Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra Domain Services (Microsoft Entra Domain Services). You need to ensure that legacy applications that require NTLM authentication can still authenticate against the managed domain. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse enabling NTLM v1 with disabling it for security, or think that password hash synchronization alone enables NTLM authentication, but the key is that NTLM v1 must be explicitly enabled on the managed domain for legacy apps that require it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NTLM v1 authentication on the managed domain

Legacy applications that require NTLM authentication must have NTLM v1 enabled on the managed domain because Microsoft Entra Domain Services, by default, disables NTLM v1 for security reasons. Enabling NTLM v1 allows these older applications to authenticate against the managed domain using the NTLM protocol, which is necessary when Kerberos is not supported.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Kerberos delegation

    Why it's wrong here

    Kerberos delegation is a modern authentication flow that enables a service to obtain a ticket from the Kerberos Distribution Center (KDC) and reuse it to access another service, typically for multi-hop or constrained delegation scenarios. It has nothing to do with the protocol version offered by the managed domain for incoming authentication, and it does not lower the authentication protocol to NTLM v1. Moreover, legacy applications that require NTLM v1 are often unable to participate in Kerberos exchanges because they lack Service Principal Names (SPNs) or proper Kerberos support. Configuring Kerberos delegation, therefore, does not fulfill the requirement to let these legacy apps authenticate, and the correct action remains enabling NTLM v1 on the managed domain.

  • ✗

    Disable NTLM v1 authentication on the managed domain

    Why it's wrong here

    Disabling NTLM v1 authentication is the exact opposite of what is needed, because legacy applications that rely on NTLM v1 will be presented with an authentication failure if this protocol is turned off. Microsoft's guidance generally encourages disabling weak protocols like NTLM v1 to improve security, but such a hardening measure breaks compatibility with applications that explicitly require this older protocol. In Microsoft Entra Domain Services, you can control NTLM settings via security policy, and setting the policy to reject NTLM v1 would block these legacy clients. Since the requirement is to support legacy applications that specifically need NTLM v1, the managed domain must be configured to allow it, not to disable it.

  • ✓

    Enable NTLM v1 authentication on the managed domain

    Why this is correct

    Enabling NTLM v1 authentication on the Microsoft Entra Domain Services managed domain directly addresses the requirement for legacy applications. Microsoft Entra Domain Services typically prioritises more secure protocols like NTLM v2 and Kerberos. However, older applications often lack support for these newer versions and specifically mandate NTLM v1. Configuring the managed domain to support NTLM v1 allows these legacy applications to successfully authenticate, ensuring their continued operation within the environment.

  • ✗

    Enable password hash synchronization for the managed domain

    Why it's wrong here

    Password hash synchronization is a foundational prerequisite for Microsoft Entra Domain Services in a hybrid environment, because the managed domain needs cached password hashes to perform NTLM and Kerberos authentication for cloud-synced user accounts. However, enabling password hash synchronization does not by itself change which authentication protocol is negotiated at the protocol level; it only ensures that the necessary password hashes are available on the managed domain. The managed domain still enforces its own authentication policy, and by default it might accept only NTLM v2 or Kerberos. Therefore, even if password hash synchronization is already running, you must separately configure the managed domain to enable NTLM v1 so that legacy applications can authenticate successfully.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.