Free MS-100 Exam Braindumps (page: 48)

Page 47 of 98

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft 365 E5 subscription and an Azure AD tenant named contoso.com.

All users have computers that run Windows 11, are joined to contoso.com, and are protected by using BitLocker Drive Encryption (BitLocker).

You plan to create a user named Admin1 that will perform following tasks:

· View BitLocker recovery keys.
· Con gure the usage location for the users in contoso.com.

You need to assign roles to Admin1 to meet the requirements. The solution must use the principle of least privilege.

Which two roles should you assign? To answer, select the appropriate roles in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



HOTSPOT (Drag and Drop is not supported)

You have an Azure AD tenant named contoso.com that contains an enterprise app named App1 and two users named User1 and User2.

You need to ensure that each user can perform the following action:

· User1: Create entitlement management access packages to provide external users with access to App1.
· User2: Create an access review for Appl.

The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft 365 E5 subscription.

You have an Azure AD tenant named contoso.com that contains the following users:

· Admin1
· Admin2
· User1

Contoso.com contains an administrative unit named AU1 that has no role assignments. User1 is a member of AU1.

You create an administrative unit named AU2 that does NOT have any members or role assignments.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Your network contains an on-premises Active Directory domain named contoso.com. The domain contains a Microsoft Exchange Server 2019 organization.

You plan to sync the domain to Azure Active Directory (Azure AD) and to enable device writeback and group writeback.

You need to identify which group types will sync from Azure AD.

Which two group types should you identify? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  1. a Microsoft 365 group that uses the Assigned membership type
  2. a security group that uses the Dynamic Device membership type
  3. a Microsoft 365 group that uses the Dynamic User membership type
  4. a security group that uses the Assigned membership type
  5. a security group that uses the Dynamic User membership type

Answer(s): A,C






Post your Comments and Discuss Microsoft MS-100 exam with other Community members: