Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table. You configure Azure AD Connect to sync contoso.com to Azure AD. Which objects will sync to Azure AD?
It is D. Global security groups from your on-premises AD are synchronized to Azure AD, and they retain their membership and other attributes during the synchronization process. This means that if you have global security groups defined in your on-premises AD and these groups contain users or other groups, the membership information will be replicated to Azure AD.
Disabled user accounts are also synchronized: https://learn.microsoft.com/en-us/answers/questions/233667/will-azure-ad-connect-sync-disabled-user-accounts
Here's the reasoning:
Azure AD Connect synchronizes enabled user accounts and groups by default.
From the table (as described in your previous question context):
Group1 is a global security group – ✅ Syncs
User1 is an enabled user account – ✅ Syncs
User2 is a disabled user account – ❌ Does not sync by default
Therefore:
Group1: ✅ Yes
User1: ✅ Yes
User2: ❌ No
Final answer: C. Group1 and User1 only
______________________________________
Its D.
Yes, disabled accounts do get synchronized via Azure AD Connect to Azure AD. By default, Azure AD Connect will sync all objects, including those that are disabled in your on-premises Active Directory, unless they are filtered out by configuration settings
The correct answer is D. Group1, User1 and User2.
Azure AD Connect synchronizes all Active Directory objects that meet the following criteria:
Object type: Azure AD Connect synchronizes user and group objects only.
**Sync scope:** Azure AD Connect only syncs objects that are in the configured sync scope.
Sync filter: Azure AD Connect only syncs objects that meet the configured sync filters.
In the scenario described, there are no sync filters or sync scope configured. Therefore, Azure AD Connect will synchronize all user and group objects in the contoso.com domain.
Details:
Group1: It is a global security group, which is a type of object synchronized by Azure AD Connect.
User1: It is an enabled user account, which is an object type synchronized by Azure AD Connect.
User2: It is a disabled user account. Azure AD Connect syncs disabled user accounts by default.
Therefore, all three objects will be synchronized with Azure AD.
All will sync, the question has NO context whatsoever. If it mentioned filtering at all, this question would change. In my tenant, we have 2x OUs, one for shared mailbox retaining and one for fully disabled users. Remove one and keep the other to prevent sync errors
As stated here; https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/concept-azure-ad-connect-sync-user-and-contacts#disabled-accounts
The answer is D
Wrong.
Yes, disabled accounts do get synchronized via Azure AD Connect to Azure AD. By default, Azure AD Connect will sync all objects, including those that are disabled in your on-premises Active Directory, unless they are filtered out by configuration settings
Builtin security groups are listed here (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#default-active-directory-security-groups) and Global security group is not part of that list therefore it will be synchronised.
ANSWER IS D
In this conversation not much is clarified, for me the answer is B
https://www.examtopics.com/discussions/microsoft/view/48837-exam-ms-100-topic-3-question-77-discussion/
From https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/concept-azure-ad-connect-sync-user-and-contacts
Azure AD Connect excludes built-in security groups from directory synchronization.
Disabled accounts are synchronized as well to Azure AD
You're right. Group1 is definitively a custom group not a built in securtity group like "domain admins" or "enterprise admins". Therefore it should synchronize to Azure AD without any issue.
Yup, you're right. Builtin security groups are listed here (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#default-active-directory-security-groups) and Global security group is not part of that list therefore it will be synchronised.
ANSWER IS D
This section is not available anymore. Please use the main Exam Page.MS-102 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Haso
Highly Voted 1 year, 8 months agoEubertT
Most Recent 3 weeks, 1 day agoJalonso
1 month, 1 week agoKock
4 months agoOdy
5 months, 3 weeks agomikl
11 months, 4 weeks agoJamesWilliams
1 year, 1 month agobenpatto
1 year, 5 months agobenpatto
1 year, 5 months agoFestus365
1 year, 5 months agomikl
11 months, 4 weeks agoRuhansen
1 year, 7 months agoCasticod
1 year, 7 months agoTisi
1 year, 7 months agogomezmax
1 year, 8 months agomikl
11 months, 4 weeks agoMr4D97
1 year, 8 months agoCasticod
1 year, 8 months agomoshkoshbgosh
1 year, 8 months agomoshkoshbgosh
1 year, 8 months agocertma2023
1 year, 8 months agoMr4D97
1 year, 8 months ago