govern-secure-microsoft-365-tenants-workloads
Microsoft 365 AI Services Administrator Associate · 132 questions
- Contoso is onboarding 500 employees from a recently acquired company. The IT admin has a CSV file containing user attributes including Department, Job Title, and Manager, and needs to create all accounts with proper Microsoft 365 license assignments as quickly as possible. Which approach should the admin use?
- Fabrikam's compliance team requires that Global Administrator access only be granted when operationally necessary. The policy mandates that users must provide a business justification, receive manager approval before activation, and have access automatically revoked after 8 hours. What should the admin configure?
- Northwind Traders has regional IT teams in North America, Europe, and Asia-Pacific. Each regional team needs to reset passwords and manage licenses only for users in their own region. No regional admin should be able to affect users in another region. What should the admin configure?
- Adventure Works wants to allow B2B collaboration so partner users can be invited as guests to Teams and SharePoint. However, they need to ensure guest users cannot enumerate other directory members or see other guest accounts in the directory. What should the admin configure?
- Contoso wants all users whose Department attribute is set to 'Sales' in Microsoft Entra ID to be automatically added to a group called 'Sales Team'. The group should include a shared mailbox and a Microsoft Teams workspace, and membership should update automatically when the Department attribute changes. What should the admin create?
- Woodgrove Bank wants to allow employees to reset their own passwords without calling the IT helpdesk. The bank's security policy requires that users verify their identity using two separate authentication methods before a password reset is permitted. The admin wants to enable mobile app notification and email OTP as the available methods. What should the admin configure?
- Alpine Ski House requires MFA for all users when accessing Microsoft 365 services from outside the corporate network. Users connecting from within the office should have a seamless experience without MFA prompts. What should the admin configure?
- Contoso's IT team discovers that many users are setting passwords containing company-specific terms like 'Contoso', 'Corp', and 'HQ2024'. These passwords pass the standard complexity requirements but are weak against targeted attacks. The admin wants to automatically block these terms and common variants. What should the admin configure?
- A user at Fourth Coffee reports that they are unable to sign in to Microsoft 365 and receive an error message. The user's account appears active in the Microsoft 365 admin center. The admin needs to quickly identify the exact failure reason, error code, and which Conditional Access policy (if any) is blocking access. What should the admin do?
- Trey Research wants high-risk user accounts (flagged by Microsoft Entra ID Protection due to leaked credentials or anomalous sign-in behavior) to be automatically remediated by forcing an immediate password change. The security team should not need to manually intervene for each incident. What should the admin configure?
- Contoso's security team requires that all Global Administrators use phishing-resistant authentication methods only. The company has decided to deploy FIDO2 hardware security keys for these accounts. What must the admin configure to enable FIDO2 authentication in Microsoft Entra ID?
- Tailwind Traders has been targeted by spear-phishing attacks where external senders impersonate the company's CEO and CFO to trick employees into taking fraudulent actions. The admin needs to configure Defender for Office 365 to detect and quarantine emails that impersonate these specific executives. What should the admin configure?
- The security operations team at Fabrikam wants to receive an email notification when Microsoft Defender for Office 365 detects that more than 10 users in the organization have received malware-containing emails within a one-hour window, indicating a potential malware campaign. What should the admin configure?
- Multiple users at Woodgrove Bank report receiving phishing emails that appear to have been delivered to their inboxes despite having anti-phishing policies in place. The security admin needs to investigate the delivery action, determine where the emails were delivered, identify how many users received them, and check whether any users clicked links in the emails. What tool should the admin use?
- Contoso needs to ensure that all email attachments are scanned in a sandbox environment before users can open them. However, users must still be able to read the email body immediately — they should not wait for attachment scanning to complete before the message is delivered to their inbox. Which Safe Attachments action should the admin configure?
- The security team at Alpine Ski House wants to test employee susceptibility to credential harvesting phishing attacks. Employees who submit their credentials on the simulated phishing page should automatically be enrolled in a security awareness training course without any manual admin effort. What should the admin configure?
- A user at Northwind Traders clicked a URL in an email and was redirected to a malicious website. The admin suspects Safe Links should have blocked the URL. The admin needs to determine why Safe Links did not block the URL and check whether other users in the organization also clicked the same link. What should the admin do?
- Fabrikam's compliance team needs to prevent credit card numbers from being shared in Microsoft Teams chats and channel messages, including in Microsoft 365 Copilot interactions within Teams. A policy must block users from sending this information and notify them of the policy violation in real time. What should the admin create?
- Contoso is running a confidential merger and acquisition project. Project documents stored in a dedicated SharePoint site must be encrypted so only designated M&A team members can open them — even if a document is accidentally shared externally or downloaded to a personal device. The protection must travel with the document. What should the admin configure?
- A financial services company must comply with regulations requiring all email communications to be retained for a minimum of 7 years and to remain immutable during that period. The requirement applies to all current and future Exchange Online mailboxes. What should the admin configure?
- A DLP alert fires in Microsoft Purview indicating that a Finance department user shared a SharePoint document containing Social Security Numbers with an external email address. Before taking action, the security admin needs to review the matched content, understand which DLP policy was triggered, and determine whether the sharing was potentially authorized. What is the correct first action?
- Woodgrove Bank has deployed Microsoft 365 Copilot to 1,000 users. The compliance team is concerned that users might be accessing sensitive customer financial data through Copilot prompts and that this exposure is not visible to administrators. The team needs a solution to monitor AI interactions involving sensitive data and receive recommendations for improving AI data security posture. What should the admin enable?
- Fabrikam is onboarding 500 new employees simultaneously across three departments. The IT administrator has a CSV file containing each employee's display name, user principal name, department, and job title. The admin wants to create all 500 accounts in Microsoft Entra ID using Microsoft Graph PowerShell. Which approach correctly accomplishes this?
- Woodgrove Bank operates three regional offices: East, West, and Central. Each region has its own IT support team that needs to manage password resets, group memberships, and user account properties — but only for users in their own region. The global IT team wants to ensure that the East IT team cannot accidentally modify a Central region user account. What should the Microsoft Entra administrator configure?
- Alpine Ski House regularly works with external contractors from partner companies. The IT team wants these contractors to access specific Teams channels and SharePoint project sites via B2B collaboration. However, the security team has flagged a concern: they do not want guest users to be able to invite additional external users on their own. The global admin needs to configure this restriction. Which setting should be adjusted?
- Tailwind Toys' security team is hardening their Microsoft 365 environment. They want the Exchange Administrator role to follow a zero-standing-access model: no one should have the role active at all times. When someone needs it, they must submit a business justification and get approved by the security team lead before the role activates. Which configuration in Microsoft Entra Privileged Identity Management (PIM) achieves this?
- Northwind Traders has accumulated over 8,000 Microsoft 365 groups over the past three years. Many are tied to completed projects and appear to be abandoned — no owner activity, no content updates. The IT governance team wants groups to automatically expire and be soft-deleted after 180 days of inactivity, with group owners receiving email notifications at 30, 15, and 1 day before expiration so they can renew active groups. What should the administrator configure?
- Fourth Coffee's IT team has noticed that employees frequently set passwords like 'FourthCoffee2024!' and '4thCoffee#1' — variations of the company name that technically pass complexity rules but are easily guessable. The security team wants to proactively block these company-specific password patterns for all users. What should the admin configure to address this?
- Adventure Works' security team wants to use Microsoft Entra ID Protection's sign-in risk signals to automate their response to risky sign-ins. Their policy is: sign-ins flagged as 'High' risk should be completely blocked, while sign-ins flagged as 'Medium' risk should be allowed if the user completes MFA. What is the correct way to implement this in Microsoft Entra?
- A user at Proseware calls the helpdesk reporting they cannot sign in to Microsoft 365. The error message displayed is 'Your account has been locked.' The admin needs to quickly determine whether the lockout is caused by Microsoft Entra Smart Lockout triggering due to too many failed attempts, or whether an administrator has explicitly disabled the user's account. Where should the admin look first to get this information?
- Bellows College wants to configure Microsoft 365 access so that students signing in from on-campus (a set of known IP ranges) are not prompted for MFA, but students accessing from off-campus must complete MFA. The IT admin needs to implement this without disrupting the growing population of remote learners. What is the correct approach?
- Litware Inc wants to protect email users from malicious attachments without introducing delays in reading emails. Employees must be able to open and read the email body immediately upon arrival, while any attached files are still being scanned in the background. The security team has asked the Microsoft 365 administrator to configure the appropriate Safe Attachments policy action. Which action should the administrator select?
- Trey Research's CEO, Megan Bowen ([email protected]), has been impersonated in phishing emails sent to employees from external addresses. Multiple employees received emails appearing to be from Megan with requests to wire transfer funds. The Microsoft 365 administrator needs to ensure that future emails attempting to impersonate the CEO are automatically quarantined before reaching any employee inbox. What is the most effective configuration?
- Wide World Importers' security operations center received an alert that multiple users clicked a malicious URL embedded in a phishing email. The security administrator needs to identify every user who received this email, determine which users actually clicked the URL, and assess whether any downstream actions occurred. The administrator wants to use a built-in Microsoft Defender for Office 365 tool to investigate. Which tool should be used?
- VanArsdel Ltd's compliance officer wants to give end users limited control over their quarantined emails. Specifically, users should be able to release their own emails quarantined by spam filtering without admin involvement. However, emails quarantined because of phishing or malware detections must require admin approval before any release — end users should only be able to request a release, not perform it themselves. How should the Microsoft 365 administrator configure this?
- Adatum Corp's security team wants to test the phishing awareness of employees in the Finance department only. The simulation should use a credential harvesting technique — presenting a fake login page when the user clicks a link — and any employee who clicks the link should automatically be enrolled in a security awareness training course without any manual intervention by the security team. What is the correct way to set up this simulation in Microsoft 365?
- Fabrikam's security operations team is receiving a high volume of 'Email messages containing malicious URL removed after delivery' alerts triggered by a known-safe internal newsletter sent from [email protected]. The alerts are flooding the security queue and causing alert fatigue, making it harder to identify real threats. The administrator needs to stop false positive alerts from this specific safe sender while ensuring the overall alert policy remains active for all other senders. What should the administrator do?
- Humongous Insurance has deployed Microsoft 365 Copilot across their organization. The compliance team is concerned that employees may enter credit card numbers or Social Security Numbers (SSNs) directly into Copilot prompts, which would violate PCI-DSS and privacy regulations. The compliance administrator needs to prevent this from happening. What is the correct DLP configuration?
- Lucerne Publishing wants all documents uploaded to their 'Legal Contracts' SharePoint site to be automatically labeled with the 'Highly Confidential - Legal' sensitivity label — without requiring any action from users — when those documents contain words like 'CONFIDENTIAL' or 'ATTORNEY-CLIENT'. What should the compliance administrator configure to achieve this?
- Munson's Pickles and Preserves has two retention requirements for Exchange email: (1) ALL Exchange email must be retained for a minimum of 7 years for regulatory compliance, and (2) individual employees must be able to mark specific customer complaint emails to be retained for 10 years. Which combination should the compliance administrator deploy?
- Tailspin Toys' compliance team receives a DLP alert in Microsoft Purview showing that an employee emailed a file containing 15 credit card numbers to an external recipient. The alert status is 'Active.' What are the correct next steps for the compliance officer managing this alert in Microsoft Purview?
- Southridge Video has deployed Microsoft 365 Copilot organization-wide. The CISO wants visibility into what sensitive data Copilot is accessing and summarizing on behalf of users, including which sensitive information types appear in Copilot interactions. The administrator needs to set up a monitoring solution. What should they configure?
- Graphic Design Institute uses an internal employee ID format: the prefix 'GDI-' followed by exactly 6 digits (for example, 'GDI-482931'). The compliance team wants DLP policies to be able to detect these employee IDs when they appear in documents or emails. What is the FIRST step the administrator must complete before the DLP policies can detect this pattern?
- Adventure Works is onboarding 300 hires from a CSV (UPN, displayName, department, jobTitle). Which approach best creates accounts at scale?
- Tailwind Traders requires Exchange Administrator to be eligible only, with manager approval and 4-hour max activation. What should be configured?
- Woodgrove Bank helpdesks in EMEA and APAC must reset passwords only for users in their region. What Entra feature scopes those roles?
- Relecloud allows B2B guests for projects but guests must not invite more guests. What should be restricted?
- Northwind wants all users with department=Finance automatically in a Microsoft 365 group used for Teams and SharePoint. Membership must update when department changes. What should be used?
- Graphic Design Institute enables SSPR and requires two verification methods before reset. Mobile app notification and email are allowed. What configuration meets this?
- Contoso requires MFA when users access Microsoft 365 from outside corporate IP ranges, but not from trusted office IPs. How should this be implemented?
- Users keep choosing passwords containing 'Contoso' and 'HQ2026'. Complexity is on, but terms are guessable. What blocks org-specific terms?
- A user cannot sign in; the account looks enabled. The admin needs the failure reason, error code, and any Conditional Access that blocked the attempt. Where first?
- Trey Research wants high user risk (e.g., leaked credentials) to force password change automatically. What should be configured?
- Global Administrators must use phishing-resistant authentication with FIDO2 security keys. What must the admin enable/configure?
- CEO and CFO display-name impersonation phishing is rising. Which Defender for Office 365 control targets user impersonation?
- SOC wants email when more than 10 users receive malware in one hour. What should be configured?
- Multiple users clicked a malicious URL in email. The analyst must find all recipients and clickers. Which tool?
- Attachments must be detonated in a sandbox, but users must read the email body immediately. Which Safe Attachments action?
- Finance users should get a credential-harvest simulation; clickers auto-enroll in training. What feature?
- A legitimate partner URL is rewritten/blocked by Safe Links. After confirming safety, what should the admin do?
- Block Social Security Numbers in Teams chat/channel messages with a policy tip. What is required?
- M&A documents must remain encrypted so only the M&A group can open them even if emailed externally. What control?
- All Exchange Online mail must be retained 7 years immutably for regulation. What is the broad control?
- A DLP alert shows a finance user shared a file with many credit card numbers externally. What is the correct first admin action in Purview?
- Compliance needs visibility into sensitive data exposure via Copilot interactions and AI data security recommendations. Which capability?
- An admin must create a single cloud user with department and usage location via automation-friendly tooling. Which is preferred on modern tenants?
- PIM role settings should require MFA on activation for Security Administrator. Where is this enforced?
- A school district wants campus IT to manage groups only for users in their campus administrative unit. What is required?
- Partners should lose guest access if no longer needed. Which governance feature periodically re-certifies guest access?
- Unused Microsoft 365 groups should expire after 180 days of inactivity with owner renewal notices. What configures this?
- IT wants to enable Microsoft Authenticator passwordless phone sign-in for users. Which admin plane primarily governs authentication methods availability?
- Baseline: all users must perform MFA when accessing Microsoft 365 cloud apps. Best control?
- Hybrid identity: custom banned passwords should apply to on-prem AD password changes too. What component extends Entra Password Protection on-premises?
- Analysts want to find legacy authentication attempts. Where?
- Medium sign-in risk should require MFA; high sign-in risk should block. How?
- A CA policy must require phishing-resistant MFA for access to a sensitive app. What concept is used?
- Attackers spoof lookalike domains similar to contoso.com. Which policy feature helps?
- Admin wants recommended baseline threat policies for anti-spam, anti-malware, Safe Links, Safe Attachments quickly. What approach is common?
- Analyst confirms a phishing message already delivered. They need to purge it from mailboxes. Which investigation experience supports soft delete/purge actions?
- Users may release their own spam-quarantined messages, but phishing/malware quarantine requires admin release. What configures this?
- Security wants recurring phishing simulations with automatic training for failures across the whole company. What product area?
- A file hash is repeatedly flagged as malware incorrectly for an internal LOB installer. After validation, what can suppress false positives for that file?
- DLP must cover Exchange, SharePoint, OneDrive, Teams, and devices. Which product family provides this unified policy approach?
- Contracts site should auto-apply Highly Confidential when documents match keywords. What is needed?
- All mail retained 7 years; specific complaint emails retained 10 years by user-applied label. What combination?
- After confirming a DLP alert is a false positive, what should the analyst do in the alert workflow?
- DSPM for AI shows recommendations to fix risky AI data exposure. What should admins do next?
- Org employee IDs look like 'ACME-######'. DLP must detect them. First step?
- After bulk-creating users, admin must assign Microsoft 365 E3 via automation. Which approach fits modern practice?
- Privileged role assignments should be re-certified quarterly. Which feature?
- Administrative unit membership for 'EU-Users' should auto-include users with usageLocation=EU. What helps?
- B2B guests should only come from partnera.com and partnerb.com. What configuration direction?
- Dynamic security group for department=Engineering should drive E5 licenses. What two pieces?
- Many users never registered SSPR methods. How can admin drive registration?
- Org must block legacy authentication protocols for Microsoft 365. Best control?
- Admin enables custom banned passwords in audit mode first. Purpose?
- A CA policy did not apply to a sign-in as expected. Where to see 'not applied' reasons?
- For high user risk, access should be blocked until admin remediates. Policy type?
- Besides FIDO2, which method class is commonly treated as phishing-resistant for privileged access scenarios?
- Anti-phishing policy can use mailbox intelligence to better detect impersonation. What is the value?
- SOC wants alerts when phishing messages are removed after delivery (ZAP-style events) at high volume. What configures notifications?
- Analyst needs to pivot from one bad subject line to all related messages in a campaign. Best tool?
- For a high-security business unit, attachments detected as malicious must never be delivered. Which Safe Attachments action fits best?
- Simulation should target only the Finance Entra group. How?
- Safe Links should rewrite URLs in email and Teams. What must be true?
- DLP must prevent credit card numbers in Exchange email and SharePoint/OneDrive files, and Teams chat. How many products?
- Label 'Confidential' should prevent external users from opening encrypted docs. What label setting area?
- Users must manually apply a 'Regulatory-10Y' retention label in Outlook. What is required after creating the label?
- Compliance officers should receive email when high-severity DLP alerts fire. Where is this commonly configured?
- DSPM for AI highlights sites contributing most to AI oversharing risk. Admin next step?
- External partner SMTP addresses should appear in the shared address book without full guest user objects. What object type is commonly used?
- Security wants email when someone activates Global Administrator via PIM. What provides this?
- Helpdesk needs password reset without user admin for all properties tenant-wide. Best role design?
- Guest accounts inactive for 90 days should be reviewed/removed. Which capabilities help?
- All Microsoft 365 groups must be prefixed with 'GRP-'. What configures this?
- New hires need a time-limited bootstrap credential to register passwordless methods. Which method?
- Access to Microsoft 365 from iOS/Android must require approved app protection / compliant devices per policy design. What engine enforces?
- User locked due to repeated bad passwords. Where to confirm Smart Lockout vs admin disable?
- Before enforcing a new sign-in risk CA policy, admin should evaluate impact. How?
- Windows Hello for Business can contribute to phishing-resistant auth postures for Windows users. How does it fit admin strategy?
- Spoof intelligence shows a partner domain spoofing that is actually legitimate bulk mail. Admin action?
- SOC wants a high-level view of email threat campaigns affecting the tenant. Where?
- A message was clean at delivery then later classified malicious. What technology can remove it retroactively?
- User requests release of a quarantined phishing message. Policy forbids end-user release. Who releases if business-justified?
- After a simulation, CISO wants compromise rate and training completion. Where?
- A malicious URL should be blocked tenant-wide even if not yet in global intel. Action?
- DLP should educate users with policy tips rather than hard block for first rollout of a new rule. What action type?
- Sensitivity labels should be visible only to Legal and Finance first. How?
- Retention should apply only to users in the HR department dynamically. What helps target?
- Endpoint DLP locations are selected but devices show no activity. What prerequisite is commonly missing?
- Executives want a posture-oriented view of AI data security risk trends over time. Which solution area?
- DLP must detect a list of internal project codenames. What SIT approach?