MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization uses Microsoft Defender for Identity and has enabled Microsoft Secure Score. You notice that the Secure Score for Identity has dropped significantly after a recent configuration change. Which action is most likely to have caused the decrease?
⚠ Common exam trap
It's easy for candidates to assume disabling password hash synchronization is a security improvement (to avoid storing hashes in the cloud), but they overlook that Defender for Identity requires it for critical leaked credential detection, and Secure Score penalizes its absence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disabling password hash synchronization in Microsoft Entra Connect.
Disabling password hash synchronization (PHS) in Microsoft Entra Connect removes the ability for Microsoft Defender for Identity to correlate on-premises Active Directory credential exposure events with cloud authentication attempts. Without PHS, Defender for Identity cannot detect when leaked credentials are used against Microsoft Entra ID, causing the Secure Score for Identity to drop because key detection capabilities are no longer available.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Changing password expiration policy to 180 days.
Why it's wrong here
Changing the password expiration policy to 180 days has minimal effect on Microsoft Secure Score for Identity because modern identity security guidance, including NIST recommendations, no longer considers forced password rotation a strong control. Defender for Identity does not rely on password expiration timers for its detection analytics, so this change neither improves the visibility of on-premises and cloud identity signals nor reduces the score. In contrast, disabling PHS directly removes a key data feed for identity threat detection, which is why this option is not the correct way to lower Secure Score.
- ✗
Enabling MFA for all users.
Why it's wrong here
Enabling MFA for all users is a security control that increases Microsoft Secure Score for Identity rather than lowering it. Microsoft evaluates the strength of your authentication posture, and MFA blocks a majority of account compromise attempts, including those that might otherwise feed identity threat analytics. Since the correct action must degrade identity-related visibility or detection capability, enabling MFA does the opposite because it strengthens conditional access and directly contributes to higher Secure Score recommendations.
- ✓
Disabling password hash synchronization in Microsoft Entra Connect.
Why this is correct
Disabling password hash synchronization (PHS) in Microsoft Entra Connect lowers Microsoft Secure Score for Identity because Defender for Identity relies on PHS to obtain on-premises password hashes for leaked-credential analysis and lateral movement path detection. Without PHS, Microsoft Entra ID loses a crucial data source that helps correlate on-premises and cloud activities, impairing the ability to identify compromised accounts and reducing the overall identity threat detection visibility. As a result, the identity protection pillar of Secure Score decreases, making this the correct action.
- ✗
Implementing a conditional access policy blocking legacy authentication.
Why it's wrong here
Implementing a conditional access policy that blocks legacy authentication improves Microsoft Secure Score for Identity because legacy protocols like POP3, IMAP4, and SMTP allow authentication without MFA and bypass modern security controls. Blocking these protocols forces clients to use modern authentication, which strengthens the overall identity security posture and increases the Secure Score. This action does not degrade Defender for Identity's data collection or detection capability; instead, it reduces attack surface, so it is not the action that would lower the score.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Password hash synchronization
Password hash synchronization is a Microsoft Microsoft Entra Connect feature that synchronizes a hash of a user's on-premises Active Directory password to Microsoft Entra ID, enabling cloud-based authentication without additional infrastructure.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.