Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to ensure that when a user's on-premises Active Directory account is disabled, their Microsoft Entra ID account is also disabled within 30 minutes. What should you do?

⚠ Common exam trap

Many exam-takers confuse password hash synchronization (which handles password changes) with account status synchronization, mistakenly thinking that disabling an on-premises account automatically disables the cloud account without configuring attribute sync and schedule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra Connect to sync the 'userAccountControl' attribute and set the sync frequency to 30 minutes.

Disabling an on-premises Active Directory account sets the 'userAccountControl' attribute (specifically the ACCOUNTDISABLE flag, bit 2). By configuring Microsoft Entra Connect to sync this attribute and setting the sync frequency to 30 minutes, the disabled state is replicated to Microsoft Entra ID within that interval, ensuring the cloud account is also disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Entra Connect cloud sync.

    Why it's wrong here

    Enabling Microsoft Entra Connect cloud sync does not modify the synchronization schedule of an existing Microsoft Entra Connect sync engine. Cloud sync is an alternative provisioning service that runs on its own independent cycle, but it does not provide a configuration option to change the frequency for account status synchronization on the current connector. To reflect account status changes quickly, you must change the sync interval on the existing Microsoft Entra Connect server.

  • ✗

    Configure password hash synchronization to run every 30 minutes.

    Why it's wrong here

    Password hash synchronization is responsible for replicating password hashes from on-premises Active Directory to Microsoft Entra ID, not for reflecting whether an account is enabled or disabled. The account status is determined by the userAccountControl attribute, and simply running password hash sync more frequently will not update accountEnabled status. Even if the PHS cycle is set to 30 minutes, account status changes would still rely on the Microsoft Entra Connect sync cycle, which already runs at that interval by default.

  • ✓

    Configure Microsoft Entra Connect to sync the 'userAccountControl' attribute and set the sync frequency to 30 minutes.

    Why this is correct

    The userAccountControl attribute stores bit flags such as UF_ACCOUNTDISABLE, which directly determines whether the account is enabled. Synchronizing this attribute through Microsoft Entra Connect propagates on-premises account status changes to Microsoft Entra ID. By explicitly setting the synchronization frequency to 30 minutes, you ensure that the next sync cycle will reflect the updated account state, making the current configuration the correct method to address the requirement.

  • ✗

    Enable password writeback.

    Why it's wrong here

    Password writeback is a feature that allows password changes performed in the cloud to be written back to the on-premises Active Directory, typically for self-service password reset scenarios. It does not synchronize the userAccountControl attribute or any other account-status flags. Enabling password writeback has no effect on the speed or content of the forward synchronization of account status from on-premises to Azure.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.