MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization is deploying Microsoft 365 for a multinational company. You need to ensure users in different regions authenticate against the nearest Microsoft Entra ID endpoint for performance. What should you configure?
⚠ Common exam trap
The trap here is that candidates often overthink performance optimization and assume manual configuration (like custom domains or traffic managers) is needed, when Microsoft Entra ID's built-in anycast routing automatically handles regional proximity without any tenant-side setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.
Microsoft Entra ID (formerly Azure AD) uses a global anycast network to automatically route authentication requests to the nearest available endpoint based on DNS resolution and network latency. No additional configuration is required because Entra ID's infrastructure is designed to provide optimal performance globally without manual traffic management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the appropriate regional subdomain (e.g., us.contoso.com) as a custom domain.
Why it's wrong here
Adding a regional subdomain such as us.contoso.com as a custom domain in Microsoft Entra ID only associates that namespace with your tenant for userPrincipalName, email, and branding purposes. The domain name has no bearing on which authentication endpoint processes sign-in traffic; Microsoft Entra ID selects the regional front end based on DNS resolution and global load balancing, not the suffix of the user's UPN. In fact, mapping a regional subdomain could create unnecessary DNS or email routing complexity, but it will never alter the geographic path of an authentication request.
- ✓
No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.
Why this is correct
No additional configuration is required because Microsoft Entra ID operates a globally distributed set of authentication front ends that are automatically selected through Microsoft's internal load balancing and DNS infrastructure. When a user signs in, their client resolves the Microsoft-managed login endpoint and is directed to the closest available regional service while the request is then handled consistently with the tenant's home instance. This routing is intrinsic to the platform and designed to optimize latency and resilience for multinational organizations without any tenant-side setup.
- ✗
Create a conditional access policy to route authentication to the nearest region.
Why it's wrong here
Conditional Access policies are evaluated after a user is authenticated and are used to enforce access requirements, such as requiring multifactor authentication, restricting access by location, or blocking specific device states. They are not involved in the network-level routing of authentication traffic and cannot influence which regional Microsoft Entra ID endpoint receives the request. Creating such a policy would only affect whether a request succeeds or is blocked after reaching the authentication service, not where the request is terminated.
- ✗
Configure a traffic manager profile in Azure to route authentication requests.
Why it's wrong here
Azure Traffic Manager is a DNS-based load balancer that you configure to distribute traffic among your own Azure-hosted endpoints, such as virtual machines, web apps, or custom services. Microsoft Entra ID's authentication endpoints are fully managed by Microsoft and are not exposed as endpoints you can register in a Traffic Manager profile. Authentication requests are directed to Microsoft Entra ID's published login endpoints using Microsoft's global DNS and traffic-management system, so a Traffic Manager profile cannot intercept or reroute them to a preferred region.
Visual reference
Go deeper
Related to this question
Learn chapter
Entra Connect Cloud Sync
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.