This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of the concepts covered in this module.
An administrator wants Relecloud's fraud-investigation agent to authenticate to systems that strictly require a Microsoft Entra user object, such as a shared mailbox. What must the administrator provision for the agent, in addition to its agent identity?
Nothing extra—the existing agent identity can authenticate to any system once it has an assigned sponsor
A second agent identity blueprint dedicated to mailbox access
An agent's user account, paired 1:1 with the agent identity
Relecloud's fraud-investigation agent runs for months with no one accountable for its purpose, lifecycle, or access reviews after its builder leaves the company. Which missing role explains this gap?
The agent identity was never assigned an Agent Registry owner
The agent identity blueprint was deleted when the builder left
A sponsor was never assigned to the agent identity
A sponsor leaves Relecloud, and no administrator has configured any Lifecycle Workflow for agent identity sponsorship. What happens to the agent identities that sponsor was accountable for?
The affected agent identities are automatically disabled until a new sponsor is assigned
Microsoft Entra ID automatically reassigns sponsorship to the departed sponsor's manager, with no configuration required
Sponsorship doesn't move to anyone automatically—it stays assigned to the departed sponsor until an administrator configures a workflow or manually reassigns it
An administrator configures a Lifecycle Workflow with the Transfer agent identity sponsorships to manager task, but the departing sponsor's manager attribute in Microsoft Entra ID was never populated. What's the most likely outcome?
The task transfers sponsorship to a co-sponsor instead, as a fallback
The task can't determine who to transfer sponsorship to, so the transfer doesn't complete as intended
The workflow fails entirely and no other tasks in it run
Relecloud applies a Conditional Access policy directly to one existing agent identity created from a shared blueprint. The engineering team then creates three more agent identities from that same blueprint. Are the three new agent identities protected by the policy?
No—a policy applied to a single agent identity protects only that identity; it must be applied at the blueprint level to cover current and future identities the blueprint creates
Yes, but only after an administrator manually re-applies the policy to each of the three new identities
Yes—Conditional Access policies automatically extend to every agent identity created from the same blueprint, regardless of where the policy is scoped
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?