Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are deploying Microsoft 365 for a new subsidiary. The subsidiary has a single domain subsidiary.com. You need to configure a hybrid identity solution with Microsoft Entra ID. The on-premises Active Directory has a single domain and all user accounts are synchronized using Microsoft Entra Connect. You want to ensure that users can sign in to Microsoft 365 using their on-premises credentials without exposing the password hash to Microsoft. What should you do?

⚠ Common exam trap

Many exam-takers confuse pass-through authentication with password hash synchronization, assuming both expose credentials, but PTA avoids any hash storage while still enabling cloud authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable pass-through authentication (PTA) with Microsoft Entra Connect.

Pass-through authentication (PTA) allows users to sign in to Microsoft 365 using their on-premises credentials without storing password hashes in Microsoft Entra ID. PTA validates passwords directly against on-premises Active Directory via an agent, ensuring no password hash is exposed to Microsoft, which meets the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure password hash synchronization.

    Why it's wrong here

    Password hash synchronisation copies a hash of the on-premises password into Microsoft Entra ID, which is exactly the exposure the requirement forbids. It is the correct choice when simplified sign-in and resilience are wanted without federation infrastructure.

  • ✗

    Create cloud-only user accounts and disable on-premises authentication.

    Why it's wrong here

    Cloud-only accounts have no on-premises credentials, so users could not sign in with their existing Active Directory passwords. This approach suits organisations with no on-premises directory dependency, not one requiring hybrid identity with on-premises credentials.

  • ✗

    Implement Active Directory Federation Services (AD FS) with Microsoft Entra ID.

    Why it's wrong here

    AD FS would satisfy the no-password-hash requirement, but it introduces on-premises federation servers and certificate infrastructure that this single-domain subsidiary does not need. Password hash synchronisation with seamless single sign-on meets the same goal without exposing hashes, making AD FS the choice only where smartcard or third-party MFA claims are mandated.

  • ✓

    Enable pass-through authentication (PTA) with Microsoft Entra Connect.

    Why this is correct

    Pass-through authentication validates passwords directly against on-premises Active Directory via a lightweight agent, so credentials are never stored in Microsoft Entra ID and no password hash is synchronised to the cloud, satisfying the requirement to avoid exposing password hashes to Microsoft.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.