Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization has a Microsoft 365 E5 tenant. You want to ensure that all users are automatically signed in to Microsoft 365 apps using single sign-on (SSO) when they are on the corporate network. You have Microsoft Entra ID joined the devices. What additional configuration is required?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Entra ID Seamless SSO (which is for non-Microsoft Entra ID joined devices) with the built-in SSO capability of Microsoft Entra ID joined devices, leading them to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No additional configuration is required; Microsoft Entra ID joined devices provide SSO automatically.

Microsoft Entra ID joined devices are already registered with Microsoft Entra ID and use the Primary Refresh Token (PRT) to enable seamless SSO for Microsoft 365 apps without any additional configuration. When a user signs into a Windows 10/11 device that is Microsoft Entra ID joined, the PRT is obtained during the initial authentication and is automatically used for browser and app sign-ins on the corporate network. Therefore, no extra steps like enabling Seamless SSO or deploying certificates are needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Entra ID Seamless Single Sign-On.

    Why it's wrong here

    Microsoft Entra ID Seamless SSO is designed for devices that are domain-joined to on-premises Active Directory and need to access Microsoft Entra ID resources without prompting. Microsoft Entra ID joined devices, however, authenticate directly to Microsoft Entra ID and obtain a Primary Refresh Token (PRT) at sign-in, which already enables silent SSO. Enabling Seamless SSO would add an unnecessary Kerberos-based component that does not apply to the Microsoft Entra ID join scenario.

  • ✓

    No additional configuration is required; Microsoft Entra ID joined devices provide SSO automatically.

    Why this is correct

    When a Windows device is Microsoft Entra ID joined, it automatically receives a Primary Refresh Token (PRT) after the user signs in with their Microsoft Entra ID credentials. This PRT is exchanged for access tokens to Microsoft 365 apps and other cloud resources without any additional sign-in prompts, providing seamless SSO across sessions. No extra configuration such as federation, password hash sync, or pass-through authentication is needed because the device and user are already registered with Microsoft Entra ID.

  • ✗

    Configure Microsoft Entra application proxy for each app.

    Why it's wrong here

    Microsoft Entra application proxy is a reverse proxy service that publishes on-premises web applications to external users, using Microsoft Entra ID as the authentication broker, but it does not provide SSO for cloud-based SaaS applications. In a Microsoft 365 E5 tenant, cloud apps are already integrated with Microsoft Entra ID, and the PRT from the Microsoft Entra ID joined device supplies the necessary token for single sign-on. Deploying Application Proxy for each app would be an incorrect and overly complex approach that addresses a different scenario (on-premises app publishing) entirely.

  • ✗

    Deploy a trusted certificate for the corporate network.

    Why it's wrong here

    A trusted corporate certificate deployed to devices is not required for SSO on Microsoft Entra ID joined devices because these devices already have a built-in device certificate and leverage the Primary Refresh Token (PRT) for authentication. While certificate-based authentication can be configured for stronger user sign-in, it is an optional security control and does not influence the automatic SSO behavior of the PRT. Deploying a certificate would add no benefit to the SSO flow in this environment.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.