Courseiva
mediumMultiple SelectObjective-mapped

MS-102 Practice Question: A Microsoft 365 Administrator for a company that…

You are a Microsoft 365 Administrator for a company that is implementing a hybrid identity solution with Active Directory Federation Services (AD FS) for single sign-on (SSO). The company has recently acquired a subsidiary with its own on-premises Active Directory domain. You need to ensure that the identity lifecycle for users from the subsidiary is managed effectively through Microsoft Entra ID (formerly Azure AD) and that licensing is assigned efficiently. Which three of the following actions should you take? (Choose three.)

⚠ Common exam trap

Candidates often assume a separate tenant is required for an acquired subsidiary (Option B) or that cloud sync is equivalent to Entra Connect for AD FS scenarios (Option D), when in fact multi-forest sync with a single tenant and group-based licensing is the recommended approach for hybrid identity lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure Microsoft Entra Connect to synchronize identities from the subsidiary’s Active Directory domain, and use group-based licensing to automatically assign Microsoft 365 licenses to synced users based on their department attribute.

Options A, C, and E are correct. A: Microsoft Entra Connect can synchronize identities from multiple on-premises AD forests into a single Microsoft Entra tenant, and group-based licensing allows automatic assignment of Microsoft 365 licenses based on directory attributes like department, ensuring efficient lifecycle management. C: Filtered synchronization scope (e.g., using OU or attribute filtering) lets you initially synchronize only a subset of users (like sales) to control the rollout and test the hybrid identity configuration. E: Microsoft Entra ID Governance’s Entitlement Management can create access packages that include licenses and assign them via dynamic group membership, providing automated, policy-driven license assignment that integrates with identity lifecycle. B is incorrect because creating a separate tenant for the subsidiary would create administrative overhead and fragmentation; cross-tenant synchronization is not needed for multi-forest sync to a single tenant. D is incorrect because Microsoft Entra cloud sync is for simple sync scenarios and does not support AD FS; in a hybrid environment with AD FS, Microsoft Entra Connect is required. F is incorrect because password hash synchronization is not required to coexist with AD FS; AD FS can be used together with directory synchronization from multiple domains, and PHS is an optional feature.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.