Courseiva

SC-900 Microsoft Entra Connect Practice Question

A small business wants to enable single sign-on (SSO) for its employees using their existing on-premises Active Directory. They plan to migrate to cloud-based identity management. Which Microsoft service should they use to connect their on-premises directory to Microsoft Entra ID?

⚠ Common exam trap

The primary trap is confusing Microsoft Entra Cloud Sync (a lightweight sync agent) with Microsoft Entra Connect (the full hybrid identity tool). Cloud Sync can sync passwords and enable SSO, but it is designed for simple scenarios; for full SSO with features like seamless SSO, pass-through authentication, or writeback, Microsoft Entra Connect is the recommended service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Connect

Microsoft Entra Connect is the correct tool for synchronizing on-premises Active Directory with Microsoft Entra ID, enabling single sign-on (SSO). Option A is correct because it provides the primary and most comprehensive synchronization service for hybrid identity. Option C (AD FS) is for federation, not the primary synchronization service for connecting on-premises AD to Entra ID. Option B (Microsoft Intune) is for device management, not identity synchronization. Option D (Microsoft Entra Cloud Sync) is a lightweight synchronization service that can connect on-premises AD and enable SSO via Password Hash Synchronization; however, Microsoft Entra Connect offers a broader range of SSO methods (including Pass-through Authentication and Seamless SSO) and comprehensive hybrid identity features (like device writeback and custom sync rules), making it the more complete and standard solution for connecting on-premises AD and enabling full SSO as implied by a general migration scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Connect

    Why this is correct

    This is correct because Microsoft Entra Connect synchronizes on-premises Active Directory with Microsoft Entra ID, enabling SSO through password hash sync or pass-through authentication.

  • Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not an identity synchronization tool.

  • Active Directory Federation Services (AD FS)

    Why it's wrong here

    Active Directory Federation Services (AD FS) provides federated identity and SSO across organizations, but it does not synchronize on-premises directories to Microsoft Entra ID; it relies on an existing synchronization tool like Entra Connect.

  • Microsoft Entra Cloud Sync

    Why it's wrong here

    Microsoft Entra Cloud Sync is a lightweight agent for synchronizing objects from on-premises AD to Entra ID, but it is designed for simple scenarios and does not support all features (e.g., password hash sync) that Entra Connect provides for full SSO.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.