AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization is implementing a hybrid identity solution with Microsoft Entra ID. Users in an on-premises Active Directory domain need to access cloud applications. You need to ensure that password changes on-premises are synchronized to Entra ID within 30 seconds. Which configuration should you use?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Entra Connect Sync (Option D) with Microsoft Entra Cloud Sync (Option C), assuming both offer the same synchronization speed, but Connect Sync uses a scheduled batch process (default 2-minute interval) that cannot meet the 30-second requirement, while Cloud Sync is designed for near-real-time sync.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Cloud Sync
Microsoft Entra Cloud Sync (Option C) is the correct choice because it is designed for near-real-time synchronization of identity changes, including password writes, with a target latency of under 30 seconds. It uses the lightweight Microsoft Entra Connect provisioning agent and the SCIM (System for Cross-domain Identity Management) protocol to sync changes from on-premises Active Directory to Entra ID, meeting the strict 30-second requirement for password change propagation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-through Authentication (PTA)
Why it's wrong here
Pass-through Authentication does not synchronize password hashes or directory changes into Microsoft Entra ID; it simply validates sign-in credentials by sending them through an on-premises agent to Active Directory. Because it is an authentication mechanism rather than a sync engine, it cannot independently propagate user or password attribute changes to the cloud on a 30-second delta cycle. Therefore PTA alone fails the stated near-real-time synchronization requirement.
- ✗
Federation with Active Directory Federation Services (AD FS)
Why it's wrong here
Active Directory Federation Services (AD FS) redirects authentication to the on-premises federation server and issues claims, but it does not sync users, groups, or password hash changes to Entra ID. Even when AD FS is deployed, you still require Microsoft Entra Connect or Cloud Sync to handle directory object synchronization, so AD FS by itself cannot deliver near-real-time updates. This makes federation an authentication solution rather than a synchronization solution that meets the 30-second goal.
- ✓
Microsoft Entra Cloud Sync
Why this is correct
Microsoft Entra Cloud Sync uses a lightweight provisioning agent installed on-premises to connect directly to Entra ID, and its default delta synchronization cycle runs roughly every 30 seconds for user, group, and password hash changes. Because it supports password hash synchronization and synchronizes attributes in near-real time, it satisfies the requirement for changes to appear in the cloud quickly. Cloud Sync is therefore the correct choice when a 30-second sync window is required without running the full Microsoft Entra Connect sync engine.
- ✗
Microsoft Entra Connect Sync with password hash synchronization
Why it's wrong here
Microsoft Entra Connect Sync with password hash synchronization is a full sync engine, but its standard delta sync schedule for directory objects is 30 minutes by default, and password hash sync alone cycles every two minutes. Neither of these intervals meets a 30-second requirement, so a password change or attribute update would not appear in Entra ID quickly enough. This slower batch-oriented architecture makes Entra Connect Sync unsuitable for the stated near-real-time scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.