Prev Next

Java / Microsoft Entra ID Interview questions

Last updated

1. What is Microsoft Entra ID? 2. What is a tenant in Microsoft Entra ID? 3. What are the Microsoft Entra ID license tiers? 4. What are the types of groups in Microsoft Entra ID? 5. What is multifactor authentication in Microsoft Entra ID? 6. What is self-service password reset in Microsoft Entra ID? 7. What are security defaults in Microsoft Entra ID? 8. What is Conditional Access in Microsoft Entra ID? 9. What is an app registration in Microsoft Entra ID? 10. What is an enterprise application in Microsoft Entra ID? 11. What is a service principal in Microsoft Entra ID? 12. What is a managed identity in Microsoft Entra ID? 13. What are the types of managed identities? 14. What is role-based access control in Microsoft Entra ID? 15. What are administrative units in Microsoft Entra ID? 16. What is Microsoft Entra Connect? 17. What is Microsoft Entra B2B collaboration? 18. What are the device identity types in Microsoft Entra ID? 19. What is Privileged Identity Management in Microsoft Entra ID? 20. What is Microsoft Entra ID Protection? 21. What are Microsoft Entra sign-in logs and audit logs? 22. What is Microsoft Entra External ID? 23. How do you manage Microsoft Entra ID with Microsoft Graph? 24. What is the difference between Entra ID and Active Directory Domain Services? 25. What is the difference between single-tenant and multitenant apps? 26. What is the difference between Entra ID and Microsoft Entra Domain Services? 27. What is the difference between Entra roles and Azure RBAC? 28. How does password hash synchronization work? 29. Which is better: PHS, PTA, or federation? 30. When would you choose Cloud Sync over Connect Sync? 31. How does Conditional Access evaluate multiple policies? 32. How do you roll out Conditional Access safely? 33. Why should you create emergency access accounts? 34. Explain the OAuth 2.0 authorization code flow in Entra ID? 35. What is the difference between OpenID Connect and SAML? 36. What is the difference between ID, access, and refresh tokens? 37. How does the Primary Refresh Token work? 38. How does Continuous Access Evaluation work? 39. How do authentication strengths work in Conditional Access? 40. Why are passkeys considered phishing-resistant? 41. Explain how PIM role activation works? 42. How do access reviews work in Microsoft Entra ID? 43. How does entitlement management work in Microsoft Entra ID? 44. What is the difference between delegated and application permissions? 45. When is admin consent required in Microsoft Entra ID? 46. How do you secure workload identities in Microsoft Entra ID? 47. How do cross-tenant access settings work? 48. How do you troubleshoot a failed Microsoft Entra ID sign-in? 49. How can you monitor Entra ID with Log Analytics? 50. How do you design a least-privilege Entra ID tenant?

1. What is Microsoft Entra ID?

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. It authenticates users, devices, and applications, then decides what each of them is allowed to reach.

It is the identity layer behind Microsoft 365, Azure, and thousands of third-party SaaS apps. Sign-ins happen over HTTPS using modern protocols such as OAuth 2.0, OpenID Connect, and SAML, not Kerberos or LDAP.

Core capabilities include single sign-on, multifactor authentication, Conditional Access, application management, and device identity. Microsoft renamed Azure AD to Entra ID in 2023; the service and its APIs kept working as before.

Take quiz
Microsoft Entra ID was previously known as:
Azure Directory Services
Windows Server Active Directory
Azure Active Directory
Which protocols does Entra ID mainly use to sign users in to apps?
OAuth 2.0, OpenID Connect, and SAML
Kerberos and LDAP only
FTP and SMTP

2. What is a tenant in Microsoft Entra ID?

A tenant is a dedicated, isolated instance of Microsoft Entra ID that an organization receives when it signs up for a Microsoft cloud service such as Microsoft 365 or Azure. It holds the organization's users, groups, devices, app registrations, and policies.

Every tenant has a unique tenant ID (a GUID) and an initial domain such as contoso.onmicrosoft.com. You can add verified custom domains like contoso.com so users sign in with familiar names.

A tenant is a security boundary. Admins of one tenant cannot manage another tenant's objects unless access is explicitly granted, for example through B2B guests. One Azure subscription trusts exactly one tenant, but a tenant can hold many subscriptions.

Take quiz
What uniquely identifies a tenant?
A tenant ID (GUID)
The subscription display name
The Global Administrator's email address
How many Entra tenants can one Azure subscription trust?
Any number at the same time
Exactly one
None, subscriptions are independent of tenants

3. What are the Microsoft Entra ID license tiers?

Entra ID is sold in a few tiers, and each one builds on the previous. Packaging changes from time to time, so confirm details on Microsoft's licensing page before purchasing.

Tier What it adds
Free Users, groups, SSO to SaaS apps, basic reports, MFA through security defaults
P1 Conditional Access, dynamic groups, SSPR with writeback, Application Proxy, hybrid identity features
P2 Everything in P1 plus ID Protection and Privileged Identity Management
ID Governance Add-on for access reviews, entitlement management, and lifecycle workflows

Take quiz
Which tier first includes Conditional Access?
Entra ID Free
Entra ID P1
Only ID Governance
Privileged Identity Management and ID Protection are part of:
Entra ID Free
Entra ID P1
Entra ID P2

4. What are the types of groups in Microsoft Entra ID?

Entra ID has two group types. Security groups control access to resources and can hold users, devices, service principals, and other groups. Microsoft 365 groups are for collaboration and come with a shared mailbox, calendar, and SharePoint site or Teams team; they can include guests.

Membership can be Assigned (manual), Dynamic User, or Dynamic Device. Dynamic membership is rule-based and needs P1. A typical rule looks like this:

(user.department -eq "Finance") and (user.accountEnabled -eq true)

Groups created with isAssignableToRole can be given Entra admin roles. They must use assigned membership, and lower-privileged admins cannot modify them.

Take quiz
Which membership type needs a rule and an Entra ID P1 license?
Assigned membership
Guest-only membership
Dynamic membership
A role-assignable group must use:
Assigned membership, not dynamic
Dynamic user membership
Any membership type

5. What is multifactor authentication in Microsoft Entra ID?

Multifactor authentication (MFA) requires a user to prove identity with at least two of three factor types: something they know (a password), something they have (a phone or security key), or something they are (a biometric).

Entra ID supports Microsoft Authenticator, passkeys and FIDO2 security keys, Windows Hello for Business, certificate-based authentication, OATH tokens, SMS, and voice. Passwordless methods are stronger than SMS or voice, which are open to SIM swapping and interception.

You can enforce MFA with security defaults, legacy per-user settings, or, preferably, Conditional Access, which asks for it only when risk or context calls for it. Users register methods once through a combined registration page shared with SSPR.

Take quiz
Which method is generally considered the weakest for MFA?
SMS text message
FIDO2 security key
Windows Hello for Business
What is the recommended way to enforce MFA selectively?
Requiring longer passwords for everyone
A Conditional Access policy
Turning off sign-in logs

6. What is self-service password reset in Microsoft Entra ID?

Self-service password reset (SSPR) lets users reset or change their own password without calling the helpdesk. They first verify identity with registered methods such as the Authenticator app, phone, or email.

You can enable SSPR for everyone or for a pilot group. For hybrid users, enabling password writeback in Microsoft Entra Connect pushes the new password back to on-premises Active Directory. Writeback needs P1 or higher.

Registration is shared with MFA through the combined security info experience, so users enroll once for both. Resets and registrations are recorded in the audit logs and authentication methods reports.

Take quiz
What does password writeback do?
Copies on-premises passwords to Microsoft in plain text
Sends cloud password resets back to on-premises AD
Rewrites the user's UPN suffix
SSPR registration is shared with:
Group-based licensing
Application Proxy connectors
MFA, through combined security info registration

7. What are security defaults in Microsoft Entra ID?

Security defaults are a free, preconfigured set of identity protections for tenants that don't use Conditional Access. New tenants have them switched on by default.

  • All users must register for MFA (within 14 days).
  • Administrators must use MFA.
  • Legacy authentication protocols are blocked.
  • MFA is required for privileged actions such as Azure management.

They are all-or-nothing: you can't exclude accounts or tune individual rules, and you can't run them alongside Conditional Access. Once you need exclusions, location logic, or device conditions, disable them and build Conditional Access policies (P1).

Take quiz
What happens to legacy authentication under security defaults?
It is required for administrators
It is allowed from trusted IPs only
It is blocked
When should you replace security defaults?
When you need granular Conditional Access policies
When the tenant has fewer than 10 users
Never, they cannot be disabled

8. What is Conditional Access in Microsoft Entra ID?

Conditional Access is Entra ID's policy engine, best understood as if-then rules: if a sign-in matches certain signals, then apply an access decision. It is the main enforcement point for Zero Trust and requires Entra ID P1.

Part Examples
Signals User or group, target app, device platform and state, location, client app, sign-in risk, user risk
Grant controls Block, require MFA, require compliant device, require authentication strength, require password change, terms of use
Session controls Sign-in frequency, persistent browser session, app-enforced restrictions, token protection

Policies are enforced after first-factor authentication succeeds. A sensible start is the template that requires MFA for admins, plus a policy that blocks legacy authentication.

Take quiz
Conditional Access policies are enforced:
After first-factor authentication succeeds
Before the user enters a username
Only on the on-premises domain controller
Which of these is a session control?
Block access
Sign-in frequency
Require MFA

9. What is an app registration in Microsoft Entra ID?

An app registration is how you tell Entra ID about an application you build so it can use the identity platform. It creates an application object in the app's home tenant, which is the global definition of the app.

It stores the Application (client) ID, redirect URIs, supported account types, credentials (client secrets, certificates, or federated credentials), exposed API scopes, app roles, and requested API permissions.

Registering is a developer task and doesn't give anyone access by itself. When the app is used in a tenant, a matching service principal, shown as an enterprise application, is created there.

Take quiz
Which value identifies the app during sign-in?
Tenant domain name
Application (client) ID
Redirect URI
What does an app registration alone do?
Assigns all users to the app automatically
Creates a managed identity
Defines the app but grants no user access

10. What is an enterprise application in Microsoft Entra ID?

An enterprise application is the tenant-local representation of an app, technically its service principal. It exists for gallery apps such as Salesforce, for apps you registered yourself, and for Microsoft's own first-party apps.

This is where admins control how the app behaves in their tenant: configure single sign-on (SAML, OIDC, password-based, linked), assign users and groups, require assignment, set up SCIM provisioning, review consent, and check sign-in activity.

Think of the app registration as the blueprint and the enterprise application as the instance running in your directory.

Take quiz
Where do you assign users to an app and configure its SSO?
Access reviews
Entra Connect Health
Enterprise applications
An enterprise application is technically a:
Service principal
Dynamic group
Conditional Access policy

11. What is a service principal in Microsoft Entra ID?

A service principal is the security identity an application or automation uses inside a tenant. A user account is a person's identity; a service principal is the app's identity. It signs in, holds role assignments, and receives permissions.

There are three kinds: application (created from an app registration), managed identity, and legacy. One is created automatically when you register an app, consent to a multitenant app, or enable a managed identity.

Because permissions are granted to the service principal, both Azure RBAC and Entra roles can target it directly. A common CLI example for a deployment pipeline:

az ad sp create-for-rbac --name "deploy-sp" --role Reader --scopes /subscriptions/<sub-id>

Take quiz
A service principal represents:
An application's identity in a tenant
A physical security key
A group of administrators
Which are the service principal types?
User, guest, and device
Application, managed identity, and legacy
Primary, secondary, and tertiary

12. What is a managed identity in Microsoft Entra ID?

A managed identity gives an Azure resource (a VM, App Service, Function, Logic App, or AKS workload) an Entra identity whose credentials Azure creates, stores, and rotates. Your code never handles a secret.

The code requests a token from the local Instance Metadata Service or the App Service identity endpoint, then presents it to services that support Entra authentication, such as Key Vault, Storage, or SQL Database.

var credential = new DefaultAzureCredential();
var client = new SecretClient(new Uri("https://myvault.vault.azure.net/"), credential);

This removes connection strings and client secrets that tend to leak into repositories, which is why it is the preferred way for Azure-hosted workloads to authenticate.

Take quiz
Who rotates a managed identity's credentials?
The developer, every 90 days
Azure, automatically
The Global Administrator, manually
Managed identities help you avoid:
Using Azure RBAC
Registering a tenant
Storing secrets in code or configuration

13. What are the types of managed identities?

Azure offers two types of managed identity, and the choice mostly comes down to lifecycle and sharing.

Aspect System-assigned User-assigned
Lifecycle Tied to the resource and deleted with it Standalone Azure resource with its own lifecycle
Sharing One resource only Can be attached to many resources
Creation Switched on in the resource's settings Created first, then assigned
Best for Simple single-resource workloads Shared access, pre-provisioned roles, frequently recreated resources

User-assigned identities let you grant RBAC roles once and reuse them across resources, which also avoids waiting on role propagation each time a resource is rebuilt.

Take quiz
Which identity is deleted automatically with its resource?
User-assigned
Neither, both always remain
System-assigned
Best choice when many VMs need identical access?
One user-assigned managed identity shared by all
A distinct shared password stored in each VM
A guest user account

14. What is role-based access control in Microsoft Entra ID?

Entra role-based access control gives administrators only the directory permissions their job needs. A role assignment combines three things: a security principal (user, group, or service principal), a role definition, and a scope.

There are many built-in roles, for example User Administrator, Helpdesk Administrator, Security Reader, Application Administrator, and Global Administrator. With P1 you can also create custom roles from specific permissions.

Scope can be the whole tenant, an administrative unit, or a single object such as one app registration. Prefer narrow roles over Global Administrator, and keep that role to a handful of accounts.

Take quiz
Which three items form a role assignment?
Principal, role definition, and scope
Domain, license, and password
Tenant, subscription, and resource group
What is the best practice for admin roles?
Make every admin a Global Administrator
Assign the least-privileged role that fits the task
Share one admin account across the team

15. What are administrative units in Microsoft Entra ID?

An administrative unit (AU) is a container that limits where a role applies. Instead of making someone Helpdesk Administrator for the whole tenant, you scope the role to an AU that holds, for instance, only one regional office's users and devices.

AUs can contain users, groups, and devices, with assigned or dynamic membership (P1). Roles that work at AU scope include User Administrator, Groups Administrator, Helpdesk Administrator, and Authentication Administrator.

A restricted management administrative unit goes further: objects inside can only be modified by admins assigned within that AU, so even tenant-wide User Administrators can't touch them. That protects executive accounts or sensitive groups.

Take quiz
What do administrative units do?
Replace Azure management groups
Scope admin roles to a subset of directory objects
Store application secrets
A restricted management AU blocks changes from:
Guest users only
Anyone who has completed MFA
Admins not assigned within that AU, even tenant-wide ones

16. What is Microsoft Entra Connect?

Microsoft Entra Connect is the on-premises tool that links Active Directory Domain Services to Entra ID so users have one identity in both worlds. It is the foundation of hybrid identity.

  • Synchronization of users, groups, and contacts, with a default delta cycle every 30 minutes.
  • Sign-in method choice: password hash sync, pass-through authentication, or federation with AD FS.
  • Writeback options such as password, device, and group writeback.
  • Entra Connect Health for monitoring.

It runs on a domain-joined Windows Server, and a second server can sit in staging mode as a standby. Filtering by domain, OU, or attribute decides which objects sync.

Take quiz
How often does the default delta sync cycle run?
Every 24 hours
Only when an admin triggers it
Every 30 minutes
What does staging mode provide?
A passive standby server ready to take over
A test tenant with no sync
Faster password hashing

17. What is Microsoft Entra B2B collaboration?

B2B collaboration lets you invite external people, such as partners, vendors, or contractors, as guest users in your tenant. Guests sign in with their own identity (their work account, a Microsoft account, Google, or an email one-time passcode) while you control what they can reach.

The flow is simple: an admin or permitted user sends an invitation, the guest redeems it, and a guest object with userType = Guest appears in your directory. You then add them to groups, apps, or Teams.

You manage risk with guest access restrictions, Conditional Access, cross-tenant access settings, and access reviews that remove stale guests. You never manage the guest's password; their home identity provider does.

Take quiz
Where does a B2B guest authenticate?
With their own home identity provider
Using a password stored by your admins
Only through your on-premises AD FS
Which attribute marks a B2B guest?
accountEnabled = false
userType = Guest
usageLocation = Guest

18. What are the device identity types in Microsoft Entra ID?

A device can relate to Entra ID in three ways, depending on who owns it and where it is managed.

Type Typical device Sign-in account
Entra registered Personal (BYOD) Windows, macOS, iOS, Android Local or personal account, work account added
Entra joined Organization-owned Windows 10/11, cloud-only Entra ID work account
Entra hybrid joined Windows devices joined to on-premises AD AD account, also registered in Entra ID

Joined and hybrid joined devices can be managed with Intune, and compliance state can then be required in Conditional Access.

Take quiz
A personal phone used for work email is usually:
Entra joined
Entra registered
Hybrid joined
Hybrid joined devices are joined to:
Only Entra ID with no AD
Entra Domain Services only
On-premises AD and registered in Entra ID

19. What is Privileged Identity Management in Microsoft Entra ID?

Privileged Identity Management (PIM) provides just-in-time, time-bound, and approval-based activation of privileged roles so admins don't hold standing access. It covers Entra roles, Azure resource roles, and PIM for Groups, and needs Entra ID P2 or Governance.

Users are made eligible for a role. When they need it, they activate it, possibly with MFA, a justification, a ticket number, and approval. The role is removed automatically when the window ends, for example after 8 hours.

PIM also raises alerts on risky patterns, keeps an audit history of every activation, and supports access reviews of privileged roles. The goal is to shrink the number of permanent Global Administrators.

Take quiz
In PIM, an eligible assignment means:
The role is active permanently
The role is blocked for the user
The user must activate the role before using it
PIM mainly reduces risk from:
Standing privileged access
Expired TLS certificates
Slow sync cycles

20. What is Microsoft Entra ID Protection?

Microsoft Entra ID Protection detects identity risk using Microsoft's signals and machine learning, then lets you respond automatically. It tracks two kinds of risk: sign-in risk (this attempt looks suspicious) and user risk (this account may be compromised).

Detections include leaked credentials, anonymous IP addresses, atypical travel, unfamiliar sign-in properties, password spray, and anomalous token activity. Risk is rated low, medium, or high.

You respond with risk-based Conditional Access: require MFA at medium sign-in risk, force a secure password change at high user risk. Admins review the Risky users and Risky sign-ins reports. Full capabilities need P2.

Take quiz
Which risk type suggests the account itself may be compromised?
User risk
Domain risk
Subscription risk
A typical automated response to high user risk is to:
Disable Conditional Access
Require a secure password change
Convert the user to a guest

21. What are Microsoft Entra sign-in logs and audit logs?

Sign-in logs record every authentication: who, which app, from where, on which device, whether Conditional Access applied, and the result code. Audit logs record directory changes such as user creation, role assignments, policy edits, and consent grants. Provisioning logs cover sync activity.

Sign-in logs are split into interactive user, non-interactive user, service principal, and managed identity sign-ins. Portal retention is 7 days for Free and 30 days for P1 and P2.

For longer retention or analysis, route them with diagnostic settings to Log Analytics, a storage account, or Event Hubs.

Take quiz
Which log shows a role assignment change?
Interactive sign-in report
Audit logs
Device compliance report
How do you keep logs beyond the portal retention period?
Disable Conditional Access
Switch the tenant to the Free tier
Export them through diagnostic settings

22. What is Microsoft Entra External ID?

Microsoft Entra External ID is Microsoft's unified platform for external identities. It covers partner scenarios (B2B collaboration) and customer-facing scenarios (CIAM) using a dedicated external tenant.

In an external tenant you build sign-up and sign-in flows for consumer apps using email and password, one-time passcode, or social providers such as Google and Facebook, with your own branding. It is meant to succeed Azure AD B2C, which is no longer sold to new customers while existing B2C tenants remain supported.

Pick B2B collaboration to give partners access to your internal resources, and an external tenant to authenticate your customers into your own app.

Take quiz
Which scenario suits an external tenant?
Giving employees access to payroll
Joining laptops to a domain
Customer sign-up for your public app
External ID is positioned as the successor to:
Azure AD B2C
Azure Key Vault
Active Directory Federation Services

23. How do you manage Microsoft Entra ID with Microsoft Graph?

Entra ID is managed programmatically through Microsoft Graph, the unified REST API for Microsoft 365 and Entra data. The older Azure AD Graph API and the AzureAD and MSOnline PowerShell modules are deprecated or retired, so new automation should use Graph.

Connect-MgGraph -Scopes "User.Read.All"
Get-MgUser -Filter "department eq 'Finance'" -Property DisplayName,UserPrincipalName

The same query over REST is GET https://graph.microsoft.com/v1.0/users?$filter=department eq 'Finance'.

Graph uses OAuth, so a script needs either delegated permissions (a signed-in admin) or application permissions (an app identity). Request only the scopes you need.

Take quiz
Which API replaces Azure AD Graph?
Microsoft Graph
Azure Resource Manager API
Exchange Web Services
What does Connect-MgGraph -Scopes control?
Which Azure region is used
Which Graph permissions the session requests
Which license is assigned

24. What is the difference between Entra ID and Active Directory Domain Services?

Entra ID is not a hosted copy of AD DS. They solve different problems and use different protocols, which is why most enterprises run both and sync them.

Aspect AD DS Entra ID
Protocols Kerberos, NTLM, LDAP OAuth 2.0, OpenID Connect, SAML, WS-Federation over HTTPS
Structure Forests, domains, OUs Flat tenant with groups and administrative units
Policy Group Policy Conditional Access and Intune
Query LDAP Microsoft Graph
Hosting Domain controllers you run Microsoft-managed cloud service

Apps that depend on Kerberos or LDAP need AD DS or Entra Domain Services; modern web and mobile apps should authenticate against Entra ID directly.

Take quiz
Which protocol set is native to Entra ID?
Kerberos, NTLM, and LDAP
OAuth 2.0, OpenID Connect, and SAML
RADIUS and TACACS+
Entra ID has no native support for:
Single sign-on
Multifactor authentication
Organizational units and Group Policy

25. What is the difference between single-tenant and multitenant apps?

A single-tenant app accepts sign-ins only from accounts in its home tenant. A multitenant app accepts accounts from any Entra tenant, and optionally personal Microsoft accounts, which is what SaaS vendors need.

The choice is the Supported account types setting on the app registration. The application object always lives in the publisher's home tenant. When a customer user or admin consents for the first time, a service principal is created in the customer's tenant that points back to it. From then on the customer controls assignment, consent, and Conditional Access for their copy.

Authority endpoint Who can sign in
/{tenant-id} Only that tenant (single-tenant)
/organizations Work or school accounts from any tenant
/common Work, school, and personal Microsoft accounts

Take quiz
In a multitenant app, where does the application object live?
In every customer tenant
Only in the first customer's tenant
In the publisher's home tenant
Which authority allows work or school accounts from any tenant, but not personal ones?
/organizations
/consumers
/{your-tenant-id}

26. What is the difference between Entra ID and Microsoft Entra Domain Services?

Microsoft Entra Domain Services is a managed, AD DS-compatible domain. Microsoft hosts the domain controllers and you get domain join, LDAP, Kerberos and NTLM, and Group Policy for legacy apps in Azure, without running DCs yourself. Entra ID alone offers none of these.

Identity flows one way, from Entra ID into the managed domain. You manage users in Entra ID (or in on-premises AD synced through Entra Connect), never in the managed domain. Cloud-only users must reset their password after you enable the service so the NTLM and Kerberos hashes get generated.

The managed domain has limits: no schema extensions and no Domain Admin or Enterprise Admin rights. Choose it for lift-and-shift apps that need LDAP or Kerberos, and use Entra ID alone for modern apps.

Take quiz
Entra Domain Services provides:
Managed domain controllers with LDAP and Kerberos
A replacement for Conditional Access
A hosted password manager
Identity sync into the managed domain is:
Two-way with full writeback
One-way, from Entra ID
Manual CSV import only

27. What is the difference between Entra roles and Azure RBAC?

They are two separate authorization systems that are easy to confuse.

Aspect Entra roles Azure RBAC
Manages Directory objects: users, groups, apps Azure resources: VMs, storage, databases
Scope Tenant, administrative unit, single app Management group, subscription, resource group, resource
Examples Global Administrator, User Administrator Owner, Contributor, Reader
Managed in Entra admin center Access control (IAM) on the resource

Being Global Administrator does not give access to subscriptions by default. A Global Administrator can switch on Access management for Azure resources to gain User Access Administrator at root scope. Do that only temporarily and treat it as a logged, break-glass action.

Take quiz
Which role system scopes down to a single resource group?
Entra directory roles
Azure RBAC
Administrative-unit roles
By default, Global Administrator grants:
Owner on every subscription
Contributor on all resource groups
No access to resources inside Azure subscriptions

28. How does password hash synchronization work?

With password hash synchronization (PHS), Entra Connect syncs a derived hash of each user's password hash, so users sign in to cloud apps with the same password and Entra ID validates it itself.

  1. The sync agent asks a domain controller for password changes using directory replication, under the MSOL_ service account.
  2. It takes the existing MD4 hash and runs it through PBKDF2 with HMAC-SHA256, using a per-user salt and 1,000 iterations.
  3. The result travels over TLS to Entra ID and is stored there.
  4. Changes are picked up roughly every 2 minutes.

The plain-text password and the original hash are never sent. PHS removes any on-premises dependency from cloud sign-in, enables leaked-credential detection in ID Protection, and works well as a backup for the other methods.

Take quiz
How often are password changes synced under PHS?
Once every 24 hours
Only when the user signs out
About every 2 minutes
What does Entra ID store with PHS?
A salted, re-hashed form of the password hash
The plain-text password
A Kerberos ticket-granting ticket

29. Which is better: PHS, PTA, or federation?

It depends on what you need to control. All three keep a single identity, but they differ in where the password is checked.

Method Password validated Dependencies Notes
PHS In the cloud None on-premises at sign-in Simplest; enables leaked-credential detection
PTA On a domain controller via agents Agents must be reachable (outbound only) Enforces on-premises logon hours and account state instantly
Federation (AD FS) On-premises federation servers AD FS farm, proxies, certificates Needed for smart cards or some third-party MFA; most infrastructure

Microsoft's general guidance is to use PHS unless a specific requirement forces another method, and to enable it even as a fallback when using PTA or federation.

Take quiz
Which method needs no on-premises sign-in infrastructure at all?
Password hash synchronization
Pass-through authentication
AD FS federation
What is Microsoft's general recommendation?
Always deploy AD FS
Use PHS, optionally as a backup for other methods
Disable password sync entirely

30. When would you choose Cloud Sync over Connect Sync?

Cloud Sync uses lightweight provisioning agents whose configuration lives in the cloud. Connect Sync is the full on-premises engine with its own SQL database and rich rule editing.

Choose Cloud Sync when you have multiple disconnected AD forests (common after acquisitions), want a simple setup, or want high availability by installing several agents. It also suits organizations that don't need heavy customization.

Choose Connect Sync when you need device writeback, directory extension attribute sync, custom sync rules with attribute transformations, or pass-through authentication, which Cloud Sync does not offer.

The feature gap keeps shrinking, so check Microsoft's current comparison table before deciding. Many tenants start on Cloud Sync and move to Connect only when a missing feature blocks them.

Take quiz
Cloud Sync agents are configured:
Only by editing a local SQL database
From the cloud, with multiple agents for availability
Through Group Policy
A good fit for Cloud Sync is:
Heavy custom sync rules with complex transformations
A tenant that needs pass-through authentication
Many disconnected AD forests after acquisitions

31. How does Conditional Access evaluate multiple policies?

Entra ID evaluates all enabled policies, not first-match. Every policy whose assignments match the sign-in applies, and the user must satisfy the combined grant controls. A block always wins over a grant.

Example: Policy A requires MFA for all cloud apps, and Policy B requires a compliant device for Exchange Online. Signing in to Exchange needs both. Within one policy, grant controls can be set to require all selected controls or just one of them. If session controls conflict, the most restrictive one applies, and an exclusion beats an inclusion in the same assignment.

flowchart TD
A["First-factor sign-in succeeds"] --> B["Find all matching policies"]
B --> C{Any policy blocks?}
C -- Yes --> D["Access blocked"]
C -- No --> E["Combine grant controls"]
E --> F{All controls satisfied?}
F -- Yes --> G["Token issued"]
F -- No --> H["Prompt user for missing control"]

To debug, use the What If tool or the Conditional Access tab on a sign-in log entry.

Take quiz
If one policy blocks and another would grant access, the result is:
Access is granted
The newest policy decides
Access is blocked
Conditional Access policies are evaluated:
All applicable policies apply together
First match stops evaluation
In alphabetical order, stopping at the first grant

32. How do you roll out Conditional Access safely?

The main risk is locking people out, so roll out in stages.

  1. Set up and test emergency access accounts first.
  2. Start from Microsoft's templates, one policy at a time, with a clear naming convention.
  3. Create the policy in report-only mode so it logs what it would have done without enforcing it.
  4. Review the impact in the Conditional Access insights workbook and test scenarios with What If.
  5. Switch it on for a pilot group, then widen to everyone.
  6. Monitor sign-in logs for unexpected failures and keep exclusions documented.

A solid baseline is: MFA for admins, MFA for all users, block legacy authentication, and risk-based policies if you have P2. Add device compliance requirements once Intune enrollment is reliable.

Take quiz
Which mode evaluates a policy without enforcing it?
Report-only
Disabled
Emergency mode
Which tool simulates a policy result for a given user and scenario?
Access reviews
What If
Entra Connect Health

33. Why should you create emergency access accounts?

Emergency access (break-glass) accounts guarantee you can still manage the tenant when normal admin sign-in fails, for example when a Conditional Access policy misfires, MFA is unavailable, or federation is down.

Microsoft recommends at least two accounts with these traits:

  • Cloud-only, using the onmicrosoft.com domain, not synced or federated.
  • Permanently assigned Global Administrator, not eligible through PIM.
  • Very long random passwords stored securely offline, plus a phishing-resistant method such as a FIDO2 key where possible.
  • Excluded from at least some Conditional Access policies, or protected by a dedicated strong one.

Never use them for daily work, and alert on any sign-in so misuse is noticed immediately. Test them on a schedule.

Take quiz
How many emergency access accounts are generally recommended?
None, they are always a risk
At least two
One per administrator
Emergency accounts should be:
Synced from on-premises AD and used daily
Guest accounts from a partner tenant
Cloud-only Global Administrators with alerts on every sign-in

34. Explain the OAuth 2.0 authorization code flow in Entra ID?

The authorization code flow is the standard way a web or mobile app gets tokens on behalf of a signed-in user. Modern apps add PKCE (Proof Key for Code Exchange) so a stolen code is useless.

sequenceDiagram
participant U as User Browser
participant A as Client App
participant E as Entra ID
participant R as Web API
A->>U: Redirect to authorize endpoint with PKCE challenge
U->>E: Sign in and consent
E->>U: Redirect with authorization code
U->>A: Code delivered to redirect URI
A->>E: POST to token endpoint with code and code verifier
E->>A: ID token, access token, refresh token
A->>R: Call API with access token
R->>A: Protected data

The app first sends the user to /oauth2/v2.0/authorize with its client ID, scopes, redirect URI, and a hashed code challenge. After sign-in and consent, Entra ID returns a short-lived authorization code. The app then redeems it at /oauth2/v2.0/token with the original code verifier, and receives tokens. The API validates the access token's signature, issuer, audience, and expiry before serving data.

Take quiz
What does PKCE protect against?
Expired user passwords
DNS poisoning of the tenant domain
Interception and replay of the authorization code
What is sent to the token endpoint to get tokens?
The authorization code and the code verifier
The user's password in a cookie
A SAML assertion for a Kerberos ticket

35. What is the difference between OpenID Connect and SAML?

Both give users single sign-on to apps, and Entra ID supports both on enterprise applications. The difference is the technology underneath.

Aspect OpenID Connect SAML 2.0
Token format JSON Web Token (JWT) XML assertion
Built on OAuth 2.0 Standalone standard
Best for Modern web apps, SPAs, mobile apps, APIs Older enterprise web apps and many commercial SaaS products
Authorization Handled naturally with OAuth access tokens Authentication only; no API access tokens

For a new app, choose OIDC. Choose SAML when a third-party product supports only SAML or when you're integrating an existing SAML-based app.

Take quiz
OpenID Connect is built on top of:
OAuth 2.0
Kerberos
LDAP
When is SAML the right choice?
When building a new mobile app
When a third-party app supports only SAML
When calling Microsoft Graph

36. What is the difference between ID, access, and refresh tokens?

Entra ID issues three token types, each with a different audience and purpose.

Token Purpose Consumed by
ID token Tells the app who signed in The client app
Access token Authorizes a call to an API, sent as a Bearer header The resource API
Refresh token Gets new access tokens without a new sign-in Only Entra ID's token endpoint

Access tokens are short-lived, typically 60 to 90 minutes by default. Refresh tokens last much longer but can be revoked, and they are never sent to APIs. An API should validate the access token's signature, iss, aud, expiry, and its scp or roles claims.

Take quiz
Who should consume an ID token?
The downstream API as proof of authorization
The client app, to learn who signed in
The user's mail server
Where is a refresh token sent?
To every API the app calls
In the redirect URL
Only to Entra ID's token endpoint

37. How does the Primary Refresh Token work?

The Primary Refresh Token (PRT) is a special long-lived token that enables single sign-on on registered, joined, and hybrid joined devices. It is issued on Windows 10/11 and, through brokers or SSO plug-ins, on macOS, iOS, and Android.

When a user signs in to the device with their work account, or with Windows Hello for Business, the device authenticates to Entra ID and receives a PRT. It is bound to the device using keys protected by the TPM where available, so it can't simply be copied elsewhere.

When the user opens a browser or app that needs Entra ID, the OS component presents the PRT and silently obtains tokens, so no prompt appears. The PRT is valid for 14 days and renewed about every 4 hours while in use. It also carries device and MFA claims, which is how Conditional Access can check compliance without prompting again.

You can verify it with dsregcmd /status and look for AzureAdPrt : YES.

Take quiz
What does dsregcmd /status show about SSO?
The user's password hash
The tenant's billing plan
Whether the device holds a PRT
A PRT is protected by:
Device-bound keys, ideally in the TPM
A shared secret in a text file
The browser cookie jar only

38. How does Continuous Access Evaluation work?

Continuous Access Evaluation (CAE) lets Entra ID and resource providers react to security events in near real time instead of waiting for an access token to expire.

Normally an access token lives 60 to 90 minutes, so a disabled user could keep working until it lapses. With CAE-capable clients and services such as Exchange Online, SharePoint Online, Teams, and Microsoft Graph, tokens can last up to 28 hours, but the service can reject them immediately after a critical event:

  • The user account is deleted or disabled.
  • The password is changed or reset.
  • MFA is enabled for the user.
  • An admin explicitly revokes the user's refresh tokens.
  • ID Protection flags high user risk.

CAE also supports near real-time enforcement of IP-based Conditional Access policies. When an event fires, the service returns a 401 with a claims challenge, and the client goes back to Entra ID to reauthenticate under current policy.

Take quiz
Which is a CAE critical event?
An admin revoking a user's refresh tokens
A user opening a new browser tab
A scheduled nightly backup
CAE-enabled tokens can live up to about:
5 minutes
28 hours
30 days

39. How do authentication strengths work in Conditional Access?

An authentication strength is a Conditional Access grant control that names exactly which combinations of methods are acceptable. It replaces the blunt "require MFA" when you need to be specific.

Built-in strength Examples of allowed methods
Multifactor authentication Password plus Authenticator push, OTP, or SMS, plus all passwordless methods
Passwordless MFA Authenticator passwordless, passkeys, Windows Hello for Business
Phishing-resistant MFA Windows Hello for Business, FIDO2 security keys and passkeys, certificate-based authentication

You can also build custom strengths, for example allowing only specific FIDO2 key models. A typical design requires phishing-resistant MFA for administrators and sensitive apps, and the standard MFA strength for everyone else. Users who haven't registered a qualifying method are prompted to register one. This feature needs P1.

Take quiz
Which built-in strength is the strictest?
Multifactor authentication
Phishing-resistant MFA
Password plus SMS
Authentication strengths are applied as:
A license SKU
A sync filter in Entra Connect
A Conditional Access grant control

40. Why are passkeys considered phishing-resistant?

Phishing resistance comes from public-key cryptography bound to the site's origin. A passkey or FIDO2 key keeps a private key that never leaves the authenticator; Entra ID stores only the public key.

  1. Entra ID sends a random challenge to the browser.
  2. The browser passes the challenge along with the site's real origin.
  3. The user unlocks the authenticator with a biometric or PIN.
  4. The authenticator signs the challenge only if the origin matches the one registered for that credential.
  5. Entra ID verifies the signature with the stored public key.

A look-alike phishing domain gets nothing: the authenticator won't sign for the wrong origin, and there's no password or one-time code for the victim to type. Push, SMS, and OTP codes, by contrast, can be relayed live by an attacker-in-the-middle proxy. Windows Hello for Business and Authenticator-based passkeys follow the same model.

Take quiz
Why can't a fake site capture a passkey sign-in?
Passkeys use longer passwords
The fake site is blocked by the user's ISP
The signature is bound to the real site's origin
What does Entra ID store for a passkey?
The public key
The private key
An image of the user's fingerprint

41. Explain how PIM role activation works?

PIM turns a permanent admin role into one the user must request, justify, and use for a limited time. The behavior is defined in each role's settings: maximum duration, whether MFA, justification, or a ticket is required, who approves, and who is notified.

flowchart TD
A["Eligible user selects Activate"] --> B["PIM checks role settings"]
B --> C{MFA or justification required?}
C -- Yes --> D["User completes MFA and enters reason"]
C -- No --> E{Approval required?}
D --> E
E -- Yes --> F["Approvers notified and decide"]
E -- No --> G["Role becomes active"]
F -- Approved --> G
F -- Denied --> H["Request ends, no access"]
G --> I["Role auto-expires at end of window"]
I --> J["Activation recorded in audit history"]

Assignments are either eligible (must activate) or active (usable now), and either permanent or time-bound. Aim for eligible, time-bound assignments, short activation windows such as 4 to 8 hours, and approval for the most sensitive roles like Global Administrator.

Take quiz
What happens when the activation window ends?
The role is removed automatically
The user keeps it until an admin runs a script
The user account is deleted
Which role setting adds a second person's decision?
Enable SSPR
Require approval to activate
Increase the sync interval

42. How do access reviews work in Microsoft Entra ID?

Access reviews let you periodically verify that people still need the access they have, then remove what they don't. You define what is reviewed, who reviews it, and how often.

  • Scope: group memberships, app assignments, Entra and Azure roles (through PIM), and access packages. Guest users are a very common target.
  • Reviewers: resource or group owners, managers, specific people, or users reviewing their own access.
  • Cadence: one-time or recurring, such as quarterly, with a set duration.
  • Help for reviewers: recommendations based on recent sign-in activity, and optional required justification.

You also choose what happens if reviewers don't respond; removing access is the safe default. With auto-apply on, decisions are enforced automatically when the review ends. Access reviews are part of ID Governance licensing.

Take quiz
Which input drives reviewer recommendations?
Password length
Recent sign-in activity
Mailbox size
If reviewers don't respond, a safe default is to:
Grant Global Administrator
Disable the review
Remove access

43. How does entitlement management work in Microsoft Entra ID?

Entitlement management bundles resources into access packages that people can request, instead of admins adding users to groups one by one. Packages live in catalogs that define which resources, such as groups, apps, SharePoint sites, and Teams, can be included.

  1. An admin or catalog owner builds an access package with its resources.
  2. A policy defines who can request it (internal users, specific partner organizations, any external user), the approval stages, and an expiry.
  3. A user requests the package and, if approved, receives all included access at once.
  4. Access expires automatically unless renewed, and reviews can be attached.

For external users, approval can auto-create the guest account, and when their last package expires the guest can be removed. This keeps partner access time-boxed and auditable without manual cleanup.

Take quiz
What is an access package?
A Windows installer for Entra Connect
A set of Conditional Access policies
A bundle of resources with request and expiry policies
What can happen to a guest when their last package expires?
Their access is removed and the guest can be cleaned up
They are promoted to Global Administrator
Their access is extended forever

44. What is the difference between delegated and application permissions?

The two permission types decide who the app acts as when it calls an API such as Microsoft Graph.

Aspect Delegated Application
Acts as The signed-in user, through the app The app itself, with no user present
Token claim scp roles
Effective access Intersection of the app's permission and the user's own rights Everything the permission allows, across the tenant
Consent User or admin, depending on the permission Always an admin
Typical use Web app reading the signed-in user's mail Background daemon or automation

Application permissions are far more powerful. Mail.Read as an application permission can read every mailbox unless you restrict it, so grant them sparingly and prefer delegated access where a user is present.

Take quiz
Which claim carries delegated permissions in an access token?
scp
roles
tid
Application permissions always require:
Only the signed-in user's MFA
Admin consent
A Teams license

Admin consent is required when an app asks for something a regular user can't approve: every application permission, delegated permissions marked as admin-restricted (for example Directory.ReadWrite.All), and any permission at all when tenant policy turns off user consent.

Tenant-wide user consent has three settings: no user consent, user consent only for verified publishers requesting low-risk permissions (the safer, recommended choice), or consent to any app (not recommended).

When users are blocked, enable the admin consent workflow so they can request approval from designated reviewers. Admins can also grant consent in the portal under Enterprise applications, or with a URL like https://login.microsoftonline.com/<tenant>/adminconsent?client_id=<app-id>.

Tight consent settings guard against illicit consent grant attacks, where a malicious app tricks a user into granting access to their mail or files.

46. How do you secure workload identities in Microsoft Entra ID?

Workload identities, meaning service principals and managed identities, don't use MFA, so protect them through credentials, scope, and monitoring.

  • Prefer managed identities for anything running in Azure.
  • Outside Azure, use federated identity credentials so GitHub Actions, Kubernetes, or other trusted IdPs get tokens without stored secrets.
  • If a secret is unavoidable, choose certificates over client secrets, keep lifetimes short, and track expiry.
  • Grant the least-privileged permissions, and be especially wary of application permissions like Directory.ReadWrite.All.
  • Assign owners, and remove unused apps and stale credentials regularly.
  • Use Conditional Access for workload identities (a Workload ID Premium feature) to block sign-ins from outside trusted locations or from risky service principals.
  • Watch the service principal sign-in logs for new locations or unusual activity.
Take quiz
Best option when GitHub Actions needs Azure access?
A client secret that never expires
A Global Administrator password in repo secrets
A federated identity credential with no stored secret
Conditional Access for workload identities targets:
Service principals, for example by location or risk
Guest users
Intune-enrolled printers

47. How do cross-tenant access settings work?

Cross-tenant access settings control how your tenant interacts with other Entra tenants. They work in two directions: inbound (their users reaching your resources) and outbound (your users reaching theirs). B2B collaboration and B2B direct connect are configured separately.

There are two layers. Default settings apply to all external organizations, and organizational settings are added per partner tenant ID and override the defaults. In each you can allow or block specific users, groups, and applications.

Trust settings let you accept MFA, compliant-device, and hybrid-joined claims from a partner's tenant, so their users aren't asked for MFA twice. You can also auto-redeem invitations for trusted partners. Separately, tenant restrictions v2 limits which external tenants your own users can sign in to from your network or devices.

A common pattern is to block outbound and inbound by default, then allow only named partners such as Fabrikam with the needed apps.

Take quiz
What does an organizational setting do?
Overrides the defaults for one specific partner tenant
Deletes the partner's tenant
Applies only to on-premises AD
What does accepting a partner's MFA claim achieve?
Their passwords are copied into your tenant
Their users aren't prompted for MFA twice
Their guests become members

48. How do you troubleshoot a failed Microsoft Entra ID sign-in?

Work from the evidence in the logs rather than guessing.

  1. Collect the user, approximate time, app, and the error text. A correlation ID or request ID from the error page speeds things up.
  2. Open Sign-in logs, filter by user, and open the failed event. Check the status, failure reason, and the AADSTS code.
  3. Review the Authentication details, Device info, and Conditional Access tabs to see which policy applied and which control failed.
  4. Reproduce the scenario with the What If tool.
  5. Fix the cause, ask the user to retry, and confirm the new log entry succeeds.
Error code Usual meaning
AADSTS50126 Invalid username or password
AADSTS50076 MFA required; user must complete it
AADSTS50105 User not assigned to the app
AADSTS65001 Consent has not been granted
AADSTS53003 Blocked by Conditional Access
AADSTS700016 App not found in the tenant

Take quiz
Which AADSTS error indicates Conditional Access blocked access?
AADSTS50126
AADSTS53003
AADSTS65001
Which sign-in log tab shows which policy failed?
Device info
Additional details
Conditional Access

49. How can you monitor Entra ID with Log Analytics?

Send the logs to a Log Analytics workspace through Entra's Diagnostic settings. Select the categories you need, such as AuditLogs, SignInLogs, NonInteractiveUserSignInLogs, and ServicePrincipalSignInLogs. The feature needs P1 or P2.

Once data arrives, query it with KQL, build workbooks, and create Azure Monitor alerts or feed Microsoft Sentinel. Failed sign-ins grouped by error and app:

SigninLogs
| where TimeGenerated > ago(24h) and ResultType != "0"
| summarize Failures = count() by ResultType, AppDisplayName
| order by Failures desc

And privileged role additions:

AuditLogs
| where OperationName == "Add member to role"
| project TimeGenerated, InitiatedBy, TargetResources

Good alert candidates are role assignments, Conditional Access policy changes, emergency account sign-ins, and spikes in risky sign-ins.

Take quiz
Where do you configure the export of Entra logs?
The Entra Connect wizard
The app registration manifest
Diagnostic settings in Entra monitoring
Which Log Analytics table holds interactive sign-in events?
SigninLogs
AuditLogs
AzureActivity

50. How do you design a least-privilege Entra ID tenant?

Think in layers, and make each one reduce standing power or exposure.

Layer Key controls
Admin model Separate cloud-only admin accounts, PIM eligible roles with approval, role-assignable groups, administrative units, fewer than five Global Administrators, two emergency accounts
Authentication Passkeys or Windows Hello for Business, phishing-resistant strength for admins, legacy authentication blocked, Temporary Access Pass for onboarding
Conditional Access Layered baseline: MFA for all, compliant device for sensitive apps, risk-based policies, report-only before enforcement
Devices Intune enrollment and compliance policies feeding Conditional Access
Apps and workloads Restricted user consent, admin consent workflow, managed identities, federated credentials, app owners and expiry tracking
Governance Access reviews, access packages with expiry, guest lifecycle, cross-tenant access settings
Monitoring Logs to Log Analytics or Sentinel with alerts on role changes, policy edits, and risky sign-ins

Start with the admin model and authentication, since a compromised privileged account does the most damage. Then move outward to apps, governance, and monitoring, measuring progress with Microsoft's Identity Secure Score.

Take quiz
Which approach best limits standing admin power?
Eligible PIM assignments with approval and MFA
Permanent Global Administrator for every admin
One shared admin account for the team
What keeps stale partner access under control?
Disabling the audit logs
Access reviews and access package expiry
Giving guests Global Reader
«
»

Comments & Discussions