Courseiva
Deploy and manage a Microsoft 365 tenanthardMultiple ChoiceObjective-mapped

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization has a hybrid identity with Microsoft Entra Connect. You need to migrate from federation to password hash synchronization with seamless single sign-on (SSO). The migration must have minimal user impact. Which tool should you use?

⚠ Common exam trap

It's easy for candidates to confuse the Azure AD Connect wizard (which can enable PHS) with the dedicated migration tool, not realizing that the wizard lacks the specific domain conversion and staged rollback capabilities needed for a low-impact migration from federation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Connect migration tool (Convert domain from federated to managed)

The Microsoft Entra Connect migration tool (Convert domain from federated to managed) is the correct choice because it automates the conversion of federated domains to managed domains while enabling password hash synchronization (PHS) and seamless SSO. This tool minimizes user impact by allowing a staged migration where users can continue authenticating via federation until the conversion is complete, and it handles the necessary configuration changes in Azure AD and on-premises Active Directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Connect migration tool (Convert domain from federated to managed)

    Why this is correct

    The Microsoft Entra Connect migration tool's 'Convert domain from federated to managed' function is the purpose-built operation to switch a domain's sign-in method from federation to cloud authentication. It performs the conversion with minimal user impact because it updates the domain's authentication type in Microsoft Entra ID while leaving users and directory objects in place. During the process, it can use staged rollback or gradual deployment, ensuring that any authentication failures can be addressed without locking all users out. This makes it the correct choice for decommissioning AD FS.

  • IdFix tool

    Why it's wrong here

    The IdFix tool is a data-quality utility that scans on-premises Active Directory for attributes—such as duplicated userPrincipalName, invalid email addresses, or invalid characters—that would cause synchronization failures to Microsoft Entra ID. It reports and corrects errors in directory objects, but it does not alter authentication protocols or domain configuration. Because this scenario requires changing how sign-in is handled, IdFix is irrelevant to the federation-to-managed conversion.

  • AD FS Management console

    Why it's wrong here

    The AD FS Management console is the administrative interface for an on-premises federation server, where you configure relying party trusts, claim issuance policies, and tokens. It can edit or remove the Microsoft Entra ID relying party trust, but this only affects server-side federation behavior—it does not change the domain's recorded authentication type in Microsoft Entra ID. Using it to try a migration would likely break sign-in before anything is converted, since the cloud still expects the federation trust.

  • Azure AD Connect wizard

    Why it's wrong here

    The Azure AD Connect wizard is run primarily for initial installation and sync configuration, including selecting the sign-on method (Password Hash Sync, Pass-through Authentication, or AD FS). While rerunning the wizard can change the intended authentication method, it does not provide a direct, per-domain 'convert from federated to managed' operation and it does not immediately clear the federation trust for an existing domain in Microsoft Entra ID. That conversion is a separate step controlled by the Microsoft Entra Connect migration tool, making the wizard an incomplete answer.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.