Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Which TWO features of Microsoft Entra ID can be used to secure hybrid identities?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Entra Domain Services (a managed domain service) with a feature of Microsoft Entra ID, when in fact it is a separate service that provides legacy LDAP and NTLM capabilities, not a native hybrid identity authentication feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Seamless Single Sign-On

Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on corporate devices connected to the corporate network, eliminating password prompts. Password Hash Synchronization (PHS) synchronizes a hash of the user's on-premises AD password to Microsoft Entra ID, enabling cloud authentication without additional infrastructure. Both features directly secure hybrid identities by extending on-premises credentials to the cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR service, not an identity feature of Microsoft Entra ID. It aggregates security logs and automates incident response across workloads, including identity-related signals from Entra ID, but it does not participate in authentication or credential synchronization. Therefore, it cannot be used as one of the two Entra ID features that secure hybrid identity.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is an enterprise mobility management (MDM/MAM) solution for enrolling and managing devices, apps, and compliance policies. Although Intune can integrate with Entra ID for conditional access, it is a device management service rather than an identity feature and does not synchronize on-premises credentials or provide authentication mechanisms. It is therefore not one of the two Entra ID identity features for securing hybrid identity.

  • ✓

    Seamless Single Sign-On

    Why this is correct

    Seamless Single Sign-On is a correct answer: it silently signs users into Microsoft Entra ID when they are on a domain-joined device connected to the corporate network, using their existing on-premises AD Kerberos tickets. It lets users access cloud and SaaS applications without re-entering passwords, reducing password fatigue and phishing exposure while relying on the on-premises credential validation. However, it is not a standalone authentication method and must be paired with Password Hash Synchronization or Pass-through Authentication.

  • ✗

    Microsoft Entra Domain Services

    Why it's wrong here

    Microsoft Entra Domain Services is a managed domain service that provides domain join, Group Policy, LDAP, and Kerberos/NTLM authentication to Azure VMs, not a hybrid identity security feature. It is intended to lift and shift legacy applications that require traditional domain services into Azure, rather than to secure on-premises and cloud identity integration. Because it does not extend the existing on-premises AD security boundary or provide single sign-on to Entra ID, it is incorrect.

  • ✓

    Password Hash Synchronization

    Why this is correct

    Password Hash Synchronization is the second correct answer: it synchronizes hash values of users' on-premises AD passwords to Microsoft Entra ID, allowing Entra ID to authenticate users directly in the cloud. The feature also feeds leaked-credential detection and enables Identity Protection risk signals for hybrid users. Importantly, Password Hash Synchronization does not send plaintext passwords, and if the on-premises account is compromised, the same hash-based authentication applies to cloud resources.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.