hardMultiple Choice
MS-102 Practice Question: Uses Microsoft Entra ID with Pass-through…
An organization uses Microsoft Entra ID with Pass-through Authentication (PTA) and Seamless Single Sign-On (SSO). They notice that password changes in on-premises Active Directory are not reflecting immediately in Microsoft Entra ID for some users. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume PTA agents instantly reflect on-premises changes, overlooking the critical dependency on Active Directory replication latency across domain controllers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's password change has not replicated to all domain controllers
In a Pass-through Authentication environment, password changes are processed by on-premises Active Directory. The password change must replicate to all domain controllers before Microsoft Entra ID can authenticate the new password via the PTA agent. If replication is incomplete, the PTA agent may contact a domain controller that still has the old password, causing the delay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The PTA agents are overloaded
Why it's wrong here
Overloaded PTA agents can introduce latency or queueing during credential validation, but they do not affect how a password change propagates across domain controllers. Even a heavily loaded agent still queries the same directory over the network, and its load does not dictate whether it receives the newly changed password. The specific symptom of a password change not being reflected is classic replication latency, not an agent performance problem.
- ✓
The user's password change has not replicated to all domain controllers
Why this is correct
The PTA agent validates each password request by contacting a domain controller in the on-premises AD environment. Because AD replication is multi-master and asynchronous, a password change made on one DC may not yet have reached the DC that the agent happens to query. Until replication completes, that DC still accepts the old password and rejects the new one, producing the exact issue described. This is the most likely cause for password changes not being reflected immediately, especially in environments with multiple domain controllers or slow site links.
- ✗
The Seamless SSO feature is disabled
Why it's wrong here
Disabling Seamless SSO only affects the silent Kerberos-based sign-on experience for domain-joined devices during the initial authentication prompt. It has no effect on how passwords are validated or how password changes are replicated within Active Directory. With PTA, even when Seamless SSO is disabled, the same real-time password validation flow is used, so newly changed passwords would still fail until the relevant DC has received the update through replication.
- ✗
Microsoft Entra ID has a password hash sync delay
Why it's wrong here
Pass-through Authentication does not use password hash synchronization at all; it validates passwords against on-premises Active Directory in real time. A delay in password hash sync is only relevant when the PTA fallback method is Password Hash Sync, but that is not the default mechanism here. Therefore, a PHS-related delay cannot explain why a password change is not reflected, because PTA relies on the current state of the on-prem DC that the agent queries, not on any synced hash in Microsoft Entra ID.
Go deeper
Related to this question
Learn chapter
Entra ID Entitlement Management and Access Packages
Key term
Pass-through authentication
Pass-through authentication is a Microsoft Microsoft Entra ID authentication method that validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud.
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.