MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft 365 E5 with Microsoft Entra ID P2. You have a hybrid identity environment with Microsoft Entra Connect Sync. You need to ensure that when a user is disabled in on-premises Active Directory, their Microsoft 365 access is blocked within 5 minutes, and any active refresh tokens are invalidated. You have already configured password hash synchronization. What should you do?
⚠ Common exam trap
The trap here is thinking that password hash synchronization alone propagates account disablement or that setting a password change flag blocks access; in reality, account status synchronization and CAE are required for timely token revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable Continuous Access Evaluation (CAE) in Microsoft Entra ID.
Synchronizing the accountEnabled attribute from on-premises Active Directory ensures that disabled accounts are reflected in Microsoft Entra ID. Enabling Continuous Access Evaluation (CAE) allows Microsoft 365 services to respond to critical events like account disablement in near real-time, invalidating refresh tokens within minutes. Together, they meet the 5-minute blocking requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Entra Password Protection and configure a custom banned password list.
Why it's wrong here
Password Protection prevents weak passwords; it does not block disabled accounts or invalidate tokens. It has no effect on account status synchronization or token revocation. This does not meet the requirement to block access within 5 minutes of disabling a user.
- ✓
Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable Continuous Access Evaluation (CAE) in Microsoft Entra ID.
Why this is correct
Synchronizing accountEnabled ensures the disabled state propagates to Microsoft Entra ID. Enabling CAE allows token revocation events, such as account disablement, to be enforced near real-time, invalidating refresh tokens within minutes. This combination meets the 5-minute blocking requirement.
- ✗
Enable 'Enable password hash synchronization' and set the 'User must change password at next logon' flag in on-premises Active Directory.
Why it's wrong here
Password hash synchronization synchronizes password hashes, not account status. Setting the flag to change password at next logon does not block access or invalidate tokens; a disabled account is still synchronized as enabled unless the accountStatus attribute is configured to sync. This does not meet the 5-minute requirement.
- ✗
Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable 'Enable soft match' on the connector.
Why it's wrong here
Soft match is used for matching objects between directories, not for blocking access. Synchronizing accountEnabled does not automatically invalidate refresh tokens within 5 minutes; token invalidation requires continuous access evaluation or a revocation event. Soft match is irrelevant to the requirement.
Go deeper
Related to this question
Learn chapter
Entra Connect Sync Rules and Filtering
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Hybrid identity
Hybrid identity is an approach that synchronizes and manages user identities across both on-premises directories and cloud-based services, allowing seamless access to resources in both environments.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.