SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to allow users to sign in to Microsoft 365 services using their existing on-premises Active Directory credentials without maintaining a separate password in the cloud. The company requires that authentication be validated directly against on-premises domain controllers. Which Microsoft Entra authentication method should they implement?
⚠ Common exam trap
Many exam-takers confuse pass-through authentication with password hash synchronization, but only pass-through authentication validates credentials on-premises in real time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-through authentication
Pass-through authentication validates user credentials directly against on-premises Active Directory, ensuring that password policies and account status are enforced in real time. It requires a lightweight agent and does not store password hashes in the cloud. This method is ideal when organizations want to maintain full control over authentication without complex federation infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Certificate-based authentication
Why it's wrong here
Certificate-based authentication uses digital certificates to authenticate users instead of passwords, often for strong authentication scenarios. It does not leverage on-premises Active Directory credentials directly. While it can be used with Microsoft Entra ID, it requires a public key infrastructure and does not meet the requirement of using existing on-premises credentials for validation against domain controllers.
- ✗
Password hash synchronization
Why it's wrong here
Password hash synchronization copies a hash of the on-premises password to Microsoft Entra ID, and authentication occurs in the cloud. While it allows users to use the same password, it does not validate credentials directly against on-premises domain controllers. This method introduces a delay in password change propagation and does not meet the requirement for direct on-premises validation.
- ✓
Pass-through authentication
Why this is correct
Pass-through authentication (PTA) uses a lightweight agent on-premises to validate user credentials directly against Active Directory. When users sign in, their passwords are encrypted and sent to the agent, which verifies them with domain controllers. This meets the requirement of direct validation without storing passwords in the cloud. It provides a seamless experience and is ideal when organizations want to enforce on-premises password policies in real time.
- ✗
Federation with Active Directory Federation Services (AD FS)
Why it's wrong here
Federation with AD FS also validates credentials on-premises, but it requires a complex infrastructure including AD FS servers and web application proxies. While it meets the requirement, it is more costly and complex to maintain. The scenario does not specify a need for federation, and PTA is a simpler solution that achieves the same goal without the overhead of deploying and managing AD FS.
Go deeper
Related to this question
Learn chapter
Authentication vs Authorisation
Key term
Federation
Federation is a system that lets you use one set of login credentials (like your work email and password) to access resources across different organizations or services without needing separate accounts for each one.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.