MS-500 Exam Question 196

You have a Microsoft 365 subscription. Auditing is enabled.
A user named User1 is a member of a dynamic security group named Group1.
You discover that User1 is no longer a member of Group1.
You need to search the audit log to identify why User1 was removed from Group1.
Which two actions should you use in the search? To answer, select the appropriate activities in the answer area.
NOTE: Each correct selection is worth one point.

MS-500 Exam Question 197

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription that is associated to a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.
You use Active Directory Federation Services (AD FS) to federate on-premises Active Directory and the tenant.
Azure AD Connect has the following settings:
* Source Anchor: objectGUID
* Password Hash Synchronization: Disabled
* Password writeback: Disabled
* Directory extension attribute sync: Disabled
* Azure AD app and attribute filtering: Disabled
* Exchange hybrid deployment: Disabled
* User writeback: Disabled
You need to ensure that you can use leaked credentials detection in Azure AD Identity Protection.
Solution: You modify the Azure AD app and attribute filtering settings.
Does that meet the goal?
  • MS-500 Exam Question 198

    You company has a Microsoft 36S E5 subscription and a hybrid Azure active Directory named contoso.com.
    Contoso.com includes the following users:
    You configure Password protection for Contoso.com as shown in the following exhibit.

    MS-500 Exam Question 199

    How should you configure Group3? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    MS-500 Exam Question 200

    You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

    Youcreate and enforce an Azure AD Identity Protection sign-in risk policy that has the following settings:
    Assignments: Include Group1, Exclude Group2
    Conditions: Sign in risk of Low and above
    Access: Allow access, Require password multi-factor authentication
    You need to identify how the policy affects User1 and User2.
    What occurs when each user signs in from an anonymous IP address? To answer, select the appropriate options in the answer area.
    NOTE:Each correct selection is worth one point.