exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 3 question 38 discussion

Actual exam question from Microsoft's MS-100
Question #: 38
Topic #: 3
[All MS-100 Questions]

Your network contains an Active Directory forest named contoso.local.
You have a Microsoft 365 subscription.
You plan to implement a directory synchronization solution that will use password hash synchronization.
From the Microsoft 365 admin center, you successfully verify the contoso.com domain name.
You need to prepare the environment for the planned directory synchronization solution.
What should you do first?

  • A. From the public DNS zone of contoso.com, add a new mail exchanger (MX) record.
  • B. From Active Directory Domains and Trusts, add contoso.com as a UPN suffix.
  • C. From the Microsoft 365 admin center, verify the contoso.local domain name.
  • D. From Active Directory Users and Computers, modify the UPN suffix for all users.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
The on-premise Active Directory domain is named contoso.local. Therefore, all the domain users accounts will have a UPN suffix of contoso.local by default.
To enable directory synchronization that will use password hash synchronization, you need to configure the domain user accounts to have the same UPN suffix as the verified domain (contoso.com in this case). Before you can change the UPN suffix of the domain user accounts to contoso.com, you need to add contoso.com as a UPN suffix in the domain.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-userprincipalname

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 4 years, 9 months ago
Answer: B Explanation The on-premise Active Directory domain is named contoso.local. Therefore, all the domain users accounts will have a UPN suffix of contoso.local by default. To enable directory synchronization that will use password hash synchronization, you need to configure the domain user accounts to have the same UPN suffix as the verified domain (contoso.com in this case). Before you can change the UPN suffix of the domain user accounts to contoso.com, you need to add contoso.com as a UPN suffix in the domain. Reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-userprincipalname
upvoted 21 times
...
DavidSapery
Highly Voted 4 years, 11 months ago
Correct answer. It says what do you do FIRST, which is add the .com domain to the UPN suffixes. Only after you do that can you modify the users' UPN suffixes.
upvoted 13 times
...
Amir1909
Most Recent 1 year, 3 months ago
B is correct
upvoted 1 times
...
KennethYY
1 year, 10 months ago
maybe outdate, even the UPN is not routable DNS, Azure AD connect still can sync, just cannot SSO
upvoted 1 times
...
mikl
4 years, 1 month ago
Think "B. From Active Directory Domains and Trusts, add contoso.com as a UPN suffix." is correct.
upvoted 2 times
...
Parvezg
4 years, 2 months ago
It's B. add contoso.com as a UPN suffix and then update users with new upn (contoso.com) before kicking off AAD connect installation.
upvoted 2 times
...
mkoprivnj
4 years, 4 months ago
B. add contoso.com as a UPN suffix
upvoted 2 times
...
ExamTopic
4 years, 11 months ago
https://docs.microsoft.com/en-us/office365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago