Drag steps to the numbered slots on the right, or tap a step then tap a slot.
AZ-104 Implement and Manage Storage Practice Question
Order the steps to configure Azure AD Connect for hybrid identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Install Azure AD Connect, then choose sync method, then connect to Azure AD, then filter domains/OUs, then finalize
Install, choose sync method, connect to Azure AD, filter domains, then finalize.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install Azure AD Connect, then choose sync method, then connect to Azure AD, then filter domains/OUs, then finalize
Why this is correct
This is the correct order because you must install the tool first, then select the synchronization method (e.g., Password Hash Sync or Pass-through Authentication), then authenticate to Azure AD, optionally filter specific domains or OUs, and finally complete the configuration and start the initial sync.
- ✗
Install Azure AD Connect, then connect to Azure AD, then choose sync method, then filter domains/OUs, then finalize
Why it's wrong here
This sequence is invalid because the synchronization method must be selected before the Connect to Azure AD step. During that step, Azure AD Connect verifies tenant credentials and establishes the authentication pipeline, which depends on knowing whether Password Hash Sync, Pass-through Authentication, or Federation will be used. The wizard's design enforces this dependency because the connection validation checks the chosen method's prerequisites.
- ✗
Install Azure AD Connect, then choose sync method, then filter domains/OUs, then connect to Azure AD, then finalize
Why it's wrong here
You cannot filter domains or OUs immediately after selecting the sync method because the filtering page requires an authenticated connection to Azure AD to list the on-premises directory tree. The Connect to Azure AD step establishes that tenant link and supplies the global admin context used to enumerate the directory, so domain/OU selection is only available after the connection succeeds. Attempting to filter before connecting would leave the wizard with no directory to filter.
- ✗
Install Azure AD Connect, then choose sync method, then connect to Azure AD, then finalize, then filter domains/OUs
Why it's wrong here
Finalizing Azure AD Connect applies all configuration and triggers the initial synchronization cycle, so any domain or OU filters must be defined before that point. If you finalize first, the sync engine starts with an unfiltered scope, and the filters you add afterward require rerunning the wizard and re-applying the configuration. The Finalize step also creates the connector and schedules sync, meaning filtering afterward is not a valid post-completion step.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.