easyMultiple Choice
SC-100 Practice Question: A company has a hybrid identity deployment using…
A company has a hybrid identity deployment using Microsoft Entra Connect. They want to ensure that if a user's on-premises account is disabled, the corresponding Microsoft Entra ID account is also disabled within 30 minutes. Which setting should they configure?
⚠ Common exam trap
It's easy for candidates to confuse account status synchronization (which relies on the sync interval) with password-related features like password hash sync or writeback, assuming they also propagate account state changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the synchronization interval for directory changes
Microsoft Entra Connect's default synchronization cycle for directory changes is 30 minutes. By configuring the synchronization interval (via the Microsoft Entra Connect scheduler or PowerShell), you can ensure that disabled on-premises accounts are reflected in Microsoft Entra ID within that timeframe. This setting directly controls how frequently Microsoft Entra Connect processes and synchronizes changes from the on-premises Active Directory to Microsoft Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable password hash synchronization
Why it's wrong here
Password hash synchronization only replicates the hash of each user's password from on-premises AD to Microsoft Entra ID to enable cloud authentication. It does not govern how quickly new user objects, group memberships, or other directory attribute changes are replicated. The timing of directory object replication is controlled by the Microsoft Entra Connect sync cycle, not by this feature. Therefore, enabling it would not reduce the delay for directory changes to appear in the cloud.
- ✓
Configure the synchronization interval for directory changes
Why this is correct
Microsoft Entra Connect's default delta synchronization runs every 30 minutes, which determines how soon on-premises directory changes appear in Microsoft Entra ID. By configuring the synchronization interval to a shorter period, you reduce the latency of object and attribute updates. This is the appropriate action to speed up propagation of directory changes, because the interval directly controls the replication rhythm. Since the step is to take for faster synchronization, this choice satisfies the scenario.
- ✗
Install Microsoft Entra application proxy
Why it's wrong here
Microsoft Entra application proxy is a cloud service that securely publishes on-premises web applications for remote users, using Microsoft Entra ID as the identity provider. It does not alter the synchronization pipeline between on-premises AD and Microsoft Entra ID, nor does it affect how frequently directory changes are replicated. Installing it would merely add remote access capability, leaving the synchronization delay unchanged. Consequently, it is tangential to the goal of accelerating directory change propagation.
- ✗
Enable password writeback
Why it's wrong here
Password writeback is a feature of Microsoft Entra ID self-service password reset that sends password changes performed in the cloud back to on-premises Active Directory. Its purpose is to keep the on-premises password up to date when a cloud user resets it, not to control the frequency of directory object synchronization. This feature operates in the opposite direction (cloud to on-prem) and only applies to password values, so it cannot speed up the replication of general directory changes to Microsoft Entra ID. Thus, enabling it would not address the core issue of synchronization latency.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.