exam questions

Exam AZ-303 All Questions

View all questions & answers for the AZ-303 exam

Exam AZ-303 topic 1 question 51 discussion

Actual exam question from Microsoft's AZ-303
Question #: 51
Topic #: 1
[All AZ-303 Questions]

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

You plan to install Azure AD Connect and enable SSO.
You need to specify which user to use to enable SSO. The solution must use the principle of least privilege.
Which user should you specify?

  • A. User3
  • B. User2
  • C. User1
  • D. User4
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
You need to have domain administrator credentials for each Active Directory forest that:
✑ You synchronize to Azure AD through Azure AD Connect.
✑ Contains users you want to enable for Seamless SSO.
Note: The domain administrator credentials are not stored in Azure AD Connect or in Azure AD. They're used only to enable Seamless SSO through Azure AD
Connect.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jasu
Highly Voted 4 years, 3 months ago
It's correct. Set up domain administrator credentials: You need to have domain administrator credentials for each Active Directory forest that: You synchronize to Azure AD through Azure AD Connect. Contains users you want to enable for Seamless SSO.
upvoted 36 times
abhishek_arya02
3 years, 10 months ago
But the question is not to install but to enable sso and for that domain user should be sufficient
upvoted 4 times
...
qerem
3 years, 11 months ago
A is correct . Link: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
upvoted 3 times
NigHtHunter2000
3 years, 5 months ago
According to your link ; "The domain administrator credentials are not stored in Azure AD Connect or in Azure AD. They're used only to enable the feature." (feature here means Enabling SSO) So its domain admins
upvoted 2 times
...
rdemontis
3 years, 9 months ago
According to this document the answer is clearly C, domain admins
upvoted 1 times
...
qerem
3 years, 11 months ago
I mean C*
upvoted 1 times
P1mp
3 years, 11 months ago
You are wrong, A is the correct answer: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start Scroll down til you see or search for *Set up domain administrator credentials
upvoted 2 times
certpro
3 years, 11 months ago
according to the link provided by qerem, answer is C , "Domain Admins"
upvoted 2 times
...
...
...
...
...
jd94
Highly Voted 3 years, 10 months ago
6/12/2021. Passed the exam. Domain user
upvoted 8 times
...
KemalM
Most Recent 3 years, 2 months ago
Selected Answer: C
Domain Admin for sure
upvoted 1 times
...
moon2351
3 years, 2 months ago
Selected Answer: C
Answer is C
upvoted 1 times
...
Klotting
3 years, 3 months ago
It’s so nice that given answer is correct
upvoted 1 times
...
Nands23
3 years, 4 months ago
This was on today's exam. 12/29/2021 There was change in option. Last option was ENTERPRISE ADMINS. I selected Domain Admins and passed exam with 8XX
upvoted 1 times
...
quantumray
3 years, 4 months ago
Question appeared On AZ-303 exam on 08/12/2021 - 49 questions, 4Q - Fabrikan case study
upvoted 1 times
17Master
3 years, 4 months ago
Which is the answer?. Whenever AD Connect is installed I use to create an account automatically and I have never tried the option.
upvoted 1 times
...
...
Deepak350
3 years, 5 months ago
answer should be domain user. As of build 1.4.18.0, you can't use an enterprise admin or domain admin account as the Azure AD DS connector account. When you select Use existing account, if you try to enter an enterprise admin account or a domain admin account, you see the following error: "Using an Enterprise or Domain administrator account for your AD forest account is not allowed. Let Azure AD Connect create the account for you or specify a synchronization account with the correct permissions."
upvoted 5 times
JeeBee
3 years, 3 months ago
Completely irrelevant, question is NOT about service account to use
upvoted 1 times
...
...
VT1100
3 years, 6 months ago
The answer is "C"/User 1. If you follow the link, it states: Continue through the wizard until you get to the Enable single sign on page. Provide domain administrator credentials for each Active Directory forest that: You synchronize to Azure AD through Azure AD Connect. Contains users you want to enable for Seamless SSO. After completion of the wizard, Seamless SSO is enabled on your tenant.
upvoted 2 times
...
syu31svc
3 years, 8 months ago
Answer is C User1 is a domain admin. You need to have domain administrator credentials for each Active Directory forest that: · You synchronize to Azure AD through Azure AD Connect. · Contains users you want to enable for Seamless SSO. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
upvoted 2 times
...
WChandra
3 years, 9 months ago
Provide domain administrator credentials for each Active Directory forest that: You synchronize to Azure AD through Azure AD Connect. Contains users you want to enable for Seamless SSO. The domain administrator credentials are not stored in Azure AD Connect or in Azure AD. They're used only to enable the feature.
upvoted 1 times
...
AAPaul
3 years, 9 months ago
I had this question in the exam that i took on July 14th 2021
upvoted 2 times
...
AravindITGuy
3 years, 10 months ago
Took exam today passed this morning was on there 6/21/2021
upvoted 2 times
...
DragonsGav
3 years, 10 months ago
User1 is the correct answer. (Reference : https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#create-the-computer-account-in-active-directory)
upvoted 1 times
...
nfett
3 years, 10 months ago
C appears to be the correct answer per their provide URl.
upvoted 1 times
...
wardy1983
3 years, 11 months ago
Its domain admin https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom
upvoted 1 times
...
QiangQiang
3 years, 11 months ago
it should be B. domain user. the question asks "You need to specify which user to use to enable SSO", not the user installing AD connect which should be Enterprise Admin. As of build 1.4.18.0, you can't use an enterprise admin or domain admin account as the Azure AD DS connector account. When you select Use existing account, if you try to enter an enterprise admin account or a domain admin account, you see the following error: "Using an Enterprise or Domain administrator account for your AD forest account is not allowed. Let Azure AD Connect create the account for you or specify a synchronization account with the correct permissions."
upvoted 3 times
pentium75
3 years, 9 months ago
But the question is not about the user required for sync, but which user is required to 'enable SSO'. And THAT must be Domain Admin (or Enterprise Admin in a multi-domain forest).
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago