exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 44 discussion

Actual exam question from Microsoft's MS-101
Question #: 44
Topic #: 2
[All MS-101 Questions]

HOTSPOT -
You have a Microsoft 365 E5 subscription linked to an Azure Active Directory (Azure AD) tenant. The tenant contains a group named Group1 and the users shown in the following table:

The tenant has a conditional access policy that has the following configurations:
✑ Name: Policy1
✑ Assignments:
- Users and groups: Group1
- Cloud aps or actions: All cloud apps
✑ Access controls:
✑ Grant, require multi-factor authentication
✑ Enable policy: Report-only
You set Enabled Security defaults to Yes for the tenant.
For each of the following settings select Yes, if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Report-only mode is a new Conditional Access policy state that allows administrators to evaluate the impact of Conditional Access policies before enabling them in their environment. With the release of report-only mode:
✑ Conditional Access policies can be enabled in report-only mode.
✑ During sign-in, policies in report-only mode are evaluated but not enforced.
✑ Results are logged in the Conditional Access and Report-only tabs of the Sign-in log details.
✑ Customers with an Azure Monitor subscription can monitor the impact of their Conditional Access policies using the Conditional Access insights workbook.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-report-only

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dan_Turnbull
Highly Voted 4 years ago
You need to turn security defaults off before you can enable the policy: "It looks like you're about to manage your organization's security configurations. That's great! You must first disable Security defaults before enabling a Conditional Access policy." "Security defaults must be disabled to enable Conditional Access policy." I believe the answer is: No, Yes, No
upvoted 54 times
bac0n
2 years, 4 months ago
Tested and confirmed.
upvoted 1 times
...
...
JFRigot
Highly Voted 4 years ago
Yes, yes, no
upvoted 41 times
Prianishnikov
4 years ago
Agree with you, tested this case.
upvoted 5 times
...
RenegadeOrange
2 years, 7 months ago
I tested this, with the conditional access policy set to report-only you can turn on security defaults, when you go to turn on the policy however it won't let you and gives you an error that security defaults must be disabled first. No, Yes, No
upvoted 3 times
...
...
GotDamnImIn
Most Recent 2 years ago
No - Security defaults need to be off before enabling Yes - Has access to do so, no warnings No - Does not have access, cannot even see the policy
upvoted 3 times
...
ElmarK
2 years, 5 months ago
Correct answer is: NO : you cannot enable a policy when security default are enabled. Yes: report-only to off is allowed No: User adminstrator has in addition no rights.
upvoted 1 times
...
RazielLycas
2 years, 9 months ago
as soon as you activate default the conditional policy will become ineffective and not accessible so N-N-N
upvoted 3 times
...
JamesM9
3 years, 1 month ago
"If you're using Conditional Access and have Conditional Access policies enabled in your environment, security defaults won't be available to you" https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults#deployment-considerations Therefore, as a result of this the answer is NNN.
upvoted 8 times
...
TashaGirl
3 years, 1 month ago
The scenario is impossible to achieve: if you have a policy in conditional access you cannot enable security defaults - "It looks like you have Identity Protection policies enabled. Enabling Identity Protection policies prevents you from enabling Security defaults." If you have Security Defaults enabled, you cannot save the conditional access policy.
upvoted 4 times
...
LillyLiver
3 years, 2 months ago
Just tested this scenario in my tenant. Replicated the question and with the Security Defaults set to "Yes" none of the users could enable the policy. So the answer is N, N, N.
upvoted 10 times
Bulldozzer
3 years, 2 months ago
You're right. N,N,N
upvoted 3 times
...
...
Ahema
3 years, 8 months ago
Y-Y-N is the answer User admin don't have access to edit conditional access policies guys
upvoted 8 times
...
Domza
3 years, 8 months ago
Darkwing Duck to the rescue :) Answers are correct. Caz you can have Read Only or OFF - Policy status. To test Conditional policy before applying them. As soon as you switch Policy ON you will get a message "Security defaults must be disabled to enable Conditional Access policy."
upvoted 3 times
Bouncy
2 years, 12 months ago
Which makes it NYN according to your arguments instead of "Answers are correct" ;)
upvoted 3 times
...
...
encxorblood
3 years, 8 months ago
N-Y-N 1. No - Can not set to on. Before the Security defaults must be disabled 2. Yes - Off ist ok with Security defaults must be disabled 3. No - No rights to edit CA
upvoted 13 times
...
Kanta
3 years, 8 months ago
NYN and agreed with below: Because you set Enabled Security defaults to Yes for the tenant... N Conditional access policy can not be changed from report-only to on Y conditional access policy can be changed from report-only to off N user admin role doesn't have rights to modify conditional access policy
upvoted 9 times
...
TesterDude
3 years, 9 months ago
This is a trick question, it's no to all of them. If you enable security defaults you can't use conditional access rules until it's disabled Sources: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults#deployment-considerations If you're using Conditional Access and have Conditional Access policies enabled in your environment, security defaults won't be available to you. If you have a license that provides Conditional Access but don't have any Conditional Access policies enabled in your environment, you are welcome to use security defaults until you enable Conditional Access policies. https://techcommunity.microsoft.com/t5/azure-active-directory-identity/introducing-security-defaults/ba-p/1061414 You can’t enable Security Defaults if you’re already using conditional access policies or other settings which conflict
upvoted 7 times
TesterDude
3 years, 9 months ago
After testing it is No Yes No because you can change conditional access from report-only to Off but not to On while security defaults are enabled
upvoted 8 times
TechMinerUK
2 years, 6 months ago
I agree with TesterDude, you can turn a Conditional Access policy off when Security Baselines is on however you can not enable them without disablng Security Baselines first
upvoted 1 times
...
...
...
GiJoe1987
3 years, 10 months ago
Security defaults must be set to off to modify/ create or turn on a conditional access policy
upvoted 4 times
...
BGM_YKA
3 years, 11 months ago
Because you set Enabled Security defaults to Yes for the tenant... N Conditional access policy can not be changed from report-only to on Y conditional access policy can be changed from report-only to off N user admin role doesn't have rights to modify conditional access policy
upvoted 10 times
...
Matajare
3 years, 11 months ago
Neither can turn anything on or off. Security Default is active, so conditional access policies are disabled. NO-NO-NO
upvoted 1 times
Matajare
3 years, 11 months ago
Sorry, I don't see "Report-Only" mode. YES-YES-NO
upvoted 2 times
...
...
bellorg
4 years ago
Tested on my LAB, don't need to turn off Security Defaults yes, yes. no
upvoted 1 times
Dan_Turnbull
4 years ago
I've tested it too. I had to disable security defaults before enabling: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults#:~:text=Organizations%20that%20choose%20to%20implement,defaults%20must%20disable%20security%20defaults.&text=in%20your%20directory%3A-,Sign%20in%20to%20the%20Azure%20portal%20as%20a%20security%20administrator,to%20Azure%20Active%20Directory%20%3E%20Properties. "Organizations that choose to implement Conditional Access policies that replace security defaults must disable security defaults."
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago