Question 22 of 88 from exam SC-300: Microsoft Identity and Access Administrator

Question 22 of 88 from exam SC-300: Microsoft Identity and Access Administrator

Question

HOTSPOT - You have an Azure Active Directory (Azure AD) tenant that has an Azure Active Directory Premium Plan 2 license.

The tenant contains the users shown in the following table.

Role

Admin1

Cloud device administrator

Admin2

Device administrator

User1

None

You have the Device Settings shown in the following exhibit.

& Devices | Device settings

Default Directory - Azure Active Directory

All devices
Device settings
Enterprise State Roaming

BitLocker keys (Preview)

x0ESb E

Diagnose and solve problems
Activity

@ Audit logs

& Bulk operation results (Preview)
Troubleshooting + Support

B New support request

«

save X Discard | Q Got feedback?

Users may join devices to Azure AD ©

GENMD selected None

Selected

Users may register their devices with Azure AD ©

Devices to be Azure AD joined or Azure AD registered require Multi-Factor Authentication ©

vs Gr

Ad We recommend that you require Multi-Factor Authentication to register or join devices using Conditional Access. Set this
device setting to No if you require Multi-Factor Authentication using Conditional Access.

Maximum number of devices per user ©

5

Additional local administrators on all Azure AD joined devices

Manage Additional local administrators on All Azure AD joined devices

User1 has the devices shown in the following table.

Name _ | Operating system Device identity
Device1__| Windows 10 Azure AD joined
Device2__| iOS Azure AD registered
Device3__| Windows 10 Azure AD registered
Device4 | Android Azure AD registered

For each of the following statements, select Yes if the statement is true.

Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

Answer Area
Statements Yes No

User1 can join four additional Windows 10 devices to Azure AD. Oo 0

Admin1 can set Devices to be Azure AD joined or Azure AD registered require QO} [Oo
Multi-Factor Authentication to Yes.

Admin2 is a local administrator on Device3. oumne)

Explanations

Answer Area
Statements Yes No

User1 can join four additional Windows 10 devices to Azure AD. | ° | °

Admin1 can set Devices to be Azure AD joined or Azure AD registered require 3° | ° |
Multi-Factor Authentication to Yes.

Admin2 is a local administrator on Device3. ° | ° |

Box 1: Yes - Users may join 5 devices to Azure AD.

Box 2: No - Cloud device administrator an enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys in the Azure portal.

The role does not grant permissions to manage any other properties on the device.

Box 3: No - An additional local device administrator has not been applied Reference: https://docs.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal.