SC-300 Exam Question 11

You configure a new Microsoft 365 tenant to use a default domain name of contoso.com.
You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies.
What should you do first?
  • SC-300 Exam Question 12

    You have an Azure Active Directory (Azure AD) tenant that has the default App registrations settings. The tenant contains the users shown in the following table.

    You purchase two cloud apps named App1 and App2. The global administrator registers App1 in Azure AD.
    You need to identify who can assign users to App1, and who can register App2 in Azure AD.
    What should you identify? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-300 Exam Question 13

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.
    You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.
    You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.
    Solution: You configure password writeback.
    Does this meet the goal?
  • SC-300 Exam Question 14

    Your network contains an Active Directory forest named contoso.com that is linked to an Azure Active Directory (Azure AD) tenant named contoso.com by using Azure AD Connect.
    You need to prevent the synchronization of users who have the extensionAttribute15 attribute set to NoSync.
    What should you do in Azure AD Connect?
  • SC-300 Exam Question 15

    Your company has two divisions named Contoso East and Contoso West. The Microsoft 365 identity architecture tor both divisions is shown in the following exhibit.

    You need to assign users from the Contoso East division access to Microsoft SharePoint Online sites in the Contoso West tenant. The solution must not require additional Microsoft 3G5 licenses.
    What should you do?