MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft Entra ID with Application Proxy to publish on-premises web apps. Users report that they are prompted for credentials multiple times when accessing an app. You need to reduce the number of authentication prompts. What should you configure?
⚠ Common exam trap
It's easy for candidates to confuse session lifetime settings (Option C) with SSO configuration, thinking that extending session duration will reduce prompts, when in fact the issue is the lack of credential delegation between the proxy and the backend app.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Kerberos Constrained Delegation (KCD) for single sign-on
The multiple authentication prompts indicate that the Application Proxy is not passing the user's credentials seamlessly to the on-premises app. Enabling Kerberos Constrained Delegation (KCD) allows the Application Proxy connector to impersonate the user and obtain a Kerberos ticket for the backend application, enabling single sign-on (SSO) and eliminating repeated credential prompts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure MFA for the application
Why it's wrong here
Enabling Microsoft Entra ID MFA (Entra ID MFA) would actually increase the number of authentication prompts for the on-premises application, not reduce them. MFA forces an additional secondary verification (e.g., phone, authenticator) each time a new token or session is requested, often on every fresh sign-in. Since the goal is to eliminate repeated credential prompts, adding a second factor compounds the friction rather than providing the seamless single sign-on experience the user wants.
- ✗
Disable pre-authentication for the application
Why it's wrong here
Disabling pre-authentication on the Application Proxy would instruct Entra ID to forward requests directly to the backend application without first validating the user's claims. This effectively bypasses Entra ID authentication, meaning users could reach the app with no organization identity check, and all policy controls such as Conditional Access, MFA, and the existing SSO provider become inoperative. While it may appear to remove prompts, it does so at the cost of losing all central authentication and security protection, so it is not an acceptable solution.
- ✗
Increase the session lifetime in conditional access
Why it's wrong here
Increasing the session lifetime in Conditional Access extends the validity period of an already-issued session token or cookie, so users might not be asked to sign in again for a longer interval. However, it does not prevent the user from being prompted for credentials on the initial access attempt to the on-premises application, which is the exact problem to solve. The first request to the Application Proxy still requires Entra ID authentication, and once the session eventually expires or is invalidated, the user faces the same prompt again. It also does nothing to bridge the authentication boundary to the on-premises Kerberos-based app.
- ✓
Enable Kerberos Constrained Delegation (KCD) for single sign-on
Why this is correct
Enabling Kerberos Constrained Delegation (KCD) is the correct approach for single sign-on to a legacy on-premises application published through Application Proxy. After the user authenticates to Entra ID, the Application Proxy connector uses the user's token to obtain a Kerberos service ticket from on-premises Active Directory on behalf of the user, then presents that ticket to the backend application. This avoids a second credential prompt because the backend app sees an already authenticated user. KCD requires the application to support Windows Integrated Authentication and careful SPN configuration, but it delivers true SSO without extra MFA prompts or session-lengthening workarounds.
Go deeper
Related to this question
Learn chapter
Hybrid Modern Authentication
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.