Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization is deploying Microsoft 365 for a multinational company. You need to ensure users in different regions authenticate against the nearest Microsoft Entra ID endpoint for performance. What should you configure?

⚠ Common exam trap

The trap here is that candidates often overthink performance optimization and assume manual configuration (like custom domains or traffic managers) is needed, when Microsoft Entra ID's built-in anycast routing automatically handles regional proximity without any tenant-side setup.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.

Microsoft Entra ID (formerly Azure AD) uses a global anycast network to automatically route authentication requests to the nearest available endpoint based on DNS resolution and network latency. No additional configuration is required because Entra ID's infrastructure is designed to provide optimal performance globally without manual traffic management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the appropriate regional subdomain (e.g., us.contoso.com) as a custom domain.

    Why it's wrong here

    Adding a regional subdomain such as us.contoso.com as a custom domain in Microsoft Entra ID only associates that namespace with your tenant for userPrincipalName, email, and branding purposes. The domain name has no bearing on which authentication endpoint processes sign-in traffic; Microsoft Entra ID selects the regional front end based on DNS resolution and global load balancing, not the suffix of the user's UPN. In fact, mapping a regional subdomain could create unnecessary DNS or email routing complexity, but it will never alter the geographic path of an authentication request.

  • ✓

    No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.

    Why this is correct

    No additional configuration is required because Microsoft Entra ID operates a globally distributed set of authentication front ends that are automatically selected through Microsoft's internal load balancing and DNS infrastructure. When a user signs in, their client resolves the Microsoft-managed login endpoint and is directed to the closest available regional service while the request is then handled consistently with the tenant's home instance. This routing is intrinsic to the platform and designed to optimize latency and resilience for multinational organizations without any tenant-side setup.

  • ✗

    Create a conditional access policy to route authentication to the nearest region.

    Why it's wrong here

    Conditional Access policies are evaluated after a user is authenticated and are used to enforce access requirements, such as requiring multifactor authentication, restricting access by location, or blocking specific device states. They are not involved in the network-level routing of authentication traffic and cannot influence which regional Microsoft Entra ID endpoint receives the request. Creating such a policy would only affect whether a request succeeds or is blocked after reaching the authentication service, not where the request is terminated.

  • ✗

    Configure a traffic manager profile in Azure to route authentication requests.

    Why it's wrong here

    Azure Traffic Manager is a DNS-based load balancer that you configure to distribute traffic among your own Azure-hosted endpoints, such as virtual machines, web apps, or custom services. Microsoft Entra ID's authentication endpoints are fully managed by Microsoft and are not exposed as endpoints you can register in a Traffic Manager profile. Authentication requests are directed to Microsoft Entra ID's published login endpoints using Microsoft's global DNS and traffic-management system, so a Traffic Manager profile cannot intercept or reroute them to a preferred region.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.