exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 4 question 10 discussion

Actual exam question from Microsoft's MS-100
Question #: 10
Topic #: 4
[All MS-100 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company plans to deploy several Microsoft Office 365 services.
You need to design an authentication strategy for the planned deployment. The solution must meet the following requirements:
✑ Users must be able to authenticate during business hours only.
✑ Authentication requests must be processed successfully if a single server fails.
✑ When the password for an on-premises user account expires, the new password must be enforced the next time the user signs in.
✑ Users who connect to Office 365 services from domain-joined devices that are connected to the internal network must be signed in automatically.
Solution: You design an authentication strategy that contains a pass-through authentication model. The solution contains two servers that have an Authentication
Agent installed and password hash synchronization configured.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
This solution meets the following goals:
✑ Users must be able to authenticate during business hours only.
✑ Authentication requests must be processed successfully if a single server fails.
✑ When the password for an on-premises user account expires, the new password must be enforced the next time the user signs in.
However, the following goal is not met:
Users who connect to Office 365 services from domain-joined devices that are connected to the internal network must be signed in automatically.

You would need to configure Single-sign on (SSO) to meet the last requirement.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kanag1
3 years, 3 months ago
Doesn't it work with ADFS configuration? Anyways the answer is NO
upvoted 1 times
kanag1
3 years, 3 months ago
Passthru with SSO is the answer. Please read the next question.
upvoted 1 times
...
...
JEricThomas610
3 years, 4 months ago
The part about preventing users from logging in was not covered in this solution.
upvoted 2 times
One111
2 years, 4 months ago
PtA respects any limitations on signing in that is applied to domain controllers or users. If you are allowed to sign in only in working hours PtA will do it.
upvoted 1 times
...
...
Eric_
3 years, 5 months ago
Question: how does this configuration prevent logons outside business-hours?
upvoted 4 times
sliix
3 years, 2 months ago
As PTA uses on-prem AD, you can limit the logins outside business hour by opening the user profile settings in ADUC.
upvoted 4 times
...
...
maxustermann
3 years, 5 months ago
Correct, SSO is missing
upvoted 3 times
One111
2 years, 4 months ago
Actually if user registers his/her device, SSO will work thru PRT. Seamless SSO make sens only for Windows 7 and 8. Windows 10 and later will accelerate signin with PRT.
upvoted 2 times
...
...
Luthercrop
3 years, 12 months ago
I agree with the answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago