exam questions

Exam AZ-103 All Questions

View all questions & answers for the AZ-103 exam

Exam AZ-103 topic 5 question 10 discussion

Actual exam question from Microsoft's AZ-103
Question #: 10
Topic #: 5
[All AZ-103 Questions]

HOTSPOT -
Your network contains an Active Directory domain named contoso.com that is synced to an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. The tenant contains only default domain names.
The domain contains the users shown in the following table.

The users have value sets for their user account as shown in the following table.

You plan to enable Azure Multi-Factor Authentication (MFA) by using the following bulk update file named File1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Yes -

Box 2: Yes -
Phone number is required for MFA.

Box 3: No -
Phone number for User3 is already available.
Reference:
https://docs.microsoft.com/en-us/office365/admin/security-and-compliance/set-up-multi-factor-authentication

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kikota12
Highly Voted 5 years, 1 month ago
Please if you’re not sure don’t talk, you’re confusing people
upvoted 45 times
senseibrutal
5 years ago
so its no no yes?
upvoted 3 times
...
...
Sheru
Highly Voted 5 years, 1 month ago
Tried it Its No, No, Yes. Bul update does not accept Distinguished Names. Also, the question says 'tenant contains only default domain names' which is @contoso.onmicrosoft.com
upvoted 35 times
Fala_Fel
4 years, 11 months ago
As AD has already synced contoso.com must be one of the default names?
upvoted 1 times
Fala_Fel
4 years, 11 months ago
Sorry ignore that, you can sync users without adding a custom domain.
upvoted 1 times
...
...
...
tashakori
Most Recent 1 year, 2 months ago
No No Yes
upvoted 1 times
...
Sunnyb
2 years, 7 months ago
Answer is Yes, No, No For the 2nd box, you can assign MFA either via email or phone number. Its not a must that a phone number will be included. This is what I do everyday at work.
upvoted 1 times
...
KenZx
4 years, 6 months ago
N N Y because On cloud we use domain onmicrosoft.com
upvoted 2 times
...
Aki_Aeshan
4 years, 6 months ago
I strongly agree to the GIVEN ANSWER. Here's why; Question is saying = Your network contains an Active Directory domain named contoso.com that is SYNCED to an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. This means its already happening. For you to achieve the sync operation between AD On-prem to Azure AD one of the requirements for you to achieve it is "adding custom domain" Here's reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-prerequisites You don't need to worry anymore if AD on-prem will work for this scenario.
upvoted 1 times
Aki_Aeshan
4 years, 6 months ago
About adding phone number. Question is also saying how the USER will successfully enabled the MFA. During MFA verification, user need to provide phone number to use. If not, enabling MFA from user side will fail.
upvoted 2 times
...
...
Thi
4 years, 7 months ago
I will go for No,No,Yes
upvoted 1 times
...
Chris78
4 years, 8 months ago
1 - It needs your domain account in the form of [email protected] 2 - When you enroll your device it does not ask you for your telephone number but it ask you what do you prefer, if you select Microsoft Authenticator App, it DOES NOT need your number. 3- same as 1st. It needs your domain name in the form of [email protected]. So its Y-N-N
upvoted 1 times
...
megaejay
4 years, 9 months ago
It's No No Yes
upvoted 1 times
...
Xtian_ar
4 years, 10 months ago
I think that the correct is N,N,Y, because the problem is that the statement are saying that the users have only default domain names, so, the domain name contoso.com is only available on-premise, not in cloud.
upvoted 4 times
...
Ralgh
4 years, 10 months ago
confusing one this , NNY OR YYN??, one has 18 votes the other has 15 votes. Which formatting will allow MFA to work?
upvoted 1 times
Ralgh
4 years, 10 months ago
I meant NNY OR YNN
upvoted 1 times
Opsho
4 years, 10 months ago
According to this; its YNN. But i am as confused as everyone; https://vceguide.com/hotspot-738/
upvoted 1 times
...
HeIsCorrect
4 years, 9 months ago
Better go for all N so that atleast 2 answers will be correct
upvoted 13 times
Gizdagyerek
4 years, 9 months ago
You're damn right! :d
upvoted 2 times
...
...
...
...
allray15
4 years, 10 months ago
The question is tricky How can you SUCCESSFULLY enable MFA without having a number?? Yes you can enable it but eventually users will still be prompt to fill it in after that then the MFA is successfully enabled. So setting up MFA successfully user requires to enable atleast 2 authenticating method whether its an Authenticator app , token , SMS or Call (which basically needs a phone number)
upvoted 3 times
...
Rajat0702
4 years, 10 months ago
Catch is "successfully " enable... 2nd can be enabled without phone number but not a successful operation.. To make it successful , we need to have phone number enabled... Trying to justify exmtopic answer :) as all answers above are confusing.
upvoted 3 times
...
vtech
4 years, 10 months ago
Some ppl are just here to confuse ppl
upvoted 21 times
...
GParreiras
4 years, 11 months ago
No, No, Yes
upvoted 4 times
...
Shades
4 years, 11 months ago
No: We cant used the domain name of On Prem AD unless the UPN suffix match one of the custom domains in Azure AD. So during setting up AD connect , we must specify the custom domain in Azure AD & map it to On prem Domain. If we skip this step we cant use the same domain name as of On Prem to authenticate to Azure AD , even though it may be in sync .In this case no custom d0main was created. https://www.codetwo.com/admins-blog/how-to-sync-on-premises-active-directory-to-azure-active-directory-with-azure-ad-connect/ No : I think we can use any other software if not phone number for MFA auth Yes : Since the default domain name of Azure AD is needed for authentication , On proem domain name will not work.
upvoted 8 times
Shades
4 years, 10 months ago
Check this link: https://www.ecanarys.com/Blogs/ArticleID/234/How-to-Sync-On-premise-AD-with-Windows-Azure-AD-using-Azure-AD-Connect-tool Here his AD on Premise was quest.com. He created 2 users , however when he synced to azure they had the same name but different domain...(something.onmicorosoft.com)..so that indicates when he would try to enable MFA , he will get the user name as something.on.microsoft.com..you can try thins by going to Azure AD-->All User-->Click on MultiFact authentication-->User setting
upvoted 1 times
...
...
macco455
5 years ago
Based on this: https://intrinium.com/o365mfa-2/ I am going with Yes, NO, No. As you can see the file in this link is showing the [email protected] with no phone number. So adding phone number is not needed also using the onmicrosoft.com domain is not needed either as the @domain.com is already in the file.
upvoted 2 times
jamesej_2020
4 years, 11 months ago
u can add the phone number later
upvoted 1 times
jamesej_2020
4 years, 11 months ago
correction. it ried it on my end. u can enable mfa using bulk without adding mobile . However when u signed in to portal.office.com u are prompted to select authentication method and it required u to put a phone number. so i order to successfully enable MFA u will need a phone number.
upvoted 1 times
jamesej_2020
4 years, 11 months ago
Remember the difference between enabled and enforced status in MFA.
upvoted 2 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...