MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization is planning to migrate from on-premises Active Directory to Microsoft Entra ID using Microsoft Entra Connect. You need to ensure that password synchronization is enabled. Which TWO components are required for password synchronization to work?
⚠ Common exam trap
Many candidates confuse Password Writeback (a separate feature for cloud-to-on-premises password changes) as a prerequisite for password synchronization, when in fact it is an optional add-on that is not required for the one-way sync of password hashes from on-premises to the cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect with password hash synchronization selected.
Microsoft Entra Connect with password hash synchronization (PHS) selected is the component that hashes the on-premises Active Directory password and synchronizes it to Microsoft Entra ID. Option E is correct because the Microsoft Entra ID service must process the incoming password hashes and store them in the cloud directory, enabling authentication against Entra ID. Without both the local sync engine (Microsoft Entra Connect) and the cloud-side service, password synchronization cannot function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra Connect with password hash synchronization selected.
Why this is correct
Microsoft Entra Connect is the official Microsoft synchronization tool that connects on-premises Active Directory with Microsoft Entra ID. When password hash synchronization (PHS) is selected, Microsoft Entra Connect retrieves a one-way hash (using MD5, SHA-256, and PBKDF2) of each user's on-premises password and securely transfers it to Entra ID. This allows users to authenticate to cloud services using the same password without any federation infrastructure, and it is the core mechanism that satisfies the migration requirement.
- ✗
Active Directory Federation Services (AD FS).
Why it's wrong here
AD FS (Active Directory Federation Services) is a claims-based identity federation technology that provides single sign-on for on-premises and cloud applications, but it does not synchronize password hashes. Instead, it redirects authentication requests to on-premises AD to validate credentials and then issues security tokens to Entra ID. Deploying AD FS solely for password synchronization would require additional servers, certificates, and proxy infrastructure, adding complexity with no benefit for the stated migration goal.
- ✗
Password Writeback enabled.
Why it's wrong here
Password writeback is a feature that enables users to reset or change their passwords in the cloud and have the new password copied back to on-premises Active Directory via Microsoft Entra Connect. This feature is independent of password hash synchronization; it is not needed for the one-way flow of password hashes from on-premises to cloud. Writeback is only relevant when you want cloud-initiated password changes to persist on-premises, which is not part of a simple migration scenario.
- ✗
Microsoft Identity Manager (MIM).
Why it's wrong here
Microsoft Identity Manager (MIM) is a separate identity management and synchronization product that can handle identity data across various systems, but it is not the standard or recommended agent for synchronizing password hashes to Microsoft Entra ID. Microsoft Entra Connect supersedes MIM for hybrid identity synchronization with Microsoft's cloud platform, and using MIM for password hash synchronization would require custom management agents and configuration. It adds unnecessary complexity and is not required to meet the migration objective.
- ✓
Microsoft Entra ID service to process synchronization.
Why this is correct
Microsoft Entra ID (formerly Azure Active Directory) is the cloud identity service that receives and processes the synchronized password hashes from Microsoft Entra Connect. Once uploaded, these hashes are used by Entra ID to validate user sign-in attempts and enforce conditional access policies. Without this cloud-side service, the synchronized data would have no authentication endpoint, so this is a correct and necessary component of the overall password synchronization architecture.
Go deeper
Related to this question
Learn chapter
Entra Connect Health Monitoring
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft Entra Connect
Microsoft Entra Connect is a tool that synchronizes on-premises Active Directory identities with Microsoft Entra ID (formerly Azure AD) to enable single sign-on and centralized identity management.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.