The conditions required before protected branches change
Connect it to review and status checks.
Teams
Group-based access and communication
Simplify consistent organization access.
Enterprise Managed Users
Centrally managed enterprise identities
Understand the governance purpose.
flowchart TD
A[Identity] --> B[Authentication: 2FA or passkey]
B --> C[Organization membership]
C --> D[Team or role permissions]
D --> E[Repository access]
E --> F[Branch protection and review rules]
The central exam principle is least privilege: grant the smallest level of access that allows someone to do their work, then review it as needs change.
Scope
What it governs
Examples to recognize
Repository role
What someone can do in a repository
Read, triage, write, maintain, or administer based on available roles.
Team
A reusable group of organization members
Apply consistent access to multiple repositories.
Organization role
Organization-level responsibilities
Manage members, settings, or other organization functions.
Branch protection does not replace collaboration. It formalizes the conditions that must be met before a protected branch is changed. In an exam scenario, connect the desired outcome to the appropriate control: review quality, automated validation, or preventing direct unreviewed changes.
Explain how 2FA and passkeys strengthen account access.
Choose the least-privileged role or team approach for a simple access scenario.
Distinguish public, private, and internal visibility.
Identify when branch protection, review requirements, and status checks apply.
Describe the governance purpose of EMUs and organization-wide Copilot policies.
Suggested answers
Account protection: 2FA requires an additional verification factor beyond a password. Passkeys provide a modern authentication approach that can reduce exposure to reusable password credentials.
Least privilege: Put people with the same access needs into a team and grant that team only the repository role required. Avoid administrator access when read, triage, write, or maintain access is enough.
Visibility: Public repositories are broadly discoverable, private repositories are restricted to authorized access, and internal repositories are limited to enterprise members where that option is available.
Protected branches: Use branch protection when important branches need controls such as required reviews, passing status checks, or restrictions on direct updates before changes are merged.
Governance: Enterprise Managed Users support centrally managed enterprise identity, while organization-wide Copilot policies help administrators govern Copilot use across organization members.