MS-102 - Implement and Manage Identity and Access (26% of the exam) - Section 2.1

Implement and manage Microsoft Entra identity including users, groups, and external identities.

Configure Microsoft Entra ID for user provisioning and group management, including dynamic membership rules and administrative units. Distinguish between member users and B2B collaboration guest users, and recognise when external identities are appropriate.

Microsoft Entra IDuser provisioninggroup managementexternal identitiesB2B collaboration

Practice question for this objective

Free sampleImplement and Manage Identity and Accessmedium

Your operations team wants to monitor an AD FS farm and a Microsoft Entra Connect Sync server from the Microsoft Entra Connect Health portal. Which licensing tier is required for any user of the tenant to consume these Health insights?

  • AMicrosoft Entra ID Free is sufficient because Health ships with the base hybrid identity tooling.
  • BMicrosoft Entra ID P1 or P2 must be assigned at the tenant level for the Health portal. Correct
  • CMicrosoft 365 E5 Compliance is the minimum SKU that unlocks the Connect Health portal blades.
  • DMicrosoft Defender for Identity P2 is required in addition to Microsoft Entra ID Free here.
Microsoft Entra Connect is free; Connect Health requires Microsoft Entra ID P1 or P2. The Microsoft Entra Connect Health prerequisites table lists a Microsoft Entra ID P1 or P2 subscription as the licensing requirement. Using Connect itself is free, but the Health monitoring portal is a P1/P2 feature.

Why A is wrong: Microsoft Entra Connect itself is free, but the Health portal explicitly requires Microsoft Entra ID P1 or P2 licensing.

Why B is correct: Correct. The Microsoft Entra Connect Health prerequisites table lists a Microsoft Entra ID P1 or P2 subscription as the licensing requirement.

Why C is wrong: Health is a Microsoft Entra ID feature, not a Microsoft 365 Compliance feature; E5 Compliance does not gate it.

Why D is wrong: Microsoft Defender for Identity is a separate product line; it has no role in entitling the Connect Health portal.

See more MS-102 practice questions, answers explained.

Exam traps in Implement and Manage Identity and Access

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • Authoring Conditional Access policies that do not include any risk condition.

    Why it is wrong: Standard Conditional Access requires only Microsoft Entra ID P1; it is the risk conditions that demand P2.

  • Add all three groups directly on the Properties page using the multi-group picker.

    Why it is wrong: Only one Microsoft Entra group can be enabled for SSPR via the admin center, so the picker does not accept three peer groups.

  • In the Hardware OATH tokens section, with Microsoft Authenticator listed as a software token.

    Why it is wrong: Hardware OATH tokens is reserved for physical OATH tokens; Microsoft Authenticator OTP is not configured there.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.