exam questions

Exam MS-900 All Questions

View all questions & answers for the MS-900 exam

Exam MS-900 topic 1 question 266 discussion

Actual exam question from Microsoft's MS-900
Question #: 266
Topic #: 1
[All MS-900 Questions]

DRAG DROP -
You have a hybrid environment that includes Microsoft Azure AD. On-premises applications use Active Directory Domain Services (AD DS) for authentication.
You need to determine which authentication methods to use.
Match each feature to its authentication source. To answer, drag the appropriate authentication sources from the column on the left to the features on the right.
Each authentication source may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DAN_17
Highly Voted 11 months, 2 weeks ago
the correct answers in my opinion are: AD DS ONLY : Being in a hybrid environment I will not perform authentication from Azure AD for windows Hello but will do it from AD onprem AZURE AD : intune is a cloud based service I cannot authenticate with Active directory on-prem AD DS and AAD : for MFA access I will use both AD and AAD based on mailbox if it is online or onprem I will still have to perform MFA authentication
upvoted 8 times
...
wando5000
Highly Voted 1 year, 7 months ago
I think the answer is correct For first part - Intune is located in Azure so Im guessing that you access intune by logging onto AAD. But also if you use configuration manager on premise then you can access Azure using comanagement "Co-management is one of the primary ways to attach your existing Configuration Manager deployment to the Microsoft 365 cloud. It helps you unlock additional cloud-powered capabilities like conditional access." https://docs.microsoft.com/en-us/mem/configmgr/comanage/overview For second part - Windows Hello lets users authenticate to: A Microsoft account. An Active Directory account. A Microsoft Azure Active Directory (Azure AD) account. Identity Provider Services or Relying Party Services that support Fast ID Online (FIDO) v2.0 authentication. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview
upvoted 6 times
wando5000
1 year, 7 months ago
as an extra note about Intune MAM policies - you need an AAD account; The following list provides the end-user requirements to use app protection policies on an Intune-managed app: The end user must have an Azure Active Directory (Azure AD) account. https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policy
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...