mediumMultiple Choice
MS-102 Practice Question: A company uses Password Hash Synchronization…
A company uses Password Hash Synchronization (PHS) to synchronize identities to Microsoft Entra ID. They want to enable users to access Microsoft 365 applications from their domain-joined work devices without being prompted to re-enter their credentials. Which feature should they enable in addition to PHS?
⚠ Common exam trap
Watch out — candidates often confuse Pass-through Authentication (PTA) with Seamless SSO, thinking PTA alone provides the same credential-free experience, but PTA only handles password validation without the automatic ticket-based sign-on that Seamless SSO provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Seamless Single Sign-On
Seamless Single Sign-On (SSO) is the correct feature to enable alongside Password Hash Synchronization (PHS) because it allows users on domain-joined devices to automatically authenticate to Microsoft 365 applications without being prompted for credentials. It works by integrating with Kerberos authentication, using a computer account in the on-premises Active Directory to issue a Kerberos ticket that Microsoft Entra ID can validate, eliminating the need for re-authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Seamless Single Sign-On
Why this is correct
Seamless Single Sign-On is the correct choice because it extends PHS by silently authenticating domain-joined devices via the on-premises Kerberos TGT, which Microsoft Entra ID converts into a user token without prompting for credentials. This eliminates the repeated sign-in prompts that would otherwise occur after PHS validates a password hash, delivering a transparent single sign-on experience. It is a dedicated Microsoft Entra Connect feature designed specifically to complement PHS or PTA in hybrid environments.
- ✗
Pass-through Authentication
Why it's wrong here
Pass-through Authentication is an authentication method, not a silent sign-on enhancement; it validates passwords on-premises through a connector agent, replacing the hash-sync mechanism used by PHS. When enabled without Seamless SSO, users must still type their password at the Microsoft Entra ID sign-in page, and the agent only validates the entered credentials. It cannot reduce sign-in prompts in a PHS-synchronized tenant because it is mutually exclusive with PHS as a password validation strategy.
- ✗
Microsoft Entra Connect Health
Why it's wrong here
Microsoft Entra Connect Health is a monitoring, analytics, and alerting service that tracks the operational health of Microsoft Entra Connect, Active Directory Federation Services, and Domain Controllers, but it has no role in validating user credentials or issuing tokens. It does not touch the authentication pipeline and cannot enable single sign-on, nor does it modify sign-in behavior for synchronized users. Its purpose is purely operational telemetry for troubleshooting and capacity planning, making it irrelevant to this scenario.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a policy engine that evaluates authentication results and signals such as user location, device compliance, and risk level to enforce decisions like requiring MFA or blocking access, but it never authenticates the user itself. These policies run only after a user is successfully authenticated, so they cannot eliminate password prompts or provide silent authentication alongside PHS. Even an allow-type Conditional Access policy still requires a prior sign-in event, which is exactly the prompt that Seamless SSO addresses.
Go deeper
Related to this question
Learn chapter
Hybrid Modern Authentication
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
Key term
SSO
Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications or systems with one set of login credentials.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.