Microsoft AZ-305 Exam
Designing Microsoft Azure Infrastructure Solutions (Page 2 )

Updated On: 12-Feb-2026
View Related Case Study

HOTSPOT (Drag and Drop is not supported)

You need to ensure that users managing the production environment are registered for Microsoft Entra MFA and must authenticate by using Microsoft Entra MFA when they sign in to the Azure portal. The solution must meet the authentication and authorization requirements.

What should you do? To answer, select the appropriate options in the answer area.

Note: Each correct selection is worth one point.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Microsoft Entra ID Protection
Only users that manage the production environment by using the Azure portal must connect from a hybrid Microsoft Entra-joined device and authenticate by using Azure Multi-Factor Authentication (MFA).

Note: Policy configuration
1. Navigate to the Azure portal.
2. Browse to Microsoft Entra ID > Security > Identity Protection > MFA registration policy.
3. Under Assignments
4. Users – Choose All users or Select individuals and groups if limiting your rollout.
5. Optionally you can choose to exclude users from the policy.
6. Enforce Policy – On
7. Save

Box 2: Grant control in capolicy1
The litware.com tenant has a Conditional Access policy named Capolicy1. Capolicy1 requires that when users manage the Azure subscription for a production environment by using the Azure portal, they must connect from a Microsoft Entra hybrid joined device.

Note: We need to configure the policy conditions for capolicy1 that prompt for MFA.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure- mfa-policy https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa



View Related Case Study

After you migrate App1 to Azure, you need to enforce the data modification requirements to meet the security and compliance requirements.

What should you do?

  1. Create an access policy for the blob service.
  2. Implement Azure resource locks.
  3. Create Azure RBAC assignments.
  4. Modify the access level of the blob service.

Answer(s): A

Explanation:

Scenario: Once App1 is migrated to Azure, you must ensure that new data can be written to the app, and the modification of new and existing data is prevented for a period of three years.
As an administrator, you can lock a subscription, resource group, or resource to prevent other users in your organization from accidentally deleting or modifying critical resources. The lock overrides any permissions the user might have.


Reference:

https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/lock-resources



View Related Case Study

HOTSPOT (Drag and Drop is not supported)

To meet the authentication requirements of Fabrikam, what should you include in the solution? To answer, select the appropriate options in the answer area.

Note: Each correct selection is worth one point.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: 1
One single Microsoft Entra tenant is needed as only the Corp tenant is migrated.

Box 2: 2
One conditional access policy for Multi-Factor Authentication (MFA) will be used for icrosofthve access, and a second conditional access policy in order to prevent external access.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- location https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- admin-mfa



View Related Case Study

HOTSPOT (Drag and Drop is not supported)

To meet the authentication requirements of Fabrikam, what should you include in the solution? To answer, select the appropriate options in the answer area.

Note: Each correct selection is worth one point.

Hot Area:


  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: 1
One single Microsoft Entra tenant is needed as only the Corp tenant is migrated.

Box 2: 2
One conditional access policy for Multi-Factor Authentication (MFA) will be used for icrosofthve access, and a second conditional access policy in order to prevent external access.

Box 3: 1


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- location https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-

admin-mfa



View Related Case Study

You need to recommend a notification solution for the IT Support distribution group.

What should you include in the recommendation?

  1. a SendGrid account with advanced reporting
  2. an action group
  3. Azure Network Watcher
  4. Microsoft Entra Connect Health

Answer(s): D

Explanation:

Scenario: An email distribution group named IT Support must be notified of any issues relating to the directory synchronization services.
Directory synchronization between Microsoft Entra ID and corp.fabrikam.com must not be affected by a link failure between Azure and the on- premises network.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-operations






Post your Comments and Discuss Microsoft AZ-305 exam prep with other Community members:

Join the AZ-305 Discussion