easyMultiple Choice
MS-102 A company has a hybrid identity setup Practice Question
A company has a hybrid identity setup. A new employee is created in on-premises AD but does not appear in Microsoft Entra ID after sync. What should the admin check first?
⚠ Common exam trap
The trap here is that candidates often jump to license assignment (Option C) because they think a user must have a license to appear in Microsoft Entra ID, but in reality, unlicensed users still appear in Microsoft Entra ID after sync; the license only enables service access, not directory presence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect synchronization status
When a new user is created in on-premises Active Directory but does not appear in Microsoft Entra ID after synchronization, the first troubleshooting step is to check the Microsoft Entra Connect synchronization status. This is because Microsoft Entra Connect is the service responsible for synchronizing objects from on-premises AD to Microsoft Entra ID, and any sync failure, delay, or misconfiguration (such as a stopped sync cycle or filtering rules) would prevent the user from appearing. Checking the sync status via the Microsoft Entra Connect wizard or the Synchronization Service Manager can immediately reveal whether the object was exported, skipped, or errored.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Organizational unit filtering
Why it's wrong here
Organizational unit filtering restricts which on-premises Active Directory containers are synchronized to Microsoft Entra ID. If the new employee's account resides in an OU that is deselected in Microsoft Entra Connect's OU filter, the object will never be provisioned, regardless of other settings. However, this scenario is just one possible sync misconfiguration; the immediate diagnostic step is to verify the overall sync status to see whether the last synchronization cycle completed and whether any errors occurred.
- ✗
DNS configuration
Why it's wrong here
DNS configuration is unrelated to user object provisioning in a hybrid identity environment. DNS records are used for name resolution of federated services such as Active Directory Federation Services, but they do not influence whether Microsoft Entra Connect creates or updates cloud user accounts. Even with incorrect DNS, the synchronization service can still connect to Exchange Online or Microsoft Entra ID via the standard endpoints, so DNS errors would not prevent a new employee from appearing.
- ✗
License assignment
Why it's wrong here
License assignment controls access to Microsoft 365 workloads but has no effect on whether a user object is synchronized to Microsoft Entra ID. A synced user exists in the cloud directory even without a license; licensing only enables services like Exchange Online or Teams. Therefore, the absence of a license might explain why the employee cannot sign in to a specific service, but it does not explain why the account is missing entirely from the Microsoft Entra ID user list.
- ✓
Microsoft Entra Connect synchronization status
Why this is correct
Microsoft Entra Connect synchronization status is the primary suspect when a newly created on-premises user does not appear in Microsoft 365. The synchronization service runs on a recurring schedule; if the last delta sync failed, the scheduler is paused, or the service itself is stopped, the new user will not be replicated to Microsoft Entra ID. Verifying the sync cycle, checking the event logs for errors, and forcing a delta sync are the correct initial troubleshooting steps before examining any other configuration.
Go deeper
Related to this question
Learn chapter
Identity Lifecycle: Joiners, Movers, Leavers
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft Entra Connect
Microsoft Entra Connect is a tool that synchronizes on-premises Active Directory identities with Microsoft Entra ID (formerly Azure AD) to enable single sign-on and centralized identity management.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.