AZ-104 · Microsoft Entra users and groups
26 cards
Microsoft Entra Licenses and SSPR
-
Quick check
Where does an administrator assign a product license, whether to one user or to a group?
AIn the Microsoft Entra admin center, under Users and Deleted users
That page lists accounts deleted less than 30 days ago and holds no license assignment.
BIn the Microsoft 365 admin center, on the Billing and Licenses page
Right. Billing > Licenses in the Microsoft 365 admin center handles both individual and group assignments.
CIn the Microsoft Entra admin center, under Password reset and Properties
That blade configures self-service password reset and has nothing to do with product licensing.
2 / 26
-
Quick check
A licensed security group gains a new member and loses another on the same day. What happens to their licenses?
ABoth keep whatever they had until an administrator revisits the assignment
Following the roster without administrator action is precisely what group-based licensing provides.
BThe new member gets the group licenses and the leaver loses what it granted
Right. Membership drives the assignment: joining grants the group licenses and leaving removes what the group provided.
CBoth accounts have to be assigned directly, because a group cannot carry licenses
One or more product licenses can be assigned to a security group, which then applies them to its members.
4 / 26
-
Quick check
A department's licenses must follow its membership automatically, and one service plan must stay switched off until launch. What meets both requirements?
AAssign the product to the security group and disable that plan there
Right. Group-based licensing tracks joiners and leavers, and selected service plans can be disabled inside the group's product assignment.
BAssign the product directly to every current member and leave the plan enabled
Direct assignment does not follow membership changes, and leaving the plan enabled ignores the launch requirement.
CAssign the product to the group's owner and let the members inherit it from there
Members do not inherit anything from an owner's own license; ownership governs the group rather than licensing it.
6 / 26
-
Keep your progress in the app
That’s 3 of 11 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
The same product license reaches a user directly and through two licensed groups. How many licenses does that user consume?
AThree, one for each route the license arrives by
Assignments are not counted one by one; the same license arriving several times is still a single license for that user.
BTwo, because the direct assignment is counted separately
A direct assignment is not consumed separately from a group-derived one for the same product.
COne, because overlapping assignments are combined
Right. The same license reaching a user from several groups or from both routes is consumed only once.
8 / 26
-
Quick check
A user has no usage location when a licensed group assigns a product. Which location is used?
AThe location of the group's owner
An owner governs the group; their own location is not applied to the members being licensed.
BThe location of the directory
Right. For group assignment, a user without a usage location inherits the directory's location.
CThe location of the last sign-in
Sign-in location is not a licensing property, and licensing does not read it.
11 / 26
-
Quick check
Which situation is the one SSPR is designed for?
AA signed-in user who simply wants to choose a new password
Any user who is signed in can change their password without this feature.
BA signed-out user whose password has been forgotten or expired
Right. SSPR lets a user who is not signed in reset a forgotten or expired password from a browser or a Windows sign-in screen.
CAn administrator who needs to unlock a resource for a colleague
SSPR is about a user recovering their own password, not about granting access to a resource.
13 / 26
-
Quick check
Which value does the Self-service password reset enabled property start on, and which one limits the feature to a single security group?
AIt starts on None, and Selected limits it to one specified security group
Right. None is the default, and Selected enables SSPR only for the members of the specified security group.
BIt starts on Selected, and None is what restricts it to a single security group
Selected is a choice an administrator makes, and None means no user in the organization can use SSPR.
CIt starts on All, and Registration limits it to one specified security group
All enables SSPR for everyone, and Registration is where sign-up and reconfirmation are configured, not a scope.
15 / 26
-
Quick check
How does SSPR authentication work for an account that holds an administrator role?
AIt follows the one-method setting and may use security questions
The configured minimum applies to other users; an administrator account is held to the stronger policy regardless.
BIt skips verification when the password has already expired
Verification is never skipped — an expired password is exactly when impersonation would be attempted.
CIt always requires two methods, and security questions are unavailable
Right. A strong two-method policy always applies to administrator accounts, and the security-question method is not available to them.
18 / 26
-
Quick check
Which setting alerts the wider administrative team when one administrator resets a password?
ANotify all admins when other admins reset their password
Right. That option notifies every administrator when another administrator resets their password.
BNotify users on password resets at their primary email addresses
That option informs the person whose own password was reset, at their primary and secondary email addresses.
CRequire users to reconfirm their authentication information
Reconfirmation is a registration setting that keeps method details current; it notifies nobody about a reset.
20 / 26
-
Quick check
A hybrid organization needs password writeback for an existing on-premises domain and for a disconnected domain gained in a merger, with both populations working during the deployment. What fits?
AUse cloud sync for the merged domain and turn writeback off for the existing one
Turning writeback off would leave one population unable to write cloud password changes back on-premises.
BUse one mandatory Microsoft Entra Connect instance to cover both domains together
A disconnected domain is the case the second option exists for; a single instance is not required to serve both.
CUse Microsoft Entra Connect in one domain and cloud sync in the other, side by side
Right. The two writeback options can be deployed side by side in different domains to target different sets of users.
23 / 26
-
Quick check
SSPR is being piloted with one security group that includes an administrator, who must present two proofs and must not use security questions. Which configuration is valid?
AScope All, with the administrator using one security question and one email method
Scope All would end the pilot, and security questions are never available to an administrator account.
BScope Selected for that group, with the administrator using two methods that are not security questions
Right. Selected delivers the group pilot, while the administrator policy independently enforces two methods and excludes security questions.
CScope None, with the administrator relying on the administrator policy to bypass the scope
None means nobody can use SSPR; the administrator policy strengthens verification but does not grant access past the scope.
26 / 26
-
11 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.