exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 4 question 3 discussion

Actual exam question from Microsoft's MS-100
Question #: 3
Topic #: 4
[All MS-100 Questions]

You have a hybrid deployment of Microsoft 365 that contains the users shown the following table.

Azure AD Connect has the following settings:
✑ Password Hash Sync: Enabled
✑ Pass-through authentication: Enabled
You need to identify which users will be able to authenticate by using Azure AD if connectivity between on-premises Active Directory and the internet is lost.
Which users should you identify?

  • A. none
  • B. User1 only
  • C. User1 and User2 only
  • D. User1, User2, and User3
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Blagojche
Highly Voted 2 years, 1 month ago
If connectivity between on-premises Active Directory and the internet is lost, users who have their password hash synchronized to Azure AD or are using pass-through authentication will be able to authenticate to Azure AD. Based on the information provided, both password hash synchronization and pass-through authentication are enabled in Azure AD Connect. Therefore, all users in the table will be able to authenticate by using Azure AD if connectivity between on-premises Active Directory and the internet is lost. So the correct answer is: D. User1, User2, and User3.
upvoted 5 times
bcquest
1 year, 10 months ago
Not automatically... You would have to manually go into AD Connect and change the method for the AD users to authenticate in the cloud, Per: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/choose-ad-authn this section:
upvoted 1 times
bcquest
1 year, 10 months ago
Considerations. You can use password hash synchronization as a backup authentication method for pass-through authentication, when the agents can't validate a user's credentials due to a significant on-premises failure. Fail over to password hash synchronization doesn't happen automatically and you must use Azure AD Connect to switch the sign-on method manually.
upvoted 1 times
...
...
...
Feyenoord
Most Recent 2 years, 1 month ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-current-limitations Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Azure AD Connect. If the server running Azure AD Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication.
upvoted 3 times
...
DeLoc
2 years, 2 months ago
Selected Answer: D
Password Hash is a fallback option to PTA. All in-scope users are synced during. All users can authenticate via PHS even if On-Prem connectivity is down.
upvoted 2 times
...
felipinho109
2 years, 3 months ago
https://www.examtopics.com/discussions/microsoft/view/54785-exam-sc-300-topic-1-question-16-discussion/ similar question on another exam
upvoted 1 times
...
nav93
2 years, 3 months ago
The password hash synchronization process runs every 2 minutes. You cannot modify the frequency of this process. When you synchronize a password, it overwrites the existing cloud password. The first time you enable the password hash synchronization feature, it performs an initial synchronization of the passwords of all in-scope users. You cannot explicitly define a subset of user passwords that you want to synchronize. However, if there are multiple connectors, it is possible to disable password hash sync for some connectors but not others using the Set-ADSyncAADPasswordSyncConfiguration cmdlet.
upvoted 1 times
...
One111
2 years, 4 months ago
Selected Answer: B
PtA requires connectivity from on-premises AADC to Azure to authenticate users. Only cloud users will authenticate during connectivity issues.
upvoted 2 times
...
Startkabels
2 years, 4 months ago
Selected Answer: B
Lol @ some of the explanations here. PHS does not matter. PTA always forces onprem users to authenticate onprem when logging into AAD (hence passthrough). Only the cloud-user can sign in.
upvoted 3 times
...
tenjgin
2 years, 6 months ago
Selected Answer: B
PHS is not a fallback for PTA (As per xyz213)
upvoted 3 times
...
hufflepuff
2 years, 6 months ago
Selected Answer: B
See BoxGhost and xyz213 below.
upvoted 1 times
...
renrenren
2 years, 7 months ago
Not sure, but probably go for D. User3 will be able to log in according to "The first time you enable the password hash synchronization feature, it performs an initial synchronization of the passwords of all in-scope users." https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization
upvoted 3 times
...
defalt1846
2 years, 7 months ago
why not c? since the user 3 never signed in.
upvoted 1 times
Downstar
2 years, 5 months ago
But at the moment that Phs is enabled. It's sync all password hashes that are in the scope. So also the hash of user 3. Even if he didn't login yet
upvoted 1 times
...
...
BoxGhost
2 years, 12 months ago
Surely the answer is B? The article linked specifically mentions you would have to re-run the wizard manually to disable PTA if connectivity is lost! https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn#cloud-authentication-pass-through-authentication Considerations. You can use password hash synchronization as a backup authentication method for pass-through authentication, when the agents can't validate a user's credentials due to a significant on-premises failure. Fail over to password hash synchronization doesn't happen automatically and you must use Azure AD Connect to switch the sign-on method manually.
upvoted 3 times
[Removed]
2 years, 11 months ago
Nop, the answer is D, because the Password Hash Syncronization is also enabled, if you are offline, AzureAD have the HASH for all three users
upvoted 4 times
xyz213
2 years, 7 months ago
I am with BoxGhost here. Only User1 https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq "Does password hash synchronization act as a fallback to Pass-through Authentication? No. Pass-through Authentication does not automatically failover to password hash synchronization. To avoid user sign-in failures, you should configure Pass-through Authentication for high availability."
upvoted 2 times
xyz213
2 years, 7 months ago
PHS with PTA is only used if you have PTA but want to use "sign-in desaster recovery or leaked credential reports - see Decision Tree: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn
upvoted 1 times
...
GAZMAN_2002
2 years, 4 months ago
I did in person training for MS-100 and the instructor said if on prem is in play with AD connect if the internet goes down then authentication can't complete because on prem is unreachable. It could still work if AD is a VM in Azure since its unlikely the internet would fail there but is still possible. I would have chosen only User 1 but now I am not sure
upvoted 2 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago