exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 34 discussion

Actual exam question from Microsoft's MS-500
Question #: 34
Topic #: 1
[All MS-500 Questions]

HOTSPOT -
Your network contains an on-premises Active Directory domain that syncs to Azure Active Directory (Azure AD) as shown in the following exhibit.

The synchronization schedule is configured as shown in the following exhibit.

Use the drop-down menus to select the answer choice that answers each question based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
paperinop541
Highly Voted 4 years, 1 month ago
for me the correct answers are: option 2 for the first question : azure ad account (cloud only) can also authenticate on Azure AD option 2 for the secondo question.
upvoted 32 times
Vexix
2 years, 4 months ago
But the option 2 means that employee must have both accounts. Employees who have cloud account AND synced account, not OR. Bit of a trick answer and how you interpret the question.
upvoted 1 times
msysadmin
2 years, 4 months ago
I agree with paperinop541. It not saying both account, if it say like via Azure AD Connect then it will be right. Azure AD mean, it does not matter user synced from on-prem or registered on Cloud. Need to focus to question.
upvoted 2 times
...
...
...
gisbern
Highly Voted 4 years, 2 months ago
PTA authentication is used, so whenever account is synced from local AD, logon process for them requires active PTA agent to contact domain controller. So only Azure AD users are able to log in while PTA agent is not working properly. Am I missing something?
upvoted 13 times
Trevor
3 years, 5 months ago
You are required to have PTA agent HA to remove warnings if it goes down. Install 2 agents.. its a warning question.
upvoted 4 times
...
gisbern
4 years, 2 months ago
I meant only users created in Azure AD can authenticate against Azure AD, for synced users they will be sent via PTA agent to local AD. Second answer is correct, AAD Connect is in maintenance mode, and changes has to be confirmed before next sync is able to run.
upvoted 3 times
EzeQ
3 years, 7 months ago
But the ash sync is enabled, doesn't that count for something?
upvoted 2 times
EzeQ
3 years, 7 months ago
I reminded that might be just got password reset
upvoted 1 times
...
Bouncy
3 years, 2 months ago
No, it doesn't: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq Does password hash synchronization act as a fallback to Pass-through Authentication? No. Pass-through Authentication does not automatically failover to password hash synchronization.
upvoted 4 times
...
...
...
Anonymousse
2 years, 8 months ago
https://cloudacademy.com/blog/azure-hybrid-identity-authentication-methods/
upvoted 1 times
...
...
Orion8575
Most Recent 2 years ago
Correct answer is 1-1 and 2-2 because it says that it did not sync for 4h, which means that if Azure AD Connect stops syncing, PTA functionality may be impacted. Users may experience issues logging in to Microsoft 365 as the authentication requests won't be processed against the on-premises directory.
upvoted 2 times
...
ChachaChatra
2 years, 4 months ago
Valid on 28/01/2023
upvoted 3 times
...
zerrowall
2 years, 5 months ago
PTA is not now working due to 4 hours last time sync when the interval is only 30 minutes. At the same time, Pass-through Authentication does not automatically failover to password hash synchronization, look here https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq#does-password-hash-synchronization-act-as-a-fallback-to-pass-through-authentication- In this case, only AAD users can authenticate. This is 1st answer to the 1st question. Regarding the 2nd question, we need to fix a problem and add an additional agent for HA to avoid warning. So the answer here is 2. Eventually: 1 - 1 2 - 2
upvoted 4 times
...
bac0n
2 years, 6 months ago
I see no reason whatsoever why an Azure AD account would not be able to sign in if there were any issues on-prem. I'm going with 2 and 2.
upvoted 4 times
...
gaida
2 years, 7 months ago
Only on prem synced ac can authenticate as it uses passthrough auth instead of PHS. Agent status has warning which is a key service for PTA. Ans is correct.
upvoted 2 times
...
pete26
2 years, 8 months ago
Valid on exam October 14, 2022
upvoted 4 times
...
SKam22
2 years, 10 months ago
According to the screenshot the AAD Connect sync stopped working but it synced before so the on-prem user and password databse were synced to AAD. Users who were already synced to AAD and all AAD users can still login to Azure AD. PTA agent is still running and can validate the password policies. I would pick option 2 for Q1.
upvoted 1 times
...
ndilru
3 years, 2 months ago
3 ways of connecting your workstations to Microsoft Azure * Azure AD Registered - BYOD concept, user can use a local account to log in and still use corporate 365 services with SSO * Azure AD Joined - when configured users have to use [email protected] to login to their PC * Hybrid Azure AD Joined - user has to provide a local domain username to access the PC. So the question is, which employees can authenticate by using Azure AD? according to the screenshot, we can see this is a hybrid setup, so the on-prem DC will be the primary authentication point. So the answer is Only employees who have an on-premises account. Note: they can also use Aure AD creds to access portal.office.com when they log in to the workstation inside.
upvoted 3 times
...
kanew
3 years, 4 months ago
I make it option 2 for both answers and even though I have worked with this for years I had to Lab it up to be sure (and still the MS wording is tricky!) Firstly, even tho the sync server hasn't synced for hours the PTA agent still works ( i tested this) so users with an AD synced a/c can still authenticate by logging in via AAD. The agent will still pick up their creds from the service bus. AAD users authenticate directly against AAD anyway so they can as well. Second Question - Adding a second PTA authentication agent does fix the warning as everyone has said (tested). However, running start-AdSyncSyncCycle give an error if the AAD config wizard has been left open(the most likely problem and also tested) so only option 2 is correct.
upvoted 9 times
...
martinods
3 years, 4 months ago
Azure AD account ( cloud only) and synced account can authenticate
upvoted 1 times
...
mbecile
3 years, 5 months ago
Question 1 = Answer 3, Only Synced On-Prem accounts can authenticate with Azure AD to sign into their On-Prem domain. Answer 2 is incorrect because it states that they also need an Azure account on top of their synced On-Prem account, when they only require the latter, not both. Question 2 (and it's answers) didn't make the most sense for me, so I'm going with the flow for that one and going with their answer.
upvoted 3 times
...
martinods
3 years, 5 months ago
Q1 = Answer 2, because no information we have regarding the PTA agent malfunction. the only information is 1 PTA agent is present, the warning means no other PTA agent ( 2 agent are required for HA)
upvoted 1 times
Bouncy
3 years, 2 months ago
Yes we do have that information: last sync 4 hours ago while sync period is set to 30 minutes -> PTA agent server is unavailable
upvoted 2 times
...
...
kakakayayaya
3 years, 5 months ago
Vague question. If user has 2 accounts: AAD and synced on-perm he/she can use any of this account lo login.
upvoted 1 times
...
FredC
3 years, 6 months ago
If password hash sync is enabled then i'm pretty sure that azure ad is the authenticating local ad accounts on its own so i believe the given answers here are correct
upvoted 1 times
...
mkoprivnj
3 years, 6 months ago
1st: 1st answer 2nd: 2nd answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...