Microsoft 365 Administrator Expert MS-102 Practice Question
Your organization's Microsoft Entra tenant is federated with an on-premises AD FS farm, and users currently authenticate to Microsoft 365 through AD FS. You plan to roll out passwordless sign-in by using FIDO2 security keys for Microsoft 365 web applications. To meet this goal while avoiding forced password changes and still allowing AD FS to service legacy on-premises apps, which change must you make in Microsoft Entra ID before enabling the FIDO2 authentication method?
Enable WebAuthn authentication on the AD FS farm and publish the WebAuthn endpoints to the Internet.
Configure Microsoft Entra certificate-based authentication and upload the organization's root certification authorities.
Convert the domain from federated to managed and enable Password Hash Synchronization in Microsoft Entra Connect.
Turn on security defaults in the Microsoft Entra tenant.
FIDO2 security keys are supported only when Microsoft Entra ID performs the primary authentication. Tenants that remain in a federated state with AD FS cannot use FIDO2. Converting the domain from federated to managed and enabling Password Hash Synchronization moves cloud sign-ins to Microsoft Entra ID while syncing credential hashes, so users keep their current passwords and AD FS can still be used for other on-premises applications if required. Simply enabling WebAuthn on AD FS, configuring certificate-based authentication, or turning on security defaults does not satisfy the prerequisite for FIDO2 in Microsoft Entra ID.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a managed domain and a federated domain in Microsoft Entra ID?
Open an interactive chat with Bash
What is Password Hash Synchronization in Microsoft Entra Connect?
Open an interactive chat with Bash
How do FIDO2 security keys improve authentication in Microsoft Entra ID?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .