exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 91 discussion

Actual exam question from Microsoft's MS-102
Question #: 91
Topic #: 1
[All MS-102 Questions]

You have a hybrid deployment of Microsoft 365 that contains the users shown in the following table.

Azure AD Connect has the following settings:

Password Hash Sync: Enabled -
Pass-through authentication: Enabled
You need to identify which users will be able to authenticate by using Azure AD if connectivity between on-premises Active Directory and the internet is lost.
Which users should you identify?

  • A. none
  • B. User1 only
  • C. User1 and User2 only
  • D. User1, User2, and User3
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
certma2023
Highly Voted 1 year, 4 months ago
Selected Answer: A
I would choose A. According to the MS documentation: "Does password hash synchronization act as a fallback to Pass-through Authentication? No. Pass-through Authentication does not automatically failover to password hash synchronization. To avoid user sign-in failures, you should configure Pass-through Authentication for high availability." https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/how-to-connect-pta-faq#does-password-hash-synchronization-act-as-a-fallback-to-pass-through-authentication- Therefore, without any admin actions, authentication won't be possible for any user until the admin make some changes on the tenant.
upvoted 8 times
amurp35
1 year, 2 months ago
Correct, except for cloud-only users. Therefore, the correct answer is B.
upvoted 11 times
mikl
7 months, 1 week ago
But how come user 2 can't sign in? Passwords are hashed in the Cloud for user 2 - so should be able to logon no?
upvoted 2 times
FiRem00
4 days, 1 hour ago
No, even though it serves as a backup, PHS would need to be changed in the backend by Microsoft in order for USer2 or User3 to login that way. It's not an automatic thing, nor can it be changed by a customer
upvoted 1 times
...
...
...
...
amurp35
Highly Voted 1 year, 2 months ago
Selected Answer: B
B. Cloud user won't be affected. Why? Because Pass-through auth is ON for the on-prem soured users. Password Hash Sync is not an auto-fallback kind of a thing. Therefore, those users cannot authenticate without some work on the configuration to enable it, since the authentication happens on-prem.
upvoted 6 times
...
MR_Eliot
Most Recent 2 months, 3 weeks ago
Selected Answer: B
B is true. PTA doesn't fallback automatically to Password Hash. Since user1 is a cloud only user, user 1 will still be able to login.
upvoted 2 times
...
APK1
4 months ago
Selected Answer: B
My selection is B User 1 only. Direct authentication requires the local network to be available.
upvoted 1 times
...
blairskimo
5 months ago
Selected Answer: D
The users have been synched then connection to on prem was lost . So you cant log in to on prem but can you log in to the cloud . The question asks “You need to identify which users will be able to authenticate by using Azure AD if connectivity between on-premises Active Directory and the internet is lost. Which users should you identify?” So yes you will be able to log in to azure and seeing the creds for all three users have been synched previously then I would choose D
upvoted 2 times
...
angra01
7 months ago
Selected Answer: B
Lost connection
upvoted 1 times
...
MarcMouelle
8 months, 1 week ago
Selected Answer: B
L'utilisateur 1 uniquement. L'authentification directe nécessite que le réseau local soit disponible or le hachage dee mot de passe crypte les mots de passes et les stocke dans l' entra id
upvoted 1 times
...
nordbymikael
8 months, 3 weeks ago
Selected Answer: B
PTA works for synced users only. Cloud-native users always use Entra ID for authentication, even if PTA is enabled.
upvoted 3 times
...
Tomtom11
10 months ago
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/choose-ad-authn
upvoted 1 times
...
Tomtom11
10 months ago
https://www.reddit.com/r/Office365/comments/zqmfho/passthrough_authentication_and_password_hash/
upvoted 1 times
...
TP447
1 year, 1 month ago
Initially i thought User1 and User2 but then realised that a change would be needed to switch to PHS. User1 being cloud only wouldnt be impacted so answer is B.
upvoted 2 times
...
Snakad
1 year, 1 month ago
Chat GPT say only User1 because in the event of a connectivity loss between on-premises Active Directory and the internet, User1 will be able to authenticate using Azure AD because they are cloud-native and have the necessary authentication methods enabled. User2 may face authentication issues as they rely on on-premises AD DS for authentication, and User3 is not provisioned in Azure AD, so they won't be able to authenticate through Azure AD.
upvoted 1 times
...
MoreCertificatesForMe
1 year, 2 months ago
Selected Answer: B
Hash Sync syncs every 2 min, so if on prem communication is down i would not think that the authentication will happen
upvoted 2 times
...
AMDf
1 year, 3 months ago
Selected Answer: B
Vote for B
upvoted 3 times
...
ae88d96
1 year, 3 months ago
Selected Answer: B
Correct Answer B, Cloud User won't be affected. Tested on my lab.
upvoted 4 times
...
Carine
1 year, 3 months ago
User1 is a cloud only user, no ? So i think he will be able to authenticate by Azure AD. So B for me.
upvoted 1 times
...
gomezmax
1 year, 3 months ago
it Should be A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago