exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 53 discussion

Actual exam question from Microsoft's MS-500
Question #: 53
Topic #: 1
[All MS-500 Questions]

Your network contains an on-premises Active Directory domain and a Microsoft 365 subscription.
You plan to deploy a hybrid Azure Active Directory (Azure AD) tenant that has Azure AD Identity Protection risk policies enabled.
You need to configure Azure AD Connect to support the planned deployment.
Which Azure AD Connect authentication method should you select?

  • A. Federation with AD FS
  • B. Federation with PingFederate
  • C. Password Hash Synchronization
  • D. Pass-through authentication
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
xyz213
Highly Voted 2 years, 10 months ago
Selected Answer: C
One of the protection risk policies is a “Use risk policy”. It will require a password change. For this to work in a hybrid environment: Make sure you have PHS, Password Writeback and SSPR enabled
upvoted 12 times
...
Ivkopivko12tka
Highly Voted 2 years, 7 months ago
Selected Answer: C
Honestly, I don't understand the fact that answers to such trivial questions are wrong. This exam is full of wrong answers, any idea how to change it?
upvoted 8 times
RomanV
2 years, 2 months ago
To learn and tackle them yourself. This is challenging us and keeping us awake :)
upvoted 1 times
...
...
GPerez73
Most Recent 2 years, 2 months ago
Selected Answer: C
I have a lab with an hybrid enviroment and I don't need ADFS to use risk sign in policies. So it is C
upvoted 1 times
...
GatesBill
2 years, 3 months ago
Correct answer should be C indeed. Password writeback should be enabled as stated also in the following article: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies#choosing-acceptable-risk-levels
upvoted 2 times
examdj101j
2 years, 2 months ago
Should be C, there's documented proof that A is the correct answer. So community answer it is, this is probably taken out of the Exam as I took it 2 weeks ago and failed, don't remember this one
upvoted 1 times
examdj101j
2 years, 2 months ago
I meant to say there is no documented proof that A is correct
upvoted 1 times
...
...
...
ajjihad1
2 years, 4 months ago
To support the deployment of a hybrid Azure Active Directory (Azure AD) tenant with Azure AD Identity Protection risk policies enabled, you should use the "Pass-through Authentication" (PTA) method in Azure AD Connect. PTA is a simple and secure authentication method that allows users to use their on-premises passwords to authenticate with Azure AD. When users sign in to Azure AD-connected applications, their passwords are validated against your on-premises Active Directory, so there's no need to store passwords in the cloud. Additionally, PTA supports the use of Azure AD Identity Protection risk policies, which help to detect and prevent risky sign-ins. The other two authentication methods in Azure AD Connect are "Password Hash Synchronization" and "Active Directory Federation Services" (AD FS). While both of these methods are also compatible with Azure AD Identity Protection, PTA is the recommended method for its simplicity and security benefits. So, you should select the "Pass-through Authentication" option when configuring Azure AD Connect for your hybrid deployment.
upvoted 3 times
...
Eve123
2 years, 5 months ago
Optionally, you can set up password hash synchronization as a backup if you decide to use Federation with Active Directory Federation Services (AD FS) as your sign-in method. https://learn.microsoft.com/en-us/azure/active-directory/hybrid/whatis-phs
upvoted 1 times
...
examdog
2 years, 6 months ago
Selected Answer: C
When using Federation, the authentication is done on-prem. So C is the answer.
upvoted 3 times
...
foster1
2 years, 6 months ago
Pretty sure thats C
upvoted 2 times
...
VJO
2 years, 7 months ago
Federation for AD FS allows for more rigorous levels of access controls. This is a requirement in the question regarding risk policies. Password Hash is a part of Federation for AD FS if needed.
upvoted 1 times
...
ccadenasa
2 years, 7 months ago
C is the correct answer for sure
upvoted 1 times
...
HartMS
2 years, 8 months ago
Selected Answer: C
C for Sure
upvoted 2 times
...
SDK91
2 years, 8 months ago
Selected Answer: C
Makes more sense
upvoted 2 times
...
mohamed_Saed
2 years, 8 months ago
Selected Answer: C
c is more likely
upvoted 4 times
...
01001010101
2 years, 8 months ago
So what is valid on the exam??
upvoted 1 times
...
JimboJones99
2 years, 9 months ago
Selected Answer: C
PHS makes the most sense for this scenario
upvoted 1 times
...
LittleScratch
2 years, 10 months ago
Selected Answer: C
Agree with Dan91 & Pete26
upvoted 3 times
...
pete26
2 years, 10 months ago
Selected Answer: C
One of the protection risk policies is a “Use risk policy”. It will require a password change. For this to work in a hybrid environment: Make sure you have PHS, Password Writeback and SSPR enabled. I will go with PHS for an answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...