MS-102 Microsoft 365 Administrator Expert Configuring Identity Synchronization 2 — Questions and Answers
Question 1: An administrator needs to synchronize only specific OUs from on-premises Active Directory to Azure AD. Which feature in Azure AD Connect should they configure?
- Domain and OU filtering (Correct answer)
- Attribute filtering
- Group-based filtering
- Source anchor filtering
Correct answer: Domain and OU filtering
Domain and OU filtering in Azure AD Connect allows administrators to select specific OUs to include or exclude from synchronization.
Question 2: Which attribute is used by default as the source anchor (immutableId) in Azure AD Connect when syncing users?
- userPrincipalName
- objectGUID (Correct answer)
- sAMAccountName
Correct answer: objectGUID
ObjectGUID is the default source anchor attribute used by Azure AD Connect to uniquely and immutably identify objects.
Question 3: A company has a staged rollout and wants to enable Password Hash Synchronization without affecting existing users who use pass-through authentication. What should they configure?
- Enable PHS as a backup for PTA (Correct answer)
- Switch the sign-in method to PHS in Azure AD Connect
- Configure PHS in staging mode only
- Set up a separate Azure AD Connect server for PHS
Correct answer: Enable PHS as a backup for PTA
Enabling PHS as a backup for PTA ensures seamless SSO failover without changing the primary authentication method for users.
Question 4: What is the minimum Azure AD Connect sync interval when using the scheduler?
- 10 minutes
- 20 minutes
- 30 minutes (Correct answer)
- 60 minutes
Correct answer: 30 minutes
The minimum synchronization interval for the Azure AD Connect scheduler is 30 minutes; setting it lower is not supported.
Question 5: An administrator wants to prevent accidental mass deletions during synchronization. Which Azure AD Connect feature helps with this?
- Soft delete protection
- Accidental delete prevention threshold (Correct answer)
- Recycle Bin integration
- Staging mode
Correct answer: Accidental delete prevention threshold
The accidental delete prevention threshold in Azure AD Connect halts a sync cycle if deletions exceed a configured number.
Question 6: When configuring Azure AD Connect Health, which role is required to view the health data in the Azure portal?
- Security Reader
- Global Reader (Correct answer)
- Reports Reader
- Security Administrator
Correct answer: Global Reader
The Global Reader role has sufficient permissions to view Azure AD Connect Health monitoring data in the portal.
Question 7: A hybrid identity administrator needs to writeback group membership changes from Azure AD to on-premises AD. Which feature must be enabled?
- Device writeback
- Password writeback
- Group writeback (Correct answer)
- Exchange hybrid writeback
Correct answer: Group writeback
Group writeback allows Azure AD groups to be written back to on-premises Active Directory so they can be used by on-premises applications.
An administrator needs to synchronize only specific OUs from on-premises Active Directory to Azure AD.
Which feature in Azure AD Connect should they configure?