Exam objective

AZ-900

Describe Azure identity, access, and security

This objective sits in Describe Azure architecture and services, which carries 38% of the Azure Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe Azure architecture and services

A company runs on-premises Active Directory and Microsoft Entra ID and is tired of maintaining two separate sets of user identities. Which tool synchronizes identities between the two?

Microsoft Entra Domain ServicesDomain Services provides a managed domain with Kerberos and group policy; it does not sync an on-premises AD to the cloud.
Microsoft Entra ConnectCorrect · your answerCorrect.
Azure ArcAzure Arc manages servers and resources across environments, not directory identities.
Microsoft Entra External IDExternal ID handles partners and customers from outside the tenant, not the company's own on-premises accounts.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

Hybrid identity hinges on one component that keeps the directory in the datacenter and the directory in the cloud describing the same people.

Why B

The source says Microsoft Entra Connect bridges the gap by synchronizing user identities between on-premises Active Directory and Microsoft Entra ID.

Source

Without a connection, an on-premises Active Directory deployment and a cloud Microsoft Entra ID deployment require you to maintain two separate identity sets. Microsoft Entra Connect bridges that gap. Microsoft Entra Connect synchronizes user identities between on-premises Active Directory and Microsoft Entra ID.

Describe Azure directory services, checked September 2026
#entra-id#entra-connect#scenario

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe Azure architecture and services

A security team wants a sign-in method that uses an unphishable hardware device and involves no username or password at all. Which Microsoft Entra ID option fits?

Sample question 2 of 3

Describe Azure architecture and services

A company stops treating devices on its internal network as automatically safe and requires every request to authenticate before access is granted. Which security model is this?

Sample question 3 of 3

Describe Azure architecture and services

In a defense-in-depth design, an analyst wants distributed denial of service protection to filter large-scale attacks before they affect availability. Which layer does this control belong to?

That’s 3 of the full Azure Fundamentals bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe Azure architecture and services