Free MS-100 Exam Braindumps (page: 53)

Page 53 of 98

You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. A temporary employee at your company uses an email address of user1@outlook.com. You need to ensure that the temporary employee can sign in to contoso.com by using the user1@outlook.com account.
What should you do?

  1. From the Azure Active Directory admin center, create a new user.
  2. From the Microsoft 365 admin center, create a new contact.
  3. From the Azure Active Directory admin center, create a new guest user.
  4. From the Microsoft 365 admin center, create a new user.

Answer(s): C

Explanation:

You can invite guest users to the directory, to a group, or to an application. After you invite a user through any of these methods, the invited user's account is added to Azure Active Directory (Azure AD), with a user type of Guest. The guest user must then redeem their invitation to access resources. An invitation of a user does not expire.
The invitation will include a link to create a Microsoft account. The user can then authenticate using their Microsoft account. In this question, the external vendor already has a Microsoft account (user1@outlook.com) so he can authenticate using that.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/b2b/add-users-administrator



Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains 10,000 users.
The company has a Microsoft 365 subscription.
You enable Azure Multi-Factor Authentication (MFA) for all the users in contoso.com.
You run the following query.
search "SigninLogs" | where ResultDescription == "User did not pass the MFA challenge." The query returns blank results.
You need to ensure that the query returns the expected results.
What should you do?

  1. From the Azure Active Directory admin center, con gure the diagnostics settings to archive logs to an Azure Storage account.
  2. From the Security & Compliance admin center, turn on auditing.
  3. From the Security & Compliance admin center, enable O ce 365 Analytics.
  4. From the Azure Active Directory admin center, con gure the diagnostics settings to send logs to an Azure Log Analytics workspace.

Answer(s): D

Explanation:

You can now send audit logs to Azure Log Analytics. This gives you much easier reporting on audit events and the ability to perform queries such as the one in this question.
References:
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-log-analytics


Reference:

References:
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-log-analytics



Your company has a Microsoft 365 subscription that has multi-factor authentication con gured for all users. Users that connect to Microsoft 365 services report that they are prompted for multi-factor authentication multiple times a day. You need to reduce the number of times the users are prompted for multi-factor authentication on their company-owned devices. Your solution must ensure that users are still prompted for MFA.
What should you do?

  1. Enable the multi-factor authentication trusted IPs setting, and then verify each device as a trusted device.
  2. Enable the remember multi-factor authentication setting, and then verify each device as a trusted device.
  3. Enable the multi-factor authentication trusted IPs setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).
  4. Enable the remember multi-factor authentication setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).

Answer(s): B

Explanation:

The remember Multi-Factor Authentication feature for devices and browsers that are trusted by the user is a free feature for all Multi-Factor Authentication users.
Users can bypass subsequent veri cations for a speci ed number of days, after they've successfully signed-in to a device by using Multi-Factor Authentication.
The feature enhances usability by minimizing the number of times a user has to perform two-step veri cation on the same device.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings



SIMULATION
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
You may now click next to proceed to the lab.

Lab information
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
admin@admin.onmicrosoft.com
Microsoft 365 Password: xxxxxxxxxx
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:

Lab Instance: 111111111
You plan to allow the users in your organization to invite external users as guest users to your Microsoft 365 tenant. You need to prevent the organization's users from inviting guests who have an email address that uses a su x of @gmail.com.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

You need to add gmail.com as a denied domain in the 'External collaboration settings'.
1. Go to the Azure Active Directory admin center.
2. Select Users then select 'User settings'.
3. Under External Users, select the 'Manage external collaboration settings'.
4. Under 'Collaboration restrictions', select the 'Deny invitations to the speci ed domains' option.
5. Under, Target Domains, type in the domain name 'gmail.com'
6. Click the Save button at the top of the screen to save your changes.
References:
https://docs.microsoft.com/en-us/azure/active-directory/b2b/allow-deny-list


Reference:

References:
https://docs.microsoft.com/en-us/azure/active-directory/b2b/allow-deny-list



Page 53 of 98



Post your Comments and Discuss Microsoft MS-100 exam with other Community members:

Elan commented on March 05, 2024
Nice to see this kind of websites. thanks
BAHRAIN
upvote

SYED NASEEMUDDIN commented on December 14, 2023
i need the 100 question and answer.
SAUDI ARABIA
upvote

Rotciv commented on June 13, 2023
MS-100 exam written and passed! I like the application as well
SOUTH AFRICA
upvote

Murchu commented on March 14, 2023
This dump was a lifesaver and gave me the confidence I needed to pass my exam.
UNITED STATES
upvote

George commented on March 02, 2022
My 4th purchase from this site and I have passed all my exams.
UNITED STATES
upvote

Rohit commented on February 28, 2021
The content of this study guide is very helpful. I really appreicate the free test engine. The Xengine App provided for free is a lifesaver.
INDIA
upvote

Hizkia commented on April 20, 2020
Very professional team. The support replied and answered my questions in less than 2 hours. Pretty impressed!
FRANCE
upvote