Free MS-100 Exam Braindumps (page: 50)

Page 50 of 98

Your company recently purchased a Microsoft 365 subscription.
You enable Microsoft Azure Multi-Factor Authentication (MFA) for all 500 users in the Azure Active Directory (Azure AD) tenant. You need to generate a report that lists all the users who completed the Azure MFA registration process. What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.

  1. From Azure Cloud Shell, run the Get-AzureADUser cmdlet.
  2. From Azure Cloud Shell, run the Get-MsolUser cmdlet.
  3. From the Azure Active Directory admin center, use the Usage & insights blade.
  4. From the Azure Active Directory admin center, use the Risky sign-ins blade.

Answer(s): B

Explanation:

You can use the Get-MsolUser cmdlet to generate a report that lists all the users who completed the Azure MFA registration process. The full command would look like this:
Get-MsolUser -All | Where-Object {$_.StrongAuthenticationMethods.Count -eq 0} | Select-Object -Property UserPrincipalName


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-reporting Topic 4



You have a Microsoft 365 Enterprise subscription.
You have a conditional access policy to force multi-factor authentication when accessing Microsoft SharePoint from a mobile device. You need to view which users authenticated by using multi-factor authentication.
What should you do?

  1. From the Microsoft 365 admin center, view the Security & Compliance reports.
  2. From the Azure Active Directory admin center, view the user sign-ins.
  3. From the Microsoft 365 admin center, view the Usage reports.
  4. From the Azure Active Directory admin center, view the audit logs.

Answer(s): B

Explanation:

With the sign-ins activity report in the Azure portal, you can get the information you need to determine how your environment is doing.
The sign-ins report can provide you with information about the usage of managed applications and user sign-in activities, which includes information about multi- factor authentication (MFA) usage. The MFA data gives you insights into how MFA is working in your organization. It enables you to answer questions like:
Was the sign-in challenged with MFA?
How did the user complete MFA?

Why was the user unable to complete MFA?
How many users are challenged for MFA?
How many users are unable to complete the MFA challenge?
What are the common MFA issues end users are running into?


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-reporting



You have a Microsoft 365 Enterprise E5 subscription.
You need to enforce multi-factor authentication on all cloud-based applications for the users in the nance department.
What should you do?

  1. Create a sign-in risk policy.
  2. Create a new app registration.
  3. Assign an Enterprise Mobility + Security E5 license to the nance department users.
  4. Con gure the sign-in status for the user accounts of the nance department users.

Answer(s): A

Explanation:

You can con gure a sign-in risk policy that applies to the Finance department users. The policy can be con gured to 'Allow access' but with multi-factor authentication as a requirement.
Note:
There are several versions of this question in the exam. The question has two possible correct answers:
1. Create a sign-in risk policy.
2. Create a conditional access policy.
Other incorrect answer options you may see on the exam include the following:
1. Create an activity policy.
2. Create a session policy.
3. Create an app permission policy.
4. Con gure the sign-in status for the user accounts of the nance department users.
5. Assign an Enterprise Mobility + Security E5 license to the nance department users.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-sign-in-risk-policy



Your network contains an on-premises Active Directory domain named contoso.local. The domain contains ve domain controllers. Your company purchases Microsoft 365 and creates a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. You plan to install Azure AD connect on a member server and implement pass-through authentication. You need to prepare the environment for the planned implementation of pass-through authentication. Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  1. Modify the email address attribute for each user account.
  2. From the Azure portal, add a custom domain name.
  3. From Active Directory Domains and Trusts, add a UPN su x.
  4. Modify the User logon name for each user account.
  5. From the Azure portal, con gure an authentication method.
  6. From a domain controller, install an Authentication Agent.

Answer(s): B,C,F

Explanation:

The on-premise Active Directory domain is named contoso.local. Before you can con gure Azure AD Connect, you need to purchase a routable domain, for example, contoso.com.
You then need to add the domain contoso.com to Microsoft as a custom domain name.
The user accounts in the Active Directory domain need to be con gured to use the domain name contoso.com as a UPN su x. You need to add contoso.com to the Active Directory rst by using Active Directory Domains and Trusts to add contoso.com add a UPN su x. You can then con gure each account to use the new
UPN su x.
An Authentication Agent is required on a domain controller to perform the authentication when pass-through authentication is used. When the custom domain and user accounts are con gured, you can install and con gure Azure AD Connect. An Authentication Agent is installed when you select the pass-through authentication option in the Azure AD Connect con guration or you can install the Authentication Agent manually.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-quick-start



Page 50 of 98



Post your Comments and Discuss Microsoft MS-100 exam with other Community members:

Elan commented on March 05, 2024
Nice to see this kind of websites. thanks
BAHRAIN
upvote

SYED NASEEMUDDIN commented on December 14, 2023
i need the 100 question and answer.
SAUDI ARABIA
upvote

Rotciv commented on June 13, 2023
MS-100 exam written and passed! I like the application as well
SOUTH AFRICA
upvote

Murchu commented on March 14, 2023
This dump was a lifesaver and gave me the confidence I needed to pass my exam.
UNITED STATES
upvote

George commented on March 02, 2022
My 4th purchase from this site and I have passed all my exams.
UNITED STATES
upvote

Rohit commented on February 28, 2021
The content of this study guide is very helpful. I really appreicate the free test engine. The Xengine App provided for free is a lifesaver.
INDIA
upvote

Hizkia commented on April 20, 2020
Very professional team. The support replied and answered my questions in less than 2 hours. Pretty impressed!
FRANCE
upvote