SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company has an on-premises Active Directory and wants to synchronize user accounts to Microsoft Entra ID. They also need to enable password hash synchronization so users can sign in to cloud resources with the same password. Which Microsoft tool should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra Connect with Microsoft Identity Manager (MIM), but MIM is a legacy tool for on-premises identity management and does not natively support password hash synchronization to Microsoft Entra ID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect
Microsoft Entra Connect is the correct tool because it is specifically designed to synchronize on-premises Active Directory user accounts to Microsoft Entra ID and supports password hash synchronization (PHS). PHS enables users to sign in to cloud resources using the same password as their on-premises environment by synchronizing a hash of the password hash to Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra Connect
Why this is correct
Microsoft Entra Connect is the essential Microsoft tool designed to achieve hybrid identity goals by synchronizing users, groups, and contacts from an on-premises Active Directory to Microsoft Entra ID. It facilitates various synchronization features, including password hash synchronization (PHS), pass-through authentication (PTA), and federation with Active Directory Federation Services (AD FS). PHS, enabled by default, securely synchronizes a hash of the user's password hash, allowing users to sign in to cloud services with their on-premises credentials.
- ✗
Microsoft Entra ID Application Proxy
Why it's wrong here
Microsoft Entra ID Application Proxy is a service that enables secure remote access to on-premises web applications from outside the corporate network. It acts as a reverse proxy, allowing users to access internal applications as if they were on the corporate network, leveraging Microsoft Entra ID for authentication and authorization. This service focuses on application access, not on synchronizing user identities or their password hashes from an on-premises directory to the cloud.
- ✗
Microsoft Identity Manager
Why it's wrong here
Microsoft Identity Manager (MIM) handles complex identity lifecycle and governance scenarios, such as cross-forest provisioning or custom workflow-driven identity management, but it does not natively perform password hash synchronisation. The stem specifically requires synchronising password hashes from on-premises Active Directory to Microsoft Entra ID, a function provided exclusively by Microsoft Entra Connect. MIM is tempting because it manages directory synchronisation in heterogeneous environments, yet it lacks the built-in password hash sync engine needed here.
- ✗
Microsoft Entra Domain Services
Why it's wrong here
Microsoft Entra Domain Services provides managed domain services, such as traditional Active Directory features like LDAP, Kerberos, and NTLM authentication, directly within the Azure cloud. It is designed for lifting and shifting legacy applications that require domain-joined virtual machines or traditional authentication protocols without deploying and managing domain controllers. While it uses identities synchronized to Microsoft Entra ID, it does not perform the initial synchronization of users or password hashes from an on-premises Active Directory itself.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Password hash synchronization
Password hash synchronization is a Microsoft Azure AD Connect feature that synchronizes a hash of a user's on-premises Active Directory password to Azure AD, enabling cloud-based authentication without additional infrastructure.
Key term
Microsoft Entra Connect
Microsoft Entra Connect is a tool that synchronizes on-premises Active Directory identities with Microsoft Entra ID (formerly Azure AD) to enable single sign-on and centralized identity management.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.