Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization has a hybrid identity deployment with Microsoft Entra Connect. You have synchronized all on-premises Active Directory users to Microsoft Entra ID. You need to enable Microsoft Entra ID Password Protection to automatically block weak passwords. You have installed the Password Protection proxy on a server and registered it. You also need to enforce the password protection policy for on-premises users. What additional step is required?

⚠ Common exam trap

Candidates often assume the proxy server alone enforces the policy, but the proxy only facilitates communication, while the DC agent is the enforcement point on each domain controller.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Password Protection DC agent on each domain controller.

The Password Protection DC agent is required on each domain controller to intercept and validate password changes against the Microsoft Entra ID Password Protection policy. Without this agent, the proxy server alone cannot enforce the policy for on-premises users, as the DC agent is the component that applies the password filter during password change operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install the Password Protection DC agent on each domain controller.

    Why this is correct

    The DC agent is the enforcement engine for Password Protection in a hybrid environment. It must be installed on every domain controller because it hosts the password filter DLL that intercepts and validates password changes against the banned password list. Without it, a password change processed by a DC lacking the agent would bypass the policy entirely, so placing it on each DC is the required configuration.

  • ✗

    Install the Password Protection proxy on all domain controllers.

    Why it's wrong here

    The proxy is a relay component that downloads the banned password list from Microsoft Entra ID and delivers it to the DC agent, but it does not enforce the policy itself. It should be installed on member servers in the forest, not on domain controllers, and this environment already has the proxy deployed. Adding the proxy to all DCs would be architecturally wrong and still would not enable on-premises enforcement; the missing step is installing the DC agent on the DCs.

  • ✗

    Enable the password filter in the Microsoft Entra Connect configuration.

    Why it's wrong here

    The password filter DLL is not delivered or enabled through Microsoft Entra Connect; it is a component of the Password Protection DC agent that registers with the Local Security Authority subsystem on domain controllers. Microsoft Entra Connect handles directory synchronization and password hash synchronization, and it has no setting to turn on a password filter. Enabling a filter through Connect would be technically meaningless because the DC agent is the only component that installs and invokes that filter.

  • ✗

    Configure a Group Policy to require password complexity.

    Why it's wrong here

    A Group Policy that enforces password complexity is a classic Active Directory password policy, which dictates length and character-class requirements, but it does not screen for banned or compromised passwords. Password Protection operates independently as a real-time check by the DC agent against the global and custom banned lists, and it can exist in audit or enforce mode. Group Policy cannot replicate this behavior, and the two mechanisms complement each other; enabling complexity alone would not satisfy the requirement to implement Password Protection.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.