SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company has a Microsoft Entra ID tenant and an on-premises Active Directory Domain Services (AD DS) forest. They need to synchronize user accounts, groups, and passwords from AD DS to Microsoft Entra ID. Due to network restrictions, they prefer a lightweight agent that can be deployed on-premises and supports staging mode for testing. Which identity synchronization tool should they use?
⚠ Common exam trap
Watch out — candidates often confuse 'Cloud Sync' as the lightweight agent because it is simpler, but they overlook that Cloud Sync does not support staging mode, which is explicitly required in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect Sync
Microsoft Entra Connect Sync is the correct choice because it is the full-featured synchronization tool that supports staging mode for testing and can be deployed as a lightweight agent on-premises. It synchronizes user accounts, groups, and passwords from AD DS to Microsoft Entra ID, including password hash synchronization, pass-through authentication, and federation integration, making it ideal for complex on-premises environments with network restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra Connect Sync
Why this is correct
Microsoft Entra Connect Sync is the primary and recommended tool for establishing hybrid identity by synchronizing users, groups, and devices from a single on-premises Active Directory Domain Services (AD DS) forest to Microsoft Entra ID. It supports various authentication methods like Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and federation with AD FS. Its robust feature set includes attribute filtering, writeback capabilities, and a crucial staging mode for testing configurations before full deployment, making it ideal for most enterprise scenarios.
- ✗
Microsoft Entra Connect Health
Why it's wrong here
Microsoft Entra Connect Health is a monitoring service designed to provide insights into the health and performance of your hybrid identity components, including Microsoft Entra Connect Sync servers, Active Directory Federation Services (AD FS), and Active Directory Domain Services (AD DS) domain controllers. It offers a centralized dashboard for alerts, usage analytics, and error reporting, helping administrators proactively identify and troubleshoot synchronization issues. However, it does not perform any identity synchronization itself; its role is purely diagnostic and reporting.
- ✗
Microsoft Entra Cloud Sync
Why it's wrong here
Microsoft Entra Cloud Sync offers a lightweight, cloud-managed synchronization agent primarily designed for organizations with multiple disconnected on-premises Active Directory forests or those requiring simpler provisioning without a full Microsoft Entra Connect Sync server. While it automates user and group provisioning from AD DS to Microsoft Entra ID, it has a more limited feature set compared to Connect Sync, lacking advanced customization options, writeback capabilities, and a staging mode. Therefore, for a single, potentially complex AD DS forest requiring comprehensive hybrid identity features, Cloud Sync is generally not the optimal choice.
- ✗
Microsoft Identity Manager (MIM)
Why it's wrong here
Microsoft Identity Manager (MIM) is an on-premises identity management solution tailored for complex, heterogeneous environments, enabling synchronization between various on-premises directories, certificate management, and self-service capabilities within the corporate network. While MIM possesses the capability to synchronize identities to Microsoft Entra ID, it is not designed as the default or standard tool for this purpose, requiring extensive configuration and custom development. Its use is typically reserved for highly specialized scenarios where its advanced on-premises identity orchestration features are indispensable, rather than basic directory synchronization.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Password hash synchronization
Password hash synchronization is a Microsoft Azure AD Connect feature that synchronizes a hash of a user's on-premises Active Directory password to Azure AD, enabling cloud-based authentication without additional infrastructure.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.