exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 27 discussion

Actual exam question from Microsoft's MS-102
Question #: 27
Topic #: 1
[All MS-102 Questions]

Your network contains an on-premises Active Directory domain named contoso.local. The domain contains five domain controllers.
Your company purchases Microsoft 365 and creates an Azure AD tenant named contoso.onmicrosoft.com.
You plan to install Azure AD Connect on a member server and implement pass-through authentication.
You need to prepare the environment for the planned implementation of pass-through authentication.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From a domain controller, install an Authentication Agent.
  • B. From the Microsoft Entra admin center, configure an authentication method.
  • C. From Active Directory Domains and Trusts, add a UPN suffix.
  • D. Modify the email address attribute for each user account.
  • E. From the Microsoft Entra admin center, add a custom domain name.
  • F. Modify the User logon name for each user account.
Show Suggested Answer Hide Answer
Suggested Answer: CEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
certma2023
Highly Voted 1 year, 6 months ago
Selected Answer: CEF
I Agree. As the local ADDS name is "contoso.local", we need to make some few steps/prerequisites before being able to set up account synchronization: -> Add a custom domain name on the Azure AD / MS Entra portal (ex. contoso.com) -> Add a local UPN suffix at the ADDS Forest level (contoso.com) -> Modify all user account UPN from [email protected] to [email protected] Then comes the Azure AD Connect deployment & the PTA configuration.
upvoted 35 times
GLLimaBR
10 months ago
I agree. I just disagree with this option: "Modify the User logon name for each user account". In fact, we change the "User logon name" domain. From my point of view, this option implies that the login name will be changed, but in reality, it is the domain.
upvoted 3 times
...
WORKTRAIN
1 year, 3 months ago
I agree. The question should be changed to "Which three actions you should do first?".
upvoted 4 times
...
...
Casticod
Highly Voted 1 year, 5 months ago
Real Question in exam
upvoted 8 times
Cryptosuri
9 months, 3 weeks ago
Then in the real exam are you supposed to put exam topics's answer or the "real" answer ? (real question too ^^)
upvoted 4 times
...
...
khangkowng1
Most Recent 3 days, 1 hour ago
Selected Answer: ACE
CHATGPT - Why not the other options? B. Configure an authentication method in Entra ID ❌ Authentication methods in Entra ID are for MFA, passwordless authentication, and SSPR, not PTA setup. D. Modify the email address attribute for each user account ❌ The email attribute (mail) is not used for authentication. Instead, UPN should match the verified domain. F. Modify the User logon name for each user account ❌ Changing User logon name (sAMAccountName) is not needed. You only need to update UPNs to match the verified domain.
upvoted 1 times
...
AK_1234
1 month, 1 week ago
Selected Answer: ABE
A , B , E
upvoted 1 times
...
Kock
1 month, 2 weeks ago
Selected Answer: ABE
A. From a domain controller, install an Authentication Agent. B. From the Microsoft Entra admin center, configure an authentication method. E. From the Microsoft Entra admin center, add a custom domain name https://learn.microsoft.com/pt-br/entra/identity/hybrid/connect/how-to-connect-pta-quick-start https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-quick-start
upvoted 1 times
...
Frank9020
3 months ago
Selected Answer: ACE
the three most essential actions: A. From a domain controller, install an Authentication Agent. C. From Active Directory Domains and Trusts, add a UPN suffix. E. From the Microsoft Entra admin center, add a custom domain name.
upvoted 3 times
...
MR_Eliot
5 months ago
Selected Answer: CEF
CEF. You should not install Authetication Agent on a domain controller. You can, but you really should not.
upvoted 4 times
...
The_W_Man21
5 months, 2 weeks ago
To prepare your environment for implementing pass-through authentication with Azure AD Connect, you should perform the following actions: From a domain controller, install an Authentication Agent (Option A). This agent is necessary for pass-through authentication to work. From Active Directory Domains and Trusts, add a UPN suffix (Option C). This ensures that user principal names (UPNs) in your on-premises AD match the domain name in Azure AD. From the Microsoft Entra admin center, add a custom domain name (Option E). This allows users to sign in with their custom domain rather than the default onmicrosoft.com domain. These steps will help you set up the necessary components for pass-through authentication
upvoted 3 times
...
certifexams
6 months, 3 weeks ago
Copilot answer ABE : To prepare the environment for implementing pass-through authentication, follow these steps: 1. Install an Authentication Agent: From a domain controller, install the Azure AD Connect Authentication Agent (also known as Microsoft Entra Connect) on a member server. This agent facilitates pass-through authentication by validating user passwords directly against the on-premises Active Directory1. Ensure that the server running the Authentication Agent is running Windows Server 2016 or later and has TLS 1.2 enabled. 2. Configure an Authentication Method: In the Microsoft Entra admin center, configure pass-through authentication as the authentication method for your Azure AD tenant. This allows users to sign in to both on-premises and cloud-based applications using the same passwords1. Specify the on-premises account for connectivity during the configuration process. 3. Add a Custom Domain Name: In the Microsoft Entra admin center, add one or more custom domain names to your Azure AD tenant. Users can sign in using these domain names1.
upvoted 2 times
...
dvmhike
9 months, 1 week ago
Option C (adding a UPN suffix) is not necessary for implementing pass-through authentication.
upvoted 1 times
...
Scotte2023
9 months, 2 weeks ago
Selected Answer: ABE
I`m going to say A.B, E as the question mentions preparation for PTA, this article helped me decide on this outcome. https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-quick-start
upvoted 2 times
...
GLLimaBR
10 months ago
I am under the impression that this question should refer to Microsoft Entra Cloud Sync and not Microsoft Entra Connect (previously called "Azure AD Connect"). I also noticed that the "Modify user logon name for each user account" option is incorrect. In fact, we changed the "User Login Name". However, this option tricks us into thinking that the login name needs to be changed, but in reality it is the domain that needs to be changed.
upvoted 1 times
...
Motanel
10 months, 1 week ago
Selected Answer: ACE
A and E is definitely correct at least. B is not correct because you configure this in Entra ID Prior to enabling Pass-through Authentication through Microsoft Entra Connect with Step 2, download the latest release of the PTA agent from the Microsoft Entra admin center. You need to ensure that your agent is versions 1.5.1742.0. or later. To verify your agent see Upgrade authentication agents After downloading the latest release of the agent, proceed with the below instructions to configure Pass-Through Authentication through Microsoft Entra Connect. https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-quick-start
upvoted 1 times
...
Motanel
10 months, 1 week ago
Prior to enabling Pass-through Authentication through Microsoft Entra Connect with Step 2, download the latest release of the PTA agent from the Microsoft Entra admin center. You need to ensure that your agent is versions 1.5.1742.0. or later. To verify your agent see Upgrade authentication agents A and E is definitely correct at least. B is not correct because you configure this in Entra ID After downloading the latest release of the agent, proceed with the below instructions to configure Pass-Through Authentication through Microsoft Entra Connect.
upvoted 1 times
...
Sesbri
1 year ago
I think the shown answers are correct as in MS exam language I think they will focus on what is to do to be ready for PTA: https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-quick-start
upvoted 1 times
...
Sesbri
1 year ago
For me the answer shown is correct. We're not talking about user preparation we're talking about infrastructural requirements. For reference see here: https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-quick-start
upvoted 1 times
...
cpaljchc4
1 year, 1 month ago
Selected Answer: CEF
https://www.examtopics.com/discussions/microsoft/view/52600-exam-ms-100-topic-4-question-9-discussion/
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago