Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Which TWO settings must be configured to set up a hybrid identity deployment using password hash synchronization?

⚠ Common exam trap

The trap here is that candidates often include Seamless SSO as a required component for password hash synchronization, when in fact it is optional. The minimal requirements for PHS are simply installing Entra Connect and enabling the PHS feature. SSO enhances the user experience but is not necessary for the synchronization of password hashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install and configure Microsoft Entra Connect.

Option A is correct because Microsoft Entra Connect is the required synchronization tool that connects your on-premises Active Directory to Microsoft Entra ID and provides the wizard where directory synchronization and sign-in methods are configured. Option C is correct because password hash synchronization is a sign-in method that must be explicitly enabled in Entra Connect (on the "User sign-in" page, select "Password Hash Synchronization") for the hybrid identity deployment to work as described. Option B is not required because Seamless SSO is an optional feature that can be enabled alongside password hash synchronization but is not necessary to set up the deployment itself. Option D is incorrect because AD FS is a separate federated authentication method, not part of a password hash synchronization deployment. Option E is incorrect because Pass-Through Authentication is an alternative sign-in method that validates passwords directly against on-premises AD and is mutually exclusive with password hash synchronization as the primary sign-in method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install and configure Microsoft Entra Connect.

    Why this is correct

    Microsoft Entra Connect provides the sync engine that hashes on-premises Active Directory passwords and writes the resulting hash to Microsoft Entra ID, which is the mechanism password hash synchronization depends on. Without this component, no directory objects or password hashes reach the cloud tenant.

  • ✗

    Configure Seamless Single Sign-On (SSO).

    Why it's wrong here

    Seamless SSO is an optional sign-in convenience for domain-joined devices, not a prerequisite for password hash synchronisation. It is tempting because it commonly accompanies PHS deployments, but it is correct only when users need silent desktop authentication; the required settings are the Entra Connect sync and PHS option.

  • ✓

    Enable password hash synchronization in Entra Connect.

    Why this is correct

    Password hash synchronization requires the feature to be enabled in Microsoft Entra Connect before directory synchronization can replicate password hashes to Microsoft Entra ID. Without this setting, on-premises credentials never reach the cloud tenant, so hybrid sign-in with synchronised passwords cannot function.

  • ✗

    Deploy Active Directory Federation Services (AD FS).

    Why it's wrong here

    AD FS provides federated authentication, a separate sign-in method that bypasses password hash synchronisation entirely. It is tempting because federation is a valid hybrid identity option, but it is correct only when the organisation requires on-premises credential validation rather than synchronised password hashes.

  • ✗

    Configure Pass-Through Authentication.

    Why it's wrong here

    Pass-through authentication is an alternative sign-in method that validates passwords against on-premises Active Directory; password hash synchronisation requires enabling the feature in Microsoft Entra Connect instead. It is tempting because both are hybrid identity sign-in options, and PTA would be correct if the requirement were on-premises credential validation.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.