Microsoft 365 Administrator Expert MS-102 Practice Question
Your company deploys Microsoft Entra Password Protection for its on-premises Active Directory forest. The Azure AD Password Protection proxy service is installed on two member servers, and the domain controller (DC) agent is installed on all DCs. After registering the forest, password changes that violate the banned password list are still accepted. Event ID 30009 on a DC reports that the agent cannot contact a proxy service. Which firewall rule should you create to restore connectivity?
Allow inbound TCP port 636 from domain controllers to each proxy server.
Allow inbound UDP port 389 from proxy servers to each domain controller.
Allow inbound TCP port 135 from domain controllers to each proxy server.
Allow outbound TCP port 443 from domain controllers to the password.azure.com endpoint.
The DC agent forwards each on-premises password change to a proxy server by using Remote Procedure Call (RPC). The proxy service listens for these RPC requests on TCP port 135 (and the associated dynamic RPC range). If port 135 is blocked, the agent cannot contact the proxy and the password is not evaluated against Microsoft Entra Password Protection policies. Allowing inbound TCP 135 from domain controllers to every proxy server re-establishes the required channel. Port 443 is only needed outbound from the proxy to Microsoft Entra cloud services, and ports 389 or 636 (LDAP/LDAPS) are not used in this workflow.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Entra Password Protection?
Open an interactive chat with Bash
How does the DC agent communicate with the proxy service in Microsoft Entra Password Protection?
Open an interactive chat with Bash
Why is TCP port 135 essential for Entra Password Protection functionality?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .