Microsoft 365 Administrator Expert MS-102 Practice Question
You administer a Microsoft Entra tenant that currently authenticates hybrid users by using Password Hash Synchronization (PHS) with Seamless Single Sign-On (Seamless SSO). New compliance rules require that account lockout policies configured in the on-premises Active Directory must also apply when users sign in to Microsoft 365, but management does not want to deploy AD FS.
You must modify the authentication configuration to meet the requirement while
keeping the existing Seamless SSO user experience, and
ensuring you can quickly revert to the current state without forcing users to re-enter their credentials.
In Microsoft Entra Connect, which change should you make?
Change the sign-in method to federated authentication with Active Directory Federation Services (AD FS).
Disable Password Hash Synchronization and enable Pass-through Authentication as the only sign-in method.
Enable Pass-through Authentication and keep Password Hash Synchronization enabled as a backup sign-in method.
Retain Password Hash Synchronization but enable Azure AD Password Protection for Active Directory.
Pass-through Authentication (PTA) validates the user's password directly against the on-premises domain controller, so any lockout policy enforced by AD immediately applies to cloud sign-ins. PTA also supports Seamless SSO without additional infrastructure. When you enable PTA in Microsoft Entra Connect and leave Password Hash Synchronization selected, the synchronized password hashes remain available as an automatic or manual fallback. This design lets you switch the sign-in method back to PHS at any time without requiring users to change or re-enter their passwords. Disabling PHS would remove that rollback path, deploying AD FS would violate the no-AD FS constraint, and enabling Azure AD Password Protection does not extend on-premises lockout policies to cloud authentication.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Pass-through Authentication (PTA) in Microsoft Entra Connect?
Open an interactive chat with Bash
How does enabling Password Hash Synchronization (PHS) serve as a fallback method?
Open an interactive chat with Bash
Why is AD FS not suitable in this scenario?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .