Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 3 question 89 discussion

Actual exam question from Microsoft's MS-100
Question #: 89
Topic #: 3
[All MS-100 Questions]

HOTSPOT -
Your network contains an on-premises Active Directory domain and a Microsoft 365 subscription.
The domain contains the users shown in the following table.

The domain contains the groups shown in the following table.

You are deploying Azure AD Connect.
You configure Domain and OU filtering as shown in the following exhibit.

You configure Filter users and devices as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
KemalM
Highly Voted 2 years ago
Wrong ... It should be No, No, No since group is Sales OU which does not synchronize When using OU-based filtering in conjunction with group-based filtering, the OU(s) where the group and its members are located must be included. (https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#group-based-filtering)
upvoted 17 times
gills
1 year, 6 months ago
This is so wrong from @KamelM. The OU selected is OU1 in the filter for OU. User 1 is in Group1 and also in OU1. User will sync for sure. There is a Group1 in OU1.
upvoted 1 times
vanr2000
1 year, 5 months ago
KemalM is correct. If you see the graph, is doing filters for OU sales. And besides nested groups are not supported. So, nothing is sync.
upvoted 3 times
...
...
...
xyz213
Highly Voted 2 years ago
Should be N/N/N When a Group is not in a synced OU nothing gets synced Besides that Nested group membership is not resolved – objects to synchronize must be direct members of the group used for filtering https://azurecloudai.blog/2019/11/07/field-notes-azure-active-directory-group-filtering-gotchas/
upvoted 10 times
chewitt
1 year, 12 months ago
Why wouldn't User 1 and 2 sync they are in OU1 that is synced?
upvoted 1 times
One111
1 year, 8 months ago
Because filtering is based on both ou and group. Filtering group is out of scope, AADC can get members. No object will be synced.
upvoted 4 times
...
...
...
emartiy
Most Recent 5 months, 3 weeks ago
Correct answer is and always will be "YES - NO - YES" check copilot answer.. n your case: OU1 and OU2 are specified in the OU-based filter. The user/group filter includes specific users and groups. The synchronized objects will be the users and groups within OU1 and OU2 that match the user/group filter criteria. Objects outside these OUs or not matching the filter criteria will not be synchronize
upvoted 1 times
...
Amir1909
7 months, 2 weeks ago
Correct
upvoted 1 times
...
9711d59
8 months, 1 week ago
You can use multiple filtering options at the same time. For example, you can use OU-based filtering to only include objects in one OU. At the same time, you can use attribute-based filtering to filter the objects further. When you use multiple filtering methods, the filters use a logical "AND" between the filters.
upvoted 1 times
...
DeLoc
1 year, 7 months ago
I find any reference that states that the Filter group need to be included in the select OU/s. So objects within OU1 that are members of Group1 should be included for sync. I think the answer should be User1 Yes - The user is in OU1 and in Group1 User2 No – The user is excluded by the group1 filter Group 2 Yes – The group is in OU1 and a member of Group1 (Group 2 is a direct member of Group 1, this is not a nested scenario)
upvoted 4 times
...
glitchlessxddd
1 year, 8 months ago
Y-Y-N. User1 and User2 are in OU1. Since nested groups are not admitted, group2 doesn't syncs.
upvoted 1 times
...
Sironin
1 year, 9 months ago
User1 is not in the Sales OU, not synced User2 is not in the Sales OU, not synced Group2 is not in the Sales OU, not synced To be within the filtering scope, both Sales OU and OU1 OU would have to be synced. So even though Group1 is synced, User1 is not because its OU is not synced. If there are other users part of Group1 in the Sales OU, they would be synced So this is N/N/N
upvoted 3 times
...
Startkabels
1 year, 9 months ago
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#sync-filtering-based-on-groups Screen 1 is to confuse you as only the second screen that shows a 1 time pilot matters. And only direct members of the selection for the pilot (group 1) are synced which is User1 only: YNN
upvoted 3 times
Paolo2022
1 year, 9 months ago
I don't agree (and I don't find the source you provide conclusive). User1 is a member of Group1 - but that User1 is not being synchronized in the first place, filtered out through the earlier OU filter. I would go for NNN. Also, I found a source with question 47 from topic 3 (now page 17) that is explicit about this: "When using OU-based filtering in conjunction with group-based filtering, the OU(s) where the group and its members are located must be included." (https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#group-based-filtering)
upvoted 1 times
...
...
Swyft
1 year, 11 months ago
The questions states "You are deploying Azure AD Connect." From MS "You can configure group-based filtering the first time that you install Azure AD Connect by using custom installation. It's intended for a pilot deployment where you want only a small set of objects to be synchronized. When you disable group-based filtering, it can't be enabled again. " https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering So it will still work. However Nested group membership is not resolved – objects to synchronize must be direct members of the group used for filtering. So I would say YNN
upvoted 5 times
...
Pupu2196
2 years ago
Can anyone provide an answer to this?
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...