Identify the core features and objects of Microsoft 365 services
Identity Posture, Privilege, Auditing, and Applications
ImportantInterpret identity posture, choose the right activity log, reduce standing privilege, and distinguish an application definition from its tenant instance.
Aligned to the current AB-900 guide, verified July 22, 2026.
Why this matters
AB-900 tests whether you can choose the right identity evidence, reduce standing privilege, and distinguish an application definition from its tenant instance.
Must Know
- Identity Secure Score recommends posture improvements; it is not proof of security or compromise.
- Sign-in logs record authentication and policy evaluation; Entra audit logs record directory changes; Purview Audit spans supported Microsoft 365 activities.
- PIM provides eligible, time-bound privileged role activation instead of permanent standing access.
- Conditional Access governs access conditions during sign-in; PIM governs activation of privileged roles.
- An app registration is the reusable application definition; an enterprise application is the local service principal used for assignment, consent, and SSO.
- Investigate with the evidence source that matches the event instead of treating every identity problem as a sign-in failure.
Compare and Distinguish
- Sign-in logs vs audit logs: authentication and policy evaluation vs changes and activities after or outside sign-in.
- Entra audit vs Purview Audit: directory-focused changes vs searchable activity across supported Microsoft 365 workloads.
- Conditional Access vs PIM: conditions for accessing resources vs eligible/time-bound activation of privileged roles.
- Identity Secure Score vs incident evidence: posture recommendations vs detections and facts about a possible attack.
- App registration vs enterprise application: global/home definition vs local tenant service principal and access configuration.
Scenario examples
- Scenario: An administrator changed a Conditional Access policy. Think: Find the directory change in Entra audit logs, then use sign-in logs to see its effect on access attempts.
- Scenario: A help-desk lead needs User Administrator for one hour. Think: Eligible PIM activation is preferable to permanent assignment.
- Scenario: A SaaS app should be limited to one group in this tenant. Think: Manage assignment on the enterprise application/service principal.
- Scenario: Secure Score recommends disabling a legacy method that a business process still uses. Think: Assess the dependency and remediation plan; the score is guidance, not an automatic command.
Exam traps
- Identity Secure Score is neither a compliance certificate nor a breach-probability score.
- PIM does not replace Conditional Access, and Conditional Access does not make a role eligible or time-limited.
- Sign-in logs do not answer every post-sign-in file or admin action; use the appropriate audit log.
- Deleting an enterprise application instance is not the same operation as deleting the home-tenant app registration.
Key takeaways
- Posture → Secure Score; sign-in → sign-in log; change/activity → audit; temporary privilege → PIM.
- Conditional Access controls access conditions; PIM controls privileged-role activation.
- Application object defines; service principal represents the tenant instance.
How it works
- Secure Score recommendations earn or lose points as configuration changes. Administrators evaluate applicability, implementation effort, licensing, and compensating controls rather than chasing points blindly.
- PIM separates eligibility from activation. An eligible person activates a role under configured requirements; the role then expires instead of remaining permanently active.
- A multitenant application has one application definition in its home tenant and a service principal in each consuming tenant. The enterprise-application view governs that tenant’s instance.
Objects and administrative surfaces
- Identity Secure Score, audit logs, sign-in logs, PIM, App registrations, and Enterprise applications — Microsoft Entra admin center.
- Unified activity search and audit records for supported Microsoft 365 workloads — Microsoft Purview portal.
- Role assignments and activation history — PIM; application assignment, permissions/consent, and SSO — Enterprise applications.
When to use it
- Use Identity Secure Score to prioritize identity-hardening improvements, then validate each recommendation against the tenant.
- Use PIM when administrative access should be just-in-time or approval-gated instead of permanently active.
- Use App registrations when defining an application and API permissions; use Enterprise applications when managing the application instance used in your tenant.
Security and governance implications
- Limit permanent privileged assignments, configure PIM approval and duration according to risk, and review activation/audit history.
- Restrict who can consent to applications and inspect requested permissions before granting tenant-wide consent.
- Treat logs as sensitive evidence; grant reader/investigator roles on a need-to-know basis and preserve records according to policy.
Troubleshooting signals
- Start with the event type and time: sign-in, directory change, or workload activity. Select the corresponding log and filter by actor, target, application, operation, or correlation ID.
- For PIM, verify eligibility, activation requirements, approval, duration, role scope, and whether propagation is complete.
- For an application, identify both the app ID and service principal/object ID; then check assignment, consent, credentials, redirect configuration, and sign-in logs.
More detail
- Identity Secure Score measures alignment with Microsoft identity-security recommendations. The score and improvement actions help prioritize work, but a high score is not proof that the tenant is secure and a low score is not proof of compromise.
- Microsoft Entra audit logs record directory changes such as user, group, application, policy, or role updates and identify actor, target, time, and result. Sign-in logs answer who attempted to authenticate, to which resource, how, under what policy/risk context, and whether it succeeded.
- Microsoft Purview Audit provides a broader search across supported Microsoft 365 user and administrator activities. Choose the log whose scope matches the event: Entra directory change, Entra sign-in, or cross-workload Microsoft 365 activity.
- Privileged Identity Management reduces standing privilege by making an assignment eligible. Activation can require justification, approval, MFA, or a limited duration and creates auditable activity. PIM governs privileged access; Conditional Access governs access decisions for sign-ins.
- An app registration creates an application object, which is the reusable definition and home-tenant configuration. An enterprise application represents the service principal—the local instance of an application in a tenant—where administrators manage assignment, consent, and SSO behavior.
Ready for the quiz?
- When would you use sign-in logs instead of audit logs?
- Why are Conditional Access and PIM complementary rather than interchangeable?
- What does Identity Secure Score tell you—and what does it not prove?
- How does an app registration differ from an enterprise application?
Related objectives
- D1.3.f — Interpret Identity Secure Score in Microsoft Entra ID
- D1.3.g — Use the appropriate tools to review audit logs for user and admin activity
- D1.3.h — Identify the role of Privileged Identity Management (PIM) in an organization
- D1.3.i — Understand App registrations and Enterprise apps