SC-300 Exam Question 36

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.
You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.
You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.
Solution: You configure pass-through authentication.
Does this meet the goal?
  • SC-300 Exam Question 37

    You have a Microsoft Exchange organization that uses an SMTP' address space of contoso.com.
    Several users use their contoso.com email address for self-service sign up to Azure Active Directory (Azure AD).
    You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.
    You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.
    Which PowerShell cmdlet should you run?
  • SC-300 Exam Question 38

    You have a Microsoft 36S tenant.
    You create a named location named HighRiskCountries that contains a list of high-risk countries.
    You need to limit the amount of time a user can stay authenticated when connecting from a high-risk country.
    What should you configure in a conditional access policy? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-300 Exam Question 39

    You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table.

    Which objects can you add as eligible in Azure Privileged identity Management (PIM) for an Azure AD role?
  • SC-300 Exam Question 40

    You have an Azure Active Directory (Azure AD) tenant.
    You open the risk detections report.
    Which risk detection type is classified as a user risk?