MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?
⚠ Common exam trap
The trap is that candidates may think PHS is sufficient because it uses the same password, but the requirement to maintain on-premises policy enforcement during logon points to PTA, not PHS. Seamless SSO is optional and not the deciding factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-through Authentication with Seamless SSO
Pass-through Authentication (PTA) validates passwords directly against on-premises Active Directory, ensuring that on-premises password policies (complexity, expiration, lockout) are enforced for cloud sign-ins. PHS merely synchronizes password hashes to Entra ID and cannot enforce on-premises lockout or account state at authentication time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password Hash Synchronization (PHS)
Why it's wrong here
Password Hash Synchronization (PHS) is the correct choice because Microsoft Entra Connect computes a one-way hash of each on-premises Active Directory password (using MD4 as an intermediate, then SHA-256 with a per-user salt) and synchronizes it to Entra ID, allowing users to sign in with the same password across cloud services. PHS requires no additional on-premises servers or proxies, provides a resilient fallback authentication path if federation or Pass-through Authentication is unavailable, and enables security features such as Entra Identity Protection and leaked-credential detection.
- ✓
Pass-through Authentication with Seamless SSO
Why this is correct
Pass-through Authentication with Seamless SSO is not the best option because it uses lightweight agents on-premises to validate passwords directly against Active Directory in real time, rather than synchronizing any password hash to Entra ID. While PTA avoids storing password hashes in the cloud, it introduces a dependency on on-premises agent availability, requires agent high availability planning, and Seamless SSO only provides silent sign-in on domain-joined devices. For a simple migration to cloud authentication, PTA is operationally more complex than PHS and does not allow cloud-based sign-in if the on-premises directory becomes unreachable.
- ✗
Active Directory Federation Services (AD FS)
Why it's wrong here
Active Directory Federation Services (AD FS) is overkill for a basic requirement to use the same password on-premises and in the cloud, because it requires deploying a federation server farm, a Web Application Proxy, signing certificates, and claims-based trust relationships between Entra ID and on-premises Active Directory. AD FS authenticates users on-premises and issues security tokens, but it adds significant administrative overhead, security attack surface, high-availability demands, and long-term certificate management that provide no benefit when the organization simply needs password parity. Modern federated sign-in is only warranted for specific needs such as smartcard authentication, certain conditional access policies, or third-party identity provider integration.
- ✗
Install Microsoft Entra Connect with default settings
Why it's wrong here
Installing Microsoft Entra Connect with default settings is the right tool but the wrong action, because simply running the wizard does not guarantee that Password Hash Synchronization is explicitly configured as the sign-on method. The Express installation may enable PHS by default, but if the directory already has an existing federation or Pass-through Authentication configuration, the wizard might preserve that behavior instead of setting PHS. The question asks which feature to enable, not which tool to install, so you must specifically select Password Hash Synchronization on the 'Sign-On method' page during configuration for the intended outcome to be met.
Go deeper
Related to this question
Learn chapter
App Consent Policies and Admin Consent
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Pass-through authentication
Pass-through authentication is a Microsoft Microsoft Entra ID authentication method that validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.