Courseiva
Deploy and Manage AD DShardMultiple ChoiceObjective-mapped

AZ-802 Deploy and Manage AD DS Practice Question

You are managing an Active Directory domain that includes several Fine-Grained Password Policies (FGPP). A user is a member of two global groups: 'Sales-Group' and 'Marketing-Group'. 'Sales-Group' is assigned a Password Settings Object (PSO) with a precedence of 50. 'Marketing-Group' is assigned a PSO with a precedence of 20. Which policy will be applied to the user?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The PSO assigned to the Marketing-Group.

Active Directory determines which Fine-Grained Password Policy to apply based on the precedence value of the Password Settings Objects. In this hierarchy, the PSO with the lower numeric value takes precedence. Therefore, a PSO with a precedence of 20 will override a PSO with a precedence of 50 when a user is a member of multiple groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Default Domain Policy.

    Why it's wrong here

    The Default Domain Policy is only applied to users if no Fine-Grained Password Policy is directly assigned to the user or to any groups the user belongs to. Since the user is a member of groups that have specific PSOs assigned, those PSOs will take priority over the global domain-wide password settings.

  • The PSO assigned to the Sales-Group.

    Why it's wrong here

    The Sales-Group has a higher precedence value of 50. In the logic used by Active Directory for Password Settings Objects, higher numbers represent lower priority. Consequently, the settings from this PSO will be ignored in favor of the PSO with the lower numeric value assigned to the user's other group membership.

  • Both policies will be merged, and the most restrictive settings will apply.

    Why it's wrong here

    Active Directory does not merge Fine-Grained Password Policies or resolve conflicts by choosing the most restrictive individual setting. Instead, it selects a single Password Settings Object based on the lowest precedence value or direct assignment. Only one PSO can be effective for a specific user object at any given time.

  • The PSO assigned to the Marketing-Group.

    Why this is correct

    The Marketing-Group's PSO has a precedence value of 20, which is lower than the Sales-Group's value of 50. Active Directory selects the PSO with the lowest numeric precedence value when multiple PSOs apply to a user through group membership, making the Marketing-Group policy the effective password policy for this user.

About these practice questions

One of 116 original AZ-802 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.