exam questions

Exam MS-900 All Questions

View all questions & answers for the MS-900 exam

Exam MS-900 topic 1 question 24 discussion

Actual exam question from Microsoft's MS-900
Question #: 24
Topic #: 1
[All MS-900 Questions]

Your company makes use of Microsoft 365 in their environment.
You have been tasked with making sure that admin roles are protected. The feature you use should achieve this by requiring approvals.
Which of the following is a feature you should use?

  • A. Mobile application protection policy.
  • B. Microsoft Azure AD Identity Protection.
  • C. Microsoft Azure AD Privilege Identity Protection.
  • D. Microsoft Azure AD Conditional Access.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rabadonqz
Highly Voted 3 years, 5 months ago
Selected Answer: C
Answer is C. You cant configure or protect Admin accounts without Privileged Identity Management. Azure AD Identity Protection is for monitoring and protecting USER accounts not ADMIN accounts.
upvoted 27 times
...
PizzaPasta
Highly Voted 3 years, 6 months ago
its either a typo here in the question or a catch question, there is no Microsoft Azure AD privilege identity protection, be aware of features and namings...
upvoted 22 times
OyYaGotta
1 year, 1 month ago
This is correct. However there is a NEW feature called Privileged Identity Management (PIM). This may be in the new exam release.
upvoted 2 times
...
...
bigdaddyzaddy
Most Recent 6 months, 2 weeks ago
Selected Answer: C
Guys some of the questions need to be updated as Microsoft has not only changed names but added new features. The answer is C. But the name is now Microsoft Entra Privileged Identity Manager (PIM) (PIM) is the feature that can protect high-privilege accounts like Global Administrators by utilizing dynamic risk profiles. It is part of the Entra ID security suite and helps manage, control, and monitor access to privileged roles within your environment. Key Features of PIM: Just-in-Time (JIT) Access: Allows Global Administrators to request elevated privileges when needed, with approval workflows in place. Dynamic Risk Profiles: PIM can evaluate risk factors dynamically based on user activity and conditions (e.g., geographic location or unusual sign-ins). If suspicious activity is detected, PIM can enforce additional security measures, such as multi-factor authentication (MFA) or just-in-time activation for global administrators.
upvoted 2 times
...
ROSEMARIE
11 months ago
C it should be PIM
upvoted 3 times
...
kiik32
1 year, 3 months ago
Selected Answer: C
pim is what requests authorization prior elevating your role
upvoted 4 times
...
NoursBear
1 year, 3 months ago
C for me too, people are mixing the two features and the given answer is simply wrong. People need to read the question again
upvoted 2 times
...
pk191
1 year, 7 months ago
Selected Answer: C
Clearly is C, PIM is about APPROVING elevated roles, NOT Identity Protection !! (There is no approval in Identity Protection config)
upvoted 1 times
...
Dhelailla
1 year, 8 months ago
Correct Answer: B Microsoft Azure AD Identity Protection. = Protection of roles. Microsoft Azure AD Privilege Identity Protection. = Just-in-time activate privileged role assignments. See Also: https://learn.microsoft.com/en-us/entra/id-protection/how-to-deploy-identity-protection
upvoted 3 times
...
Du_MS900
1 year, 8 months ago
Para garantir que as funções administrativas estejam protegidas exigindo aprovações, você deve usar a "Proteção de Identidade do Microsoft Azure AD" (opção B). Essa é uma solução que ajuda a proteger as identidades e contas dos administradores, tornando o acesso mais seguro e garantindo a integridade das credenciais administrativas. A Proteção de Identidade do Microsoft Azure AD oferece recursos para proteger contra ameaças de segurança, como autenticação multifator, políticas de senha e verificações de identidade, que podem ser configuradas para exigir aprovações ou aprovações adicionais para atividades administrativas críticas.
upvoted 1 times
...
Tyffty
1 year, 9 months ago
Selected Answer: C
PIM is the answer
upvoted 1 times
...
Snakad
1 year, 10 months ago
The B is correct, Privileged Identity Management is for have admin right / roles for a specific time. https://learn.microsoft.com/en-us/answers/questions/127057/what-is-the-key-difference-between-priviledged-ide
upvoted 1 times
...
Storm
1 year, 10 months ago
Answer : C The only answer where it is possible to require approval is PIM. Seems a lot of people think it should be Conditional Access. Conditional Access is used to protect the login eg. MFA. But you cannot require approval.
upvoted 1 times
...
UzziTheOne
1 year, 11 months ago
Selected Answer: B
The answer is B.
upvoted 2 times
Tyffty
1 year, 9 months ago
Is this guy a troll
upvoted 1 times
...
...
UzziTheOne
1 year, 11 months ago
Selected Answer: B
The answer is B.
upvoted 1 times
...
RahulX
1 year, 11 months ago
Privileged Identity Management is the correct ans.
upvoted 1 times
...
Tyffty
1 year, 11 months ago
Conditional access doesn't have anything to do with approval. CA restricts. PIM approves
upvoted 1 times
...
https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure Azure AD Privileged Identity Management
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...