MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company has a hybrid identity configuration with Microsoft Entra Connect Sync. You need to enable password hash synchronization (PHS) for hybrid users. What is the prerequisite?
⚠ Common exam trap
A common mix-up: candidates confuse the on-premises administrative permissions (like Enterprise Admin) with the cloud role required to toggle the PHS feature, mistakenly thinking local AD permissions are sufficient, when in fact the Hybrid Identity Administrator role in Entra ID is the specific prerequisite for enabling PHS at the tenant level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hybrid Identity Administrator role in Microsoft Entra ID
The Hybrid Identity Administrator role in Microsoft Entra ID is required to enable password hash synchronization (PHS) because this role grants the necessary permissions to configure directory synchronization settings, including the PHS feature, within the Entra ID tenant. Without this role, the synchronization account used by Microsoft Entra Connect Sync cannot modify the tenant-level PHS toggle, even if the local service account has sufficient permissions on-premises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-through authentication agent installed
Why it's wrong here
Pass-through authentication (PTA) is an alternative authentication mechanism that validates user passwords directly against on-premises Active Directory, not a precursor to password hash synchronization. Since PHS simply syncs password hashes through Microsoft Entra Connect, it does not require any agent installed on on-premises servers. Therefore, installing a PTA agent is unnecessary and unrelated to enabling PHS.
- ✗
Password writeback enabled
Why it's wrong here
Password writeback is a feature used by self-service password reset to propagate new cloud passwords back to on-premises Active Directory. It is not a prerequisite for password hash synchronization; rather, PHS is actually a prerequisite for enabling password writeback because writeback relies on the synchronized identity. Enabling writeback without first configuring PHS would be impossible, so this option confuses the dependency direction.
- ✓
Hybrid Identity Administrator role in Microsoft Entra ID
Why this is correct
Configuring password hash synchronization requires changing tenant-level directory synchronization settings, which is protected by administrative roles. The Hybrid Identity Administrator role in Microsoft Entra ID grants permission to manage provisioning and synchronization, including enabling PHS. A Global Administrator can also perform this task, but Hybrid Identity Administrator is the least-privileged role that can, making it a necessary prerequisite.
- ✗
Federation with AD FS
Why it's wrong here
Federation with Active Directory Federation Services (AD FS) establishes a federated authentication flow where on-premises AD FS issues claims to Entra ID. Password hash synchronization is a completely separate, managed authentication method that works without any federation infrastructure. Federation is an optional deployment choice, not a requirement; in fact, organizations often enable PHS as a fallback even when they also deploy AD FS, so its absence does not block PHS.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Hybrid identity
Hybrid identity is an approach that synchronizes and manages user identities across both on-premises directories and cloud-based services, allowing seamless access to resources in both environments.
Key term
Password hash synchronization
Password hash synchronization is a Microsoft Microsoft Entra Connect feature that synchronizes a hash of a user's on-premises Active Directory password to Microsoft Entra ID, enabling cloud-based authentication without additional infrastructure.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.