Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are designing a Microsoft Entra ID tenant for a new subsidiary. You need to ensure that users can authenticate using their existing on-premises Active Directory credentials without synchronizing password hashes to the cloud. Which identity model should you choose?

⚠ Common exam trap

Watch out — candidates often confuse federation (AD FS) with pass-through authentication, assuming that only federation can avoid password hash sync, but PTA also avoids hash sync while being simpler to deploy and manage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-through authentication (PTA)

Pass-through authentication (PTA) allows users to authenticate against on-premises Active Directory directly, without synchronizing password hashes to the cloud. When a user signs in to Microsoft Entra ID, the authentication request is forwarded to an on-premises PTA agent, which validates the credentials against the local domain controller. This meets the requirement of using existing on-premises credentials without storing password hashes in the cloud.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Federation with AD FS

    Why it's wrong here

    Federation with AD FS is incorrect because it requires deploying and maintaining AD FS infrastructure, including federation servers, WAP servers, and certificates, to establish a trust between Entra ID and on-premises AD. Beyond the extra infrastructure burden, it issues SAML/WS-Fed tokens and handles authentication directly on-premises, which is unnecessarily complex if the requirement is simply to validate user passwords without storing them in the cloud. AD FS also introduces additional attack surface and high availability requirements, making it a heavyweight solution compared with pass-through authentication (PTA).

  • ✗

    Cloud-only identity

    Why it's wrong here

    Cloud-only identity is incorrect because it creates user accounts in Entra ID with passwords stored as cloud hashes, with no connection to any on-premises Active Directory. If the tenant must integrate with existing on-premises users or validate credentials against the on-prem AD domain, cloud-only identities cannot leverage those on-premises accounts at all. This would require recreating all users, duplicating groups, and potentially creating a separate identity lifecycle, defeating the purpose of a hybrid authentication scenario.

  • ✓

    Pass-through authentication (PTA)

    Why this is correct

    Pass-through authentication (PTA) is correct because it validates user passwords directly against on-premises Active Directory at sign-in time without ever storing password hashes in the cloud. PTA uses a lightweight agent installed on an on-premises server that receives authentication requests from Entra ID and validates them against the local domain controller. This gives organizations the benefit of cloud-based authentication while preserving on-premises password policies, account states, and lockout settings, and avoids the cloud hash storage that would otherwise be introduced.

  • ✗

    Password hash synchronization (PHS)

    Why it's wrong here

    Password hash synchronization (PHS) is incorrect because it synchronizes a hash of the on-premises user password to Entra ID, meaning password hashes are stored in the cloud. Even though PHS is simpler and provides seamless fallback for other authentication methods, it violates any requirement that password hashes must never be stored in the cloud. PHS also prevents on-premises password policies and lockout states from being enforced during cloud-based sign-in, because the cloud validates against its own copy of the hash rather than calling the on-premises domain controller.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.