exam questions

Exam AZ-305 All Questions

View all questions & answers for the AZ-305 exam

Exam AZ-305 topic 5 question 1 discussion

Actual exam question from Microsoft's AZ-305
Question #: 1
Topic #: 5
[All AZ-305 Questions]

HOTSPOT -
You need to ensure that users managing the production environment are registered for Azure MFA and must authenticate by using Azure MFA when they sign in to the Azure portal. The solution must meet the authentication and authorization requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Azure AD Identity Protection
Only users that manage the production environment by using the Azure portal must connect from a hybrid Azure AD-joined device and authenticate by using
Azure Multi-Factor Authentication (MFA).

Note: Policy configuration -
1. Navigate to the Azure portal.
2. Browse to Azure Active Directory > Security > Identity Protection > MFA registration policy.
3. Under Assignments
4. Users - Choose All users or Select individuals and groups if limiting your rollout.
5. Optionally you can choose to exclude users from the policy.
6. Enforce Policy - On
7. Save
Box 2: Grant control in capolicy1
The litware.com tenant has a Conditional Access policy named Capolicy1. Capolicy1 requires that when users manage the Azure subscription for a production environment by using the Azure portal, they must connect from a hybrid Azure AD-joined device.
Note: We need to configure the policy conditions for capolicy1 that prompt for MFA.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-mfa-policy https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Guest
Highly Voted 1 year, 11 months ago
If it helps there seem to be only 3 case studies. All the others have the same case, but different questions Maybe the admins can merge this ? topic 5: Litware topic 6: Contoso topic 7: Fabrikam topic 8: Litware = topic 5 topic 9: Fabrikam = topic 7 topic 10: Contoso ltd = topic 6 topic 11: Fabrikam = topic 7 topic 12: Litware = topic 5 topic 13: Contoso ltd = topic 6 topic 14: Contoso ltd = topic 6 topic 15: Litware = topic 5 topic 16: Fabrikam = topic 7
upvoted 51 times
OPT_001122
1 year, 10 months ago
This is a great help!!!! . i added few more details into it - case study specific details topic 5: Litware-Question #1-Page42 topic 8: Litware-Question #1-Page44 topic 8: Litware-Question #2-Page44 topic 8: Litware-Question #3-Page45 topic 8: Litware-Question #4-Page45 topic 8: Litware-Question #5-Page45 topic 12: Litware-Question #1-Page47 topic 15: Litware-Question #1-Page48 ==================================== Total = 8
upvoted 16 times
OPT_001122
1 year, 10 months ago
Total = 9 topic 5: Litware-Question #2-Page42
upvoted 3 times
comoon
1 year, 9 months ago
what is this, man?
upvoted 4 times
...
...
...
...
Davin0406
Highly Voted 2 years, 1 month ago
Correct. appeared in exam, 10/14/2022. I passed with 946/1000 and there were only 1~2 new questions but others were all from AZ-305 dump.
upvoted 31 times
...
SeMo0o0o0o
Most Recent 2 weeks, 6 days ago
CORRECT
upvoted 1 times
...
Lazylinux
7 months, 1 week ago
Given Answer is correct
upvoted 2 times
...
memo454
1 year, 2 months ago
This Case study was in the Exam. I passed the exam today 17-09-2023 with a score of 906/1000. Four new questions.! The team is easier than AZ-104. A new question of hot spot related to FrontDoor and PIM, to drag the OWASP or Just-in Time. Another question related to subnets and DNS.
upvoted 11 times
...
NotMeAnyWay
1 year, 5 months ago
1. To register the users for Azure MFA, use: a. Azure AD identity Protection. Azure AD Identity Protection is a tool that allows organizations to discover, investigate, and remediate identity-based risks in their environment. It can help you manage the roll-out of Multi-Factor Authentication (MFA) registration by prompting users for registration during risk sign-in attempts. 2. To enforce Azure MFA authentication, configure: a. Grant control in capolicy1. Grant controls are used to enforce additional requirements that a user must meet before they are granted access. You can enforce Azure MFA by setting it as a requirement in the Grant control settings of Capolicy1.
upvoted 7 times
...
steel72
1 year, 8 months ago
The provided answer is correct. First box "Azure AD Identity Protection": https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-mfa-policy Second box "Grant control in capolicy1": 7. Under Access controls > Grant, select Grant access, Require multifactor authentication, and select Select. https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-all-users-mfa#create-a-conditional-access-policy
upvoted 6 times
...
globy118
1 year, 9 months ago
appeared in exam 02/15/2023
upvoted 2 times
...
OPT_001122
1 year, 10 months ago
the given ans is correct
upvoted 1 times
...
Mo22
1 year, 10 months ago
I agree with both selections, the answer is correct to me
upvoted 1 times
...
[Removed]
1 year, 11 months ago
Given answer is correct, 'nuff said.
upvoted 1 times
...
Ghoshy
1 year, 11 months ago
One can define AD Authentication Method Policy which enforces MFA. So, it could be Azure AD Authentication Method Policy and Grant Control. You could navigate to Access Method for the AD by Security-> Manage Section-> Authentication Methods
upvoted 3 times
...
jellybiscuit
2 years, 2 months ago
Identity Protection Grant control Identity protection can create MFA registration policies if you have AD Premium P2. (which is mentioned in the study) https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-mfa-policy https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
upvoted 11 times
...
Neo2c
2 years, 2 months ago
It's security defaults for MFA https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults
upvoted 2 times
Neo2c
2 years, 2 months ago
The Document Says the if we use Conditional acess policy then it doe not make sense to use Security defaults. so it should be the third option which enables the MS authenticator APP for MFA
upvoted 1 times
...
Som_triv
1 year, 2 months ago
You can use security defaults in Microsoft Entra tenants to quickly enable Microsoft Authenticator for all users. The scenario here is only for specific users, so that option is not valid.
upvoted 1 times
...
...
kay000001
2 years, 2 months ago
1: Azure AD Identity Protection 2: Grant control in capolicy1
upvoted 4 times
...
One111
2 years, 3 months ago
First part does not make sens. Identity Protection has nothing to do with hybrid adjoined device or enforcing mfa to resource managers. It can provide risky policies or password protection.
upvoted 2 times
ServerBrain
1 year, 11 months ago
Because Microsoft is notorious for providing irrelevant info to try and throw you off, focus on the buzzwords. By focusing on those buzzwords, the answer should be easier to formulate..
upvoted 1 times
...
jellybiscuit
2 years, 2 months ago
https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-mfa-policy It does if you have Azure AD Premium P2
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...