nerdexam
Microsoft

SC-300 · Question #327

You have an Azure AD tenant that contains the users shown in the following table. You enable self-service password reset (SSPR) for all the users and configure SSPR to require security questions as…

The correct answer is B. User3 and User4 only. Basically, some administrative roles, by design can only use strong, two-gate password reset policy, regardles of SSPR settings. User Administrator and Password Administrator will be always forced to use two methods and cannot use security questions. Securiry Reader and User…

Submitted by jakub_pl· Mar 6, 2026Implement authentication and access management

Question

You have an Azure AD tenant that contains the users shown in the following table. You enable self-service password reset (SSPR) for all the users and configure SSPR to require security questions as the only authentication method. Which users must use security questions when resetting their password?

Exhibit

SC-300 question #327 exhibit

Options

  • AUser4 only
  • BUser3 and User4 only
  • CUser1 and User4 only
  • DUser1, User3, and User4 only
  • EUser1, User2, User3, and User4

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    78% (36)
  • C
    2% (1)
  • D
    4% (2)
  • E
    13% (6)

Explanation

Basically, some administrative roles, by design can only use strong, two-gate password reset policy, regardles of SSPR settings. User Administrator and Password Administrator will be always forced to use two methods and cannot use security questions. Securiry Reader and User will use whatever is set under SSPR, so security questions in this https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr- policy#administrator-reset-policy-differences

Topics

#SSPR#security questions#authentication methods#password reset

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice