AZ-104 · Microsoft Entra users and groups
21 cards
Microsoft Entra Users and External Identities
-
Quick check
A person signs in successfully. What does Microsoft Entra ID build at that point, and what does it decide?
AA user account, which holds the details needed to authenticate the person
The user account already exists before sign-in; it is what makes authentication possible rather than what follows it.
BAn access token, which sets what may be reached and done
Right. After authentication, the access token authorizes the user and sets which resources are available and what can be done with them.
CA directory switch, which moves the session into a different directory
Switching directories changes which directory an administrator is working in; it is not something sign-in produces.
2 / 21
-
Quick check
The accounts you need to edit belong to a different Microsoft Entra directory from the one on screen. What has to happen first?
ASwitch directory: one directory is active at a time
Right. Only one directory is active at a time, so the context has to change before the correct objects can even be listed.
BNothing, because All users lists every directory of the organization at once
All users shows the active directory only, so the accounts of the other directory are simply not in that list.
CSort All users by the User Type column so the other directory appears
User Type separates members from guests inside the current directory and never brings in another directory's accounts.
4 / 21
-
Quick check
Which path creates a cloud user, and which detail belongs on its form?
AGroups, then New group, followed by a membership type
New group creates a group object and its membership rule, which is a different object entirely.
BDeleted users, then Restore user, followed by a confirmation
Restore user brings back an account that was deleted; nothing new is created by that path.
CUsers, then New user and Create new user, followed by a user principal name
Right. Creation begins at Users > New user > Create new user, and the user principal name is the sign-in name entered on the form.
6 / 21
-
Keep your progress in the app
That’s 3 of 10 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
A license assignment fails because a user's usage location does not match where that person actually works. Where is the value corrected?
AOn the user's Properties tab in the admin center
Right. Usage location is an editable user property on the Properties tab, and fixing it lets the license assign correctly next time.
BIn the membership type setting of the group that licenses them
Membership type decides how a group is populated and holds no location value for any individual user.
CIn the Directory + Subscription panel
That panel changes which directory is active and stores nothing about an individual user's location.
8 / 21
-
Quick check
The same change must be applied to eleven accounts in the All users list. How should the administrator begin?
AOpen one user's page and add the other ten there as properties
A user's page manages that individual only, and other accounts cannot be held inside it as properties.
BTick the check boxes of those accounts in the list
Right. The check boxes in the list are the multi-user selection surface, so the command that follows applies to every ticked account.
CSwitch directory once for every account in the operation
Directory switching changes the active directory and is not a way to pick individual accounts.
10 / 21
-
Quick check
An account was created in on-premises Active Directory and reaches Microsoft Entra ID through a synchronization activity. How is it classified, and what source is displayed?
AA guest user, displayed with Invited user
Invited user marks an identity from outside the organization, not an account that originates on-premises.
BA cloud identity, displayed with an External Microsoft Entra directory source
That source belongs to an account defined in another Microsoft Entra instance, which is still a cloud identity.
CA directory-synchronized identity, displayed with Windows Server AD
Right. Origin in on-premises Active Directory makes it a directory-synchronized identity, and the source shown is Windows Server AD.
13 / 21
-
Quick check
A contractor keeps their own account outside your organization, needs your resources for one project, and must lose that access when it ends. What fits?
AA guest user, whose source reads Invited user and whose access ends on removal
Right. Guests are the object type for identities outside the organization, and removing the account removes all of their access.
BA synchronized account brought in from on-premises Active Directory
Synchronization models employees who originate on-premises, which is not the contractor's own external account.
CA cloud administrator account whose usage location is cleared afterwards
An administrator account is a stronger identity than the work needs, and usage location affects licensing rather than access.
15 / 21
-
Quick check
What is true of a user account during the first 30 days after it is deleted?
AIt keeps working normally until the window closes
Deletion suspends the account immediately; the 30 days are a recovery window, not continued service.
BIt is suspended, and it can be restored with all its properties
Right. Within that window the object is suspended and restoration brings it back together with all its properties.
CIt has already been removed for good and must be recreated from scratch
Permanent deletion only begins after the window, so at this stage nothing has been lost yet.
17 / 21
-
Quick check
An account deleted 20 days ago must come back with its original properties, and a replacement account is unacceptable. What should the administrator do?
ABuild a new account carrying the same name
A new object starts empty, so the properties of the original account do not come back with it.
BLet the 30 days pass, then restore the object
Once the window closes the deletion becomes permanent, and a permanently deleted user cannot be restored.
COpen Deleted users, select the account and choose Restore user
Right. At day 20 the account is still suspended, so restoring it from Deleted users recovers the object with all its properties.
19 / 21
-
Quick check
An administrator is viewing directory A and must update several users in directory B without touching similarly named accounts in A. Which sequence meets both constraints?
ASwitch to directory B, open All users, and tick the accounts to change
Right. Directory context has to change first, and the check boxes then limit the operation to the chosen accounts in directory B.
BTick the names in directory A first, and then switch over to directory B
Those ticks belong to directory A's objects and do not carry over when the directory context changes.
CStay in directory A and open one user page to manage both directories
One directory is active at a time, and a single user's page scopes the work to that individual anyway.
21 / 21
-
10 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.