nerdexam
Microsoft

MS-721 · Question #85

Drag and Drop Question You need to provision a Microsoft Teams-certified common area phone device at a field site. The solution must ensure that a standard user can complete the physical handset tasks

The correct answer is From the Microsoft Teams admin center, upload the MAC address of the device; From the Microsoft Teams admin center, generate a verification code; Instruct the user to enter the verification code on the device; From the Microsoft Teams admin center, remotely sign-in a user to the device. The question requires understanding the secure provisioning sequence for a Microsoft Teams common area phone using the device code flow, which avoids sharing credentials directly with the end-user.

Implement and configure Teams Phone

Question

Drag and Drop Question You need to provision a Microsoft Teams-certified common area phone device at a field site. The solution must ensure that a standard user can complete the physical handset tasks without sharing credentials. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Exhibit

MS-721 question #85 exhibit

Answer Area

Drag items

From the Microsoft Teams admin center apply a managed tag to the deviceInstruct the user to enter the verification code on the deviceEnable the web server on the device and sign in by using a browserFrom the Microsoft Teams admin center, upload the MAC address of the deviceFrom the Microsoft Teams admin center, remotely sign-in a user to the deviceFrom the Microsoft Teams admin center, generate a verification code

Correct arrangement

  • From the Microsoft Teams admin center, upload the MAC address of the device
  • From the Microsoft Teams admin center, generate a verification code
  • Instruct the user to enter the verification code on the device
  • From the Microsoft Teams admin center, remotely sign-in a user to the device

Explanation

The question requires understanding the secure provisioning sequence for a Microsoft Teams common area phone using the device code flow, which avoids sharing credentials directly with the end-user.

Approach. The correct approach involves using the device code flow for remote sign-in, which is ideal for common area phones at field sites without sharing credentials. The sequence is as follows:

  1. From the Microsoft Teams admin center, upload the MAC address of the device: This step is crucial for the Teams admin center to recognize and manage the specific physical device. Without identifying the device, no further configuration or sign-in can proceed.
  2. From the Microsoft Teams admin center, generate a verification code: Once the device is registered, the administrator initiates the remote sign-in process by generating a unique verification code. This code acts as a temporary token to link the device to a specific resource account.
  3. Instruct the user to enter the verification code on the device: The user at the field site, without needing any credentials, physically inputs the generated verification code onto the device's interface. This action establishes a secure link between the device and the admin-initiated sign-in process.
  4. From the Microsoft Teams admin center, remotely sign-in a user to the device: After the code is entered on the device, the administrator completes the sign-in process from the Teams admin center, associating a Common Area Phone resource account (or a designated user account) with the device. This finalizes the provisioning without the user ever seeing or entering account credentials.

Common mistakes.

  • common_mistake. Choosing 'From the Microsoft Teams admin center apply a managed tag to the device' is incorrect for the initial sign-in sequence. Tags are typically applied after a device is provisioned and signed in, for organizational or policy management purposes. Selecting 'Enable the web server on the device and sign in by using a browser' is also incorrect because while it's a valid sign-in method for some devices, the question specifically states 'without sharing credentials' and implies a remote/device code flow for ease of use at a field site. This method often requires direct credential entry or is less secure for a general user compared to the device code flow, and it's not the primary method for the 'without sharing credentials' requirement when a remote sign-in option is available.

Concept tested. Provisioning and secure sign-in methods for Microsoft Teams-certified common area phones, specifically leveraging the device code flow for remote sign-in without direct credential sharing.

Topics

#Common Area Phone#Device Provisioning#Teams Phone#Resource Account

Community Discussion

No community discussion yet for this question.

Full MS-721 Practice