HOTSPOT (Drag and Drop is not supported) You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.For which users can you configure the Job title property and the Usage location property in Azure AD? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.Hot Area:
Answer(s): A
Box 1: User1 and User2 only.You can add or update a user's profile information using Azure Active Directory.Add user profile information, including a profile picture, job-specific information, and some settings using Azure Active Directory (Azure AD).The user profile includes:Job info. Add any job-related information, such as the user's job title, department, or manager.Box 2: User1, User2, and User3 Invite users with Azure Active Directory B2B collaboration, Update user's name and usage location.To assign a license, the invited user's Usage location must be specified. Admins can update the invited user's profile on the Azure portal.1. Go to Azure Active Directory > Users and groups > All users. If you don't see the newly created user, refresh the page.2. Click on the invited user, and then click Profile.3. Update First name, Last name, and Usage location.4. Click Save, and then close the Profile blade.
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-profile-azure-portal https://docs.microsoft.com/en-us/power-platform/admin/invite-users-azure-active-directory-b2b-collaboration#update-users-name-and-usage-location
You have an Azure Active Directory (Azure AD) tenant that: contains a user named User1.You need to ensure that User1 can create new catalogs and add1 resources to the catalogs they own.What should you do?
Answer(s): C
Create and manage a catalog of resources in Azure AD entitlement management.Create a catalog.A catalog is a container of resources and access packages. You create a catalog when you want to group related resources and access packages. A user who has been delegated the catalog creator role can create a catalog for resources that they own. Whoever creates the catalog becomes the first catalog owner. A catalog owner can add more users, groups of users, or application service principals as catalog owners.Prerequisite roles: Global administrator, Identity Governance administrator, User administrator, or Catalog creator.Incorrect:* Groups Administrator - Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.* Service Support AdministratorUsers with this role can create and manage support requests with Microsoft for Azure and Microsoft 365 services, and view the service dashboard and message center in the Azure portal and Microsoft 365 admin center.
https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-catalog-create https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant.Users sign in to computers that run Windows 10 and are joined to the domain.You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).You need to configure the Windows 10 computers to support Azure AD Seamless SSO.What should you do?
Enable Seamless SSO through Azure AD Connect.At the User sign-in page, select the Enable single sign on option.Note:The option will be available for selection only if the Sign On method is Password Hash Synchronization or Pass-through Authentication.Seamless SSO can be combined with either the Password Hash Synchronization or Pass-through Authentication sign-in methods.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
Your company has two divisions named Contoso East and Contoso West. The Microsoft 365 identity architecture for both divisions is shown in the following exhibit.You need to assign users from the Contoso East division access to Microsoft SharePoint Online sites in the Contoso West tenant. The solution must not require additional Microsoft 365 licenses.What should you do?
Answer(s): B
Before any of your users can grant SharePoint Online team site access to external guests, you will have to enable guest sharing from within Azure ActiveDirectory.
https://redmondmag.com/articles/2020/03/11/guest-access-sharepoint-online-team-sites.aspx https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/multi-tenant-common-considerations
DRAG DROP (Drag and Drop is not supported)You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.You need to ensure that User1 can create access reviews for groups, and that User2 can review the history report for all the completed access reviews. The solution must use the principle of least privilege.Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.NOTE: Each correct selection is worth one point.
HOTSPOT (Drag and Drop is not supported)You have an Azure subscription.You need to create two custom roles named Role1 and Role2. The solution must meet the following requirements:• Users that are assigned Role1 can create or delete instances of Azure Container Apps.• Users that are assigned Role2 can enforce adaptive network hardening rules.Which resource provider permissions are required for each role? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
HOTSPOT (Drag and Drop is not supported)You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team.You need to ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives. The solution must use the principle of least privilege.Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.You have an administrative unit named Au1. Group1, User2, and User3 are members of Au1.User5 is assigned the User administrator role for Au1.For which users can User5 reset passwords?
Answer(s): D
Share your comments for Microsoft SC-300 exam with other users:
very helpfull
relevant questions