Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your company, Fabrikam Inc., uses Microsoft Entra ID with hybrid identity. You have an on-premises Active Directory and use Microsoft Entra Connect Sync to synchronize users. You need to configure Microsoft Entra ID Protection to detect leaked credentials and risky sign-ins. Additionally, you must ensure that when a user is detected as high risk, their access is automatically blocked and they are required to change their password. You also need to enable password writeback so that password changes are written back to on-premises AD. You have the following options: A. Enable Identity Protection, configure user risk policy to require password change, and enable password writeback in Microsoft Entra Connect. B. Enable Identity Protection, configure sign-in risk policy to block access, and enable password hash sync. C. Configure Conditional Access policy to require MFA for all users, and enable seamless SSO. D. Deploy Microsoft Defender for Identity and configure automatic remediation. Which option should you choose?

⚠ Common exam trap

Watch out — candidates often confuse sign-in risk policies (which block access) with user risk policies (which can require a password change), and they may overlook that password writeback must be explicitly enabled in Microsoft Entra Connect, not just password hash sync.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Identity Protection, configure user risk policy to require password change, enable password writeback

It directly addresses all requirements: enabling Identity Protection allows detection of leaked credentials and risky sign-ins; configuring the user risk policy to require a password change automatically blocks high-risk users until they change their password; and enabling password writeback in Microsoft Entra Connect ensures that password changes performed in the cloud are written back to on-premises Active Directory, maintaining hybrid identity synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Identity Protection, configure user risk policy to require password change, enable password writeback

    Why this is correct

    It combines user risk detection in Microsoft Entra ID Protection with a user risk policy that automatically requires a secure password change when an account is flagged as compromised. Password writeback is essential in a hybrid environment to propagate the new password to on-premises Active Directory. This workflow directly remediates the risk and meets all stated requirements.

  • ✗

    Enable Identity Protection, configure sign-in risk policy to block access, enable password hash sync

    Why it's wrong here

    A sign-in risk policy only blocks access at the time of a suspicious sign-in; it does not require the user to change their password, so the underlying user compromise remains unresolved. Additionally, password hash sync only supports authentication to Microsoft Entra ID, not password writeback, meaning password changes cannot be written back to on-premises Active Directory. The lack of a user risk policy and writeback capability fails the remediation requirement.

  • ✗

    Deploy Microsoft Defender for Identity, configure automatic remediation

    Why it's wrong here

    Microsoft Defender for Identity is an on-premises security solution that detects attacks against Active Directory, not a Microsoft Entra ID Protection feature that manages user risk. It does not offer user risk policies or sign-in risk policies that trigger password changes, and its 'automatic remediation' does not change passwords. Therefore, it does not provide the required risk-based password change remediation.

  • ✗

    Configure Conditional Access policy to require MFA, enable seamless SSO

    Why it's wrong here

    Requiring MFA through Conditional Access strengthens authentication but does not detect or remediate compromised identities or user risk. Seamless SSO only improves the sign-on experience for domain-joined devices and has no involvement in risk detection or password writeback. This approach lacks both the risk-based password change policy and writeback capability needed to satisfy the requirements.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.