Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft MS-102 Exam - Topic 1 Question 1 Discussion

Your on-premises network contains an Active Directory domain.You have a Microsoft 365 subscription.You need to sync the domain with the subscription. The solution must meet the following requirements:On-premises Active Directory password complexity policies must be enforced.Users must be able to use self-service password reset (SSPR) in Azure AD.What should you use?
D) pass-through authentication
A) password hash synchronization
B) Azure AD Identity Protection
C) Azure AD Seamless Single Sign-On (Azure AD Seamless SSO)

Microsoft MS-102 Exam - Topic 1 Question 1 Discussion

Actual exam question for Microsoft's MS-102 exam
Question #: 1
Topic #: 1
[All MS-102 Questions]

Your on-premises network contains an Active Directory domain.

You have a Microsoft 365 subscription.

You need to sync the domain with the subscription. The solution must meet the following requirements:

On-premises Active Directory password complexity policies must be enforced.

Users must be able to use self-service password reset (SSPR) in Azure AD.

What should you use?

Show Suggested Answer Hide Answer
Suggested Answer: D

Azure Active Directory (Azure AD) Pass-through Authentication allows your users to sign in to both on-premises and cloud-based applications using the same passwords.

This feature is an alternative to Azure AD Password Hash Synchronization, which provides the same benefit of cloud authentication to organizations. However, certain organizations wanting to enforce their on-premises Active Directory security and password policies, can choose to use Pass-through Authentication instead.

Note: Azure Active Directory (Azure AD) self-service password reset (SSPR) lets users reset their passwords in the cloud, but most companies also have an on-premises Active Directory Domain Services (AD DS) environment for users. Password writeback allows password changes in the cloud to be written back to an on-premises directory in real time by using either Azure AD Connect or Azure AD Connect cloud sync. When users change or reset their passwords using SSPR in the cloud, the updated passwords also written back to the on-premises AD DS environment.

Password writeback is supported in environments that use the following hybrid identity models:

Password hash synchronization

Pass-through authentication

Active Directory Federation Services


https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback

Contribute your Thoughts:

0/2000 characters
Elli
9 months ago
B seems off, Identity Protection isn’t for syncing like this.
upvoted 0 times
...
Layla
9 months ago
Agree with A, it meets all the requirements perfectly.
upvoted 0 times
...
Franchesca
10 months ago
Wait, can SSPR really work with on-prem policies? Sounds tricky!
upvoted 0 times
...
Maryrose
10 months ago
I think D, pass-through authentication could work too.
upvoted 0 times
...
Louann
10 months ago
Definitely A, password hash sync is the way to go!
upvoted 0 times
...
Darci
10 months ago
Azure AD Seamless SSO sounds familiar, but I don't think it directly relates to password complexity policies. I might be mixing it up with something else.
upvoted 0 times
...
Andree
10 months ago
I practiced a similar question where pass-through authentication was mentioned, but I can't recall if it meets the SSPR requirement.
upvoted 0 times
...
Ena
11 months ago
I think Azure AD Identity Protection is more about detecting risks rather than syncing passwords, so that doesn't seem right for this question.
upvoted 0 times
...
Royal
11 months ago
I remember that password hash synchronization allows for enforcing on-premises password policies, but I'm not entirely sure if it supports SSPR.
upvoted 0 times
...
Edelmira
11 months ago
I'm feeling a little lost on this one. I know Cisco ISE is used for network access control, but I don't have much experience with the actual configuration process. I'll have to guess and hope for the best.
upvoted 0 times
...
Belen
11 months ago
Hmm, I'm a bit unsure about the details of how Aviatrix Firenet works. I'll need to re-read that section of the material.
upvoted 0 times
...
Carol
11 months ago
I remember practicing a question that mentioned semantic analysis; I feel like that could be part of the definition—maybe C?
upvoted 0 times
...
Thea
11 months ago
Wait, what's the deal with the periods and ellipses? I don't think I've seen those used in file paths before. I'll have to double-check that detail.
upvoted 0 times
...

Save Cancel