exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 2 question 59 discussion

Actual exam question from Microsoft's MS-100
Question #: 59
Topic #: 2
[All MS-100 Questions]

HOTSPOT -
Your network contains an on-premises Active Directory forest named contoso.com. The forest contains the following domains:
✑ Contoso.com
✑ East.contoso.com
The forest contains the users shown in the following table.

The forest syncs to an Azure Active Directory (Azure AD) tenant named contoso.com as shown in the exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Yes -
The UPN of user1 is [email protected] so he can authenticate to Azure AD by using the username [email protected].

Box 2: No -
The UPN of user2 is [email protected] so he cannot authenticate to Azure AD by using the username [email protected].

Box 3: No -
The UPN of user3 is [email protected] so he cannot authenticate to Azure AD by using the username [email protected].

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mkuczynski
Highly Voted 4 years, 1 month ago
User1 can authenticate by on-prem AD. YNN
upvoted 10 times
...
Amir1909
Most Recent 1 year, 4 months ago
Correct
upvoted 1 times
...
One111
1 year, 9 months ago
In Active Directory, each user has two UPN's: Explicit UPN (eUPN): This is the value of the user object's userPrincipalName attribute. This can be changed to any value, regardless of any alternate UPN suffixes you have configured in the forest. Implicit UPN (iUPN): This is constructed by concatenating the value of the user object's samAccountName attribute with the value of the domain's FQDN. The FQDN is stored as the value of the dnsRoot attribute of the domain's crossRef object stored at LDAP://CN=DOMAIN_NETBIOS_NAME,CN=Partitions,CN=Configuration,DC=DOMAIN) If PtA uses AD to find user it will work for 'root domain' and 'any subdomain' within forest added as alternative suffix domain.
upvoted 1 times
...
mllerena
2 years, 5 months ago
[email protected] (Autentícate) -> UPN contoso.com -> SI [email protected] (Autentícate) -> UPN East.contoso.com -> NO [email protected] (Autentícate) -> UPN Fabrikam.com -> NO
upvoted 1 times
...
Cheekypoo
2 years, 10 months ago
Was in my exam today 05/08/22.
upvoted 1 times
...
TechMinerUK
3 years ago
I believe the answer provided is correct as from the question it appears that contoso.com is setup in AzureAD and Microsoft 365 however because the users still have their east.contoso.com and fabrikam.com set as their UPNs in Active Directory when they synchronise to AzureAD they will likely have a UPN like the bellow: %username%@contoso.onmicrosoft.com Because of this they would need to use the above username to sign in succesfully or on Active Directory they would need their UPN suffix changing to contoso.com before actioning a delta sync to update their AzureAD profiles with the correct domain for their username
upvoted 2 times
...
jjong
3 years, 9 months ago
i agree with the ans provided YNN. Box 2: No – (need to use east.contoso.com) Box 3: No – (not configured as domain on on-prem AD)
upvoted 4 times
One111
1 year, 9 months ago
Suffix is used on Azure to recognize domain and determine authentication mode, which is PtA. Lokal domain lookup for user with whatever.contoso.com\user in contoso.com forest willa be successfully completed. Questions is how PtA looks for user ,is IT by upn or samAccountName mapped (alternative suffix configuration have to applied before).
upvoted 1 times
...
...
melatocaroca
3 years, 12 months ago
The default configuration in Azure AD Connect sync assumes: Each user has only one enabled account, and the forest where this account is located is used to authenticate the user. This assumption is for password hash sync, pass-through authentication and federation. UserPrincipalName and sourceAnchor/immutableID come from this forest. Each user has only one mailbox. The forest that hosts the mailbox for a user has the best data quality for attributes visible in the Exchange Global Address List (GAL). If there's no mailbox for the user, any forest can be used to contribute these attribute values. If you have a linked mailbox, there's also an account in a different forest used for sign-in. So user 1 default user 2 and user 3 default, user 2 and 3 can not login without change their UPN
upvoted 1 times
...
PandaTuga
4 years ago
the answer for this exam is YNN But you could actually sync the 3 users with sync rule that would set all cloud UPN accounts to @contoso.com and they all will be able to sign-in that way
upvoted 2 times
...
Gus01
4 years, 1 month ago
All answers should be NO. Password Hash Sync is disabled so user1 cannot authenticate to Azure only Pass Thru is working so has to Authenticate to On Prem AD
upvoted 3 times
Lyl4ch
4 years, 1 month ago
It doesn't specify that he must use the same on-prem password.
upvoted 1 times
...
Jaxon_84
4 years, 1 month ago
Passthrough authentication is on however, so, that allows for authentication.
upvoted 6 times
J0J0
4 years ago
but not on Azure AD. Authentication happens in on-premise.
upvoted 1 times
venwaik
3 years, 11 months ago
if pass-through is on, that means that the on-prem pass-through module is installed and is communicating with Azure. Therefore, User1 can succesfully sign in with the on-prem password. Authentication for User 1 = Yes
upvoted 5 times
...
...
...
Rudelke
2 years, 11 months ago
Question asks if you can authenticate TO Azure AD (by any means). What you are thinking about is "can User one be authenticated BY Azure AD using...." Questions about who is doing the authorisation (AD vs AAD) also happen but it's not this one.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...