docs.microsoft.com/en-us/azure/active-directory/authentication/active-directory-passwords-faq

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Exam103
Highly Voted 5 years, 1 month ago
imho it is: No, No, No. A User Administrator is not able to change these settings.
upvoted 39 times
ExamPrep
5 years, 1 month ago
Agreed - No, No, No Just tried it - created a user with the 'User Administrator' role and went into Azure Active Directory. The 'password reset' section is greyed out.
upvoted 12 times
ExamPrep
5 years, 1 month ago
Also here specifically states that the User Administrator role has no access to MFA settings: https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#user-administrator
upvoted 6 times
_syamantak
4 years, 9 months ago
SSPR is different from MFA.
upvoted 2 times
...
...
jamesej_2020
4 years, 10 months ago
because u need P2 license to use SSPR. lol
upvoted 2 times
jjkidd72
4 years, 8 months ago
At least P1 or free trial.
upvoted 1 times
...
...
...
certificatores
5 years, 1 month ago
there is no source for this statement but from below one, we can come to this conclusion. but it is still not clear cut https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles
upvoted 1 times
...
sk1974
4 years, 9 months ago
Yes . An 'Authentication administrator' has those privileges - https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#authentication-administrator-permissions
upvoted 1 times
...
...
Shades
Highly Voted 4 years, 10 months ago
1) No : Because they have chosen number of methods required to reset :2 (Its not optional now) 2) No because user one does not belong to grp 2 , which is selected for password reset 3) No: because it cant be done by User admin. It has to be done by Global Admin: see in link below , it says to log in as Global Admin https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr
upvoted 13 times
Estowicz
4 years, 9 months ago
Thank you!
upvoted 1 times
...
Shades
4 years, 9 months ago
I chose 2 methods for Password reset : Mobile (SMS) & security questions. Had to answer both while authenticating ( I had chosen MFA)
upvoted 1 times
...
Shades
4 years, 9 months ago
I tired it & while I clicked on forgot password , It took me to a page where it asked for verification code and then security questions. I did not have a choice
upvoted 1 times
...
...
I
Most Recent 4 years, 2 months ago
The answers should be No, No, No. There has no such a role called User Administritor! If User3 were User Access Administrator, then the third one would be 'Yes'. Really suspect the questions here are not from Microsoft because of so many wrongs.
upvoted 1 times
I
4 years, 2 months ago
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#user-access-administrator
upvoted 1 times
...
...
portabrothers
4 years, 3 months ago
in my test answer 3 is NO
upvoted 1 times
...
Aghora
4 years, 5 months ago
NO NO NO user admin can not enable or play with MFA https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 1 times
...
maj1155
4 years, 5 months ago
Note Security questions are stored privately and securely on a user object in the directory and can only be answered by you during registration. There is no way for your administrator to read or modify your questions or answers. If you don't see the security questions option, it's possible that your organization doesn't allow you to use security questions for verification. If this is the case, you'll need to choose another method or contact your administrator for more help. Administrator accounts are not allowed to use Security Questions as a password reset method. If you are logged in as an admin level account you will not see these options.
upvoted 1 times
...
Thi
4 years, 6 months ago
NO No No I will choose as per discussion
upvoted 1 times
Thi
4 years, 6 months ago
given answer is correct. Last box is yes because as per microsoft User Administrator Create and manage all aspects of users and groups Manage support tickets Monitor service health Change passwords for users, Helpdesk administrators, and other User Administrators
upvoted 1 times
...
...
jamhaneef
4 years, 8 months ago
No one knows strongly what the correct answer is?
upvoted 1 times
...
groy
4 years, 8 months ago
Given answers are correct..
upvoted 1 times
...
Xtian_ar
4 years, 9 months ago
Third is wrong, the correct answer is NO. I have tested it and a User administrator has the option to configure password reset grayed out.
upvoted 1 times
Xtian_ar
4 years, 8 months ago
I realized that may be the third is YES, because the statement says that User3 can add security questions to the password reset process, because the user is member of group 2 that has MFA enabled for his user too. It does not matter the role
upvoted 1 times
...
...
ted22222222
4 years, 10 months ago
box1: Yes Two methods are options either use Mobile phone or Security Questions to reset the password. So the user 2 choose Security questions to reset the password, after answer 3 security questions, he can reset his password . Unless his answers wrong.
upvoted 1 times
Mjrt
4 years, 10 months ago
Number of authentication methods required This option determines the minimum number of the available authentication methods or gates a user must go through to reset or unlock their password. It can be set to either one or two. https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks Two options methods is not optional, so box1:No
upvoted 1 times
bartw
4 years, 3 months ago
In the text of your link: You can configure the number of the available authentication methods a user must provide to reset or unlock their password. This value can be set to either one or two. Users can, and should, register multiple authentication methods. Again, it's highly recommended that users register two or more authentication methods so they have more flexibility in case they're unable to access one method when they need it. this is about registering the number of methods, not the how much needed to reset password.
upvoted 1 times
...
...
...
ahmed812
4 years, 11 months ago
User2 needs 2 methods. Agree!!
upvoted 3 times
...
GDup
4 years, 11 months ago
Third question is No. Tested it. User Administrator role does not have access to Azure Active Directory > Password Reset
upvoted 4 times
...
ahmed812
4 years, 11 months ago
User2 is member of group2 and it has SSPR enabled. The requirement is 3 question to reset the password. So first one is YES
upvoted 2 times
macco455
4 years, 11 months ago
Incorrect, 2 different methods are required for password reset so just answering the 3 questions will not work
upvoted 6 times
ted22222222
4 years, 10 months ago
Two methods are options either use Mobile phone or Security Questions to reset the password.
upvoted 2 times
Xtian_ar
4 years, 8 months ago
no, two methods are not only opctions, are required too
upvoted 4 times
...
...
...
...
PretoBruno
4 years, 11 months ago
User2: Two authentication methods are required for password reset as per the exhibit. User1: Self-service password reset is only enabled for Group2 (User1 is not a member of Group2). User3: has an administrator role assigned that DOES NOT support security questions as the second authentication method for password reset: Microsoft enforces a strong default two-gate password reset policy for any Azure administrator role. This policy may be different from the one you have defined for your users, and this policy can't be changed. You should always test password reset functionality as a user without any Azure administrator roles assigned. With a two-gate policy, administrators don't have the ability to use security questions. https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-policy
upvoted 1 times
...
[Removed]
4 years, 12 months ago
Yes, the satisfaction of one of the options is enough to proceed: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks No, not a member of the right group No, "User with this role do not have permissions to manage MFA." https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles#user-administrator
upvoted 2 times
_syamantak
4 years, 9 months ago
Youre wrong. the link clearly says : "If the policy requires two methods, check that the user has the appropriate data defined for at least two of the authentication methods enabled by the administrator policy."
upvoted 1 times
...
...
Cloudyuga
5 years ago
Answers are correct. To test this u need a Azure AD P2 licence.
upvoted 3 times
jamesej_2020
4 years, 10 months ago
lier. dont confuse people. https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-licensing
upvoted 2 times
_syamantak
4 years, 9 months ago
A few lines back you only lol'd another comment saying SSPR needed P2 license!
upvoted 1 times
...
_syamantak
4 years, 9 months ago
Basic SSPR features are available in Microsoft 365 Business Standard or higher and all Azure AD Premium SKUs at no cost
upvoted 1 times
...
jamhaneef
4 years, 6 months ago
I think you dont know anything. ha ha.. He is right
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago