An Azure AD tenant contains several users. You must prevent the users from creating app passwords, while ensuring that User1 can continue to use the Mail and Calendar app. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: From multi-factor authentication, configure the service settings..
Why this is the answer
The correct answer is to configure the service settings from multi-factor authentication. This allows you to disable the creation of app passwords for all users, which is necessary to meet the requirement of preventing users from creating app passwords. However, it also provides an option to allow specific users, like User1, to continue using app passwords if they have already been generated or if their application (like Mail and Calendar) still requires them. Assigning User1 the Authentication Policy Administrator role is incorrect because this role manages authentication policies but doesn't directly control app password creation for individual users. Enabling Azure AD Password Protection is incorrect as it focuses on preventing weak passwords and password spraying, not app password generation. Configuring an MFA registration policy is incorrect because it dictates how users register for MFA, not how they use or create app passwords. Creating a new app registration is incorrect as it's for integrating an application with Azure AD, not for managing app password policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed