exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 15 question 1 discussion

Actual exam question from Microsoft's MS-100
Question #: 1
Topic #: 15
[All MS-100 Questions]

HOTSPOT -
You create the Microsoft 365 tenant.
You implement Azure AD Connect as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
In the exhibit, seamless single sign-on (SSO) is disabled. Therefore, as SSO is disabled in the cloud, the Sales department users can access only on-premises applications by using SSO.
In the exhibit, directory synchronization is enabled and active. This means that the on-premises Active Directory user accounts are synchronized to Azure Active
Directory user accounts. If the on-premises Active Directory becomes unavailable, the users can access resources in the cloud by authenticating to Azure Active
Directory. They will not be able to access resources on-premises if the on-premises Active Directory becomes unavailable as they will not be able to authenticate to the on-premises Active Directory.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Amir1909
1 year, 4 months ago
- both on-permiss and cloud-based - on-permiss only
upvoted 1 times
...
Davidchercm
3 years, 5 months ago
what is the correct answer ? it should be using PHS right ?
upvoted 1 times
...
junior6995
3 years, 9 months ago
Kind of funny, you Turn on PSH but you disable SSO. wft?
upvoted 3 times
jkklim
3 years, 6 months ago
why cannot ?
upvoted 1 times
...
Startkabels
2 years, 7 months ago
Enabling SSO in the cloud doesnt mean it can be/is used. PHS means the on-prem pw is synced and required to signin when AD is offline.
upvoted 1 times
Paolo2022
2 years, 6 months ago
As far as I understand it, Password Hash Sync does work as a high availability approach for on-prem authentication. So if on-prem AD is down, users can still sign-in to on-prem services via the AAD Connect server. Failover doesn't happen automatically, but in principle it is possible. Therefore, I would choose option 1 in box 2.
upvoted 3 times
JCkD4Ni3L
2 years, 2 months ago
I agree, here is an interesting article about it. https://www.semperis.com/blog/understanding-azure-ad-password-hash-sync/#:~:text=Microsoft%20needed%20to%20provide%20an%20easy%20way%20to,synchronize%20with%20Azure%20AD%20use%20password%20hash%20sync.
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...