Microsoft MS-102 Synchronization Monitoring And Troubleshooting With Connect Health Practice Test

 

MS-102 skills 2.1 | 31 original questions

This MS-102 practice set focuses on synchronization monitoring and troubleshooting with connect health through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

The operations team at Trey Research needs to resolve an issue without granting broader permissions than necessary. Security and operations teams agree on the target state: monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 3 locations and approximately 380 managed identities or devices. Which approach most directly addresses the requirement?

  1. Exclude emergency access accounts from policies that could block all administrators
  2. Check Cloud Sync agent health and provisioning logs
  3. Configure the Microsoft Entra authentication methods policy
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Use Microsoft Entra Connect Health

Correct answer: E

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Learning point: MS102-T08-Q001: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 2

The tenant administrator at Humongous Insurance is designing the next phase of the Microsoft 365 rollout. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to determine whether a sync service problem is infrastructure-related before changing synchronization rules. The control owner requires a review after 55 days and evidence from 16 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which administrative choice should be recommended?

  1. Investigate a synchronization health alert in Microsoft Entra Connect Health
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Start a new Conditional Access policy in report-only mode
  4. Check synchronization logs and the affected object attributes
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: A

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q002: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 3

During a tenant review at Coho Winery, the identity administrator identifies one unresolved requirement. A controlled pilot must demonstrate how to monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 72 related tickets from 6 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Use Microsoft Entra Connect Health
  3. Configure the custom banned password list in Microsoft Entra Password Protection
  4. Confirm user compromise only when investigation supports that conclusion
  5. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: B

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q003: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 4

Margie Travel has completed a pilot and must now choose the production administration approach. An internal assessment finds the control technically functional but unable to determine whether a sync service problem is infrastructure-related before changing synchronization rules. The initial rollout covers 19 locations and approximately 890 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Require multifactor authentication with a Conditional Access grant control
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Investigate a synchronization health alert in Microsoft Entra Connect Health
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Use the Risky users and Risky sign-ins views to investigate identity risk

Correct answer: C

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q004: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 5

During a tenant review at Coho Winery, the messaging administrator identifies one unresolved requirement. The organization is replacing a manual process. The replacement must monitor synchronization infrastructure health and receive alerts about supported hybrid identity components while remaining centrally manageable. The initial rollout covers 9 locations and approximately 150 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which administrative choice should be recommended?

  1. Pilot risk-based access controls with a scoped group before broad enforcement
  2. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  3. Run IdFix against the on-premises directory before synchronization
  4. Use Microsoft Entra Connect Health
  5. Enable SSPR for the intended user scope

Correct answer: D

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q005: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 6

A quarterly control review at Proseware Logistics identifies a gap that must be corrected before the next audit. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to determine whether a sync service problem is infrastructure-related before changing synchronization rules. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 32 users across 22 administrative groups. What should the administrator configure first?

  1. Configure the Microsoft Entra authentication methods policy
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Configure Conditional Access conditions and grant controls for the required scenario
  4. Review synchronization scope and filtering before recreating objects
  5. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: E

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Learning point: MS102-T08-Q006: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 7

During a tenant review at Tailspin Toys, the service desk lead identifies one unresolved requirement. The service owner wants a supportable design that will monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The control owner requires a review after 49 days and evidence from 12 representative cases. Which option best satisfies the requirement?

  1. Use Microsoft Entra Connect Health
  2. Check synchronization logs and the affected object attributes
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Review Microsoft Entra sign-in logs and authentication details
  5. Exclude emergency access accounts from policies that could block all administrators

Correct answer: A

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q007: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 8

During a tenant review at Litware Financial, the security operations analyst identifies one unresolved requirement. An internal assessment finds the control technically functional but unable to determine whether a sync service problem is infrastructure-related before changing synchronization rules. The affected scope contains 66 users across 2 administrative groups. The architecture board will reject a choice that solves a different problem from the one stated. Which control should the team use?

  1. Confirm user compromise only when investigation supports that conclusion
  2. Investigate a synchronization health alert in Microsoft Entra Connect Health
  3. Use Microsoft Entra Connect Health
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: B

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q008: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 9

Adventure Works is preparing a change requested by the hybrid identity engineer. Audit evidence shows that the current process cannot reliably monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The change must be repeatable and supportable after the project team leaves. The affected scope contains 83 users across 15 administrative groups. Which action should the administrator take?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Use the Risky users and Risky sign-ins views to investigate identity risk
  3. Use Microsoft Entra Connect Health
  4. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: C

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q009: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 10

The security operations analyst at Margie Travel is designing the next phase of the Microsoft 365 rollout. A post-incident action item requires the tenant to determine whether a sync service problem is infrastructure-related before changing synchronization rules. The affected scope contains 9 users across 5 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which administrative choice should be recommended?

  1. Run IdFix against the on-premises directory before synchronization
  2. Enable SSPR for the intended user scope
  3. Define how user risk and sign-in risk will trigger remediation actions
  4. Investigate a synchronization health alert in Microsoft Entra Connect Health
  5. Require multifactor authentication with a Conditional Access grant control

Correct answer: D

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

E: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q010: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 11

Alpine Ski House is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The administrator must avoid granting unrelated tenant-wide privilege. The team will validate the change with 18 pilot groups before expanding it to 26 users. Which control should the team use?

  1. Configure Conditional Access conditions and grant controls for the required scenario
  2. Review synchronization scope and filtering before recreating objects
  3. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  4. Pilot risk-based access controls with a scoped group before broad enforcement
  5. Use Microsoft Entra Connect Health

Correct answer: E

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Learning point: MS102-T08-Q011: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 12

The operations team at Blue Yonder Airlines needs to resolve an issue without granting broader permissions than necessary. Audit evidence shows that the current process cannot reliably determine whether a sync service problem is infrastructure-related before changing synchronization rules. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 43 related tickets from 8 business units, so the team wants a targeted fix. Which control should the team use?

  1. Investigate a synchronization health alert in Microsoft Entra Connect Health
  2. Review Microsoft Entra sign-in logs and authentication details
  3. Exclude emergency access accounts from policies that could block all administrators
  4. Check Cloud Sync agent health and provisioning logs
  5. Configure the Microsoft Entra authentication methods policy

Correct answer: A

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q012: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 13

The operations team at Tailspin Toys needs to resolve an issue without granting broader permissions than necessary. The service owner wants a supportable design that will monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 21 locations and approximately 600 managed identities or devices. Which action should the administrator take?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Use Microsoft Entra Connect Health
  3. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  4. Start a new Conditional Access policy in report-only mode
  5. Check synchronization logs and the affected object attributes

Correct answer: B

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q013: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 14

A quarterly control review at Southridge Video identifies a gap that must be corrected before the next audit. The next migration wave is blocked until the team can determine whether a sync service problem is infrastructure-related before changing synchronization rules. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The team will validate the change with 11 pilot groups before expanding it to 77 users. Which action should the administrator take?

  1. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  2. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  3. Investigate a synchronization health alert in Microsoft Entra Connect Health
  4. Configure the custom banned password list in Microsoft Entra Password Protection
  5. Confirm user compromise only when investigation supports that conclusion

Correct answer: C

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q014: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 15

A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to monitor synchronization infrastructure health and receive alerts about supported hybrid identity components. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 94 related tickets from 24 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Define how user risk and sign-in risk will trigger remediation actions
  2. Require multifactor authentication with a Conditional Access grant control
  3. Correct duplicate or invalid identity attributes before the first sync
  4. Use Microsoft Entra Connect Health
  5. Configure password writeback for supported hybrid SSPR scenarios

Correct answer: D

Why: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

Option review:

A: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. It directly addresses the stated requirement.

E: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q015: Use Microsoft Entra Connect Health – Connect Health centralizes health monitoring and alerts for supported Entra Connect components.

Question 16

The operations team at Southridge Video needs to resolve an issue without granting broader permissions than necessary. The change advisory board wants the smallest supported control that can determine whether a sync service problem is infrastructure-related before changing synchronization rules. The team will validate the change with 14 pilot groups before expanding it to 20 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which administrative choice should be recommended?

  1. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  2. Pilot risk-based access controls with a scoped group before broad enforcement
  3. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  4. Run IdFix against the on-premises directory before synchronization
  5. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: E

Why: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Option review:

A: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. It directly addresses the stated requirement.

Learning point: MS102-T08-Q016: Investigate a synchronization health alert in Microsoft Entra Connect Health – Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues.

Question 17

Datum Dynamics is standardizing administration after several teams used inconsistent procedures. Administrators have confirmed the present design does not troubleshoot why a specific hybrid identity object failed to synchronize. The initial rollout covers 4 locations and approximately 370 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?

  1. Check synchronization logs and the affected object attributes
  2. Check Cloud Sync agent health and provisioning logs
  3. Configure the Microsoft Entra authentication methods policy
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Configure Conditional Access conditions and grant controls for the required scenario

Correct answer: A

Why: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Option review:

A: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q017: Check synchronization logs and the affected object attributes – Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved.

Question 18

An incident review at Proseware Logistics produces a single administrative requirement for the service desk lead. The support team has reproduced the issue and narrowed it to this requirement: troubleshoot a Cloud Sync flow that stopped provisioning scoped users. The service desk has 54 related tickets from 17 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which administrative choice should be recommended?

  1. Start a new Conditional Access policy in report-only mode
  2. Check Cloud Sync agent health and provisioning logs
  3. Investigate a synchronization health alert in Microsoft Entra Connect Health
  4. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  5. Review Microsoft Entra sign-in logs and authentication details

Correct answer: B

Why: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Option review:

A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q018: Check Cloud Sync agent health and provisioning logs – Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling.

Question 19

Wide World Importers is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A post-incident action item requires the tenant to determine why an otherwise valid user never enters the synchronization pipeline. The initial rollout covers 7 locations and approximately 710 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which approach most directly addresses the requirement?

  1. Configure the custom banned password list in Microsoft Entra Password Protection
  2. Confirm user compromise only when investigation supports that conclusion
  3. Review synchronization scope and filtering before recreating objects
  4. Use Microsoft Entra Connect Health
  5. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync

Correct answer: C

Why: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Option review:

A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q019: Review synchronization scope and filtering before recreating objects – OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem.

Question 20

The compliance administrator at Alpine Ski House is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to troubleshoot why a specific hybrid identity object failed to synchronize. The affected scope contains 88 users across 20 administrative groups. The architecture board will reject a choice that solves a different problem from the one stated. What should the administrator configure first?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Configure password writeback for supported hybrid SSPR scenarios
  3. Use the Risky users and Risky sign-ins views to investigate identity risk
  4. Check synchronization logs and the affected object attributes
  5. Use an authentication strength in Conditional Access when a specific strength of MFA is required

Correct answer: D

Why: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

E: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q020: Check synchronization logs and the affected object attributes – Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved.

Question 21

Blue Yonder Airlines has completed a pilot and must now choose the production administration approach. Before the tenant expands to another business unit, the administrator must troubleshoot a Cloud Sync flow that stopped provisioning scoped users. The team will validate the change with 10 pilot groups before expanding it to 14 users. The architecture board will reject a choice that solves a different problem from the one stated. Which administrative choice should be recommended?

  1. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  2. Run IdFix against the on-premises directory before synchronization
  3. Enable SSPR for the intended user scope
  4. Define how user risk and sign-in risk will trigger remediation actions
  5. Check Cloud Sync agent health and provisioning logs

Correct answer: E

Why: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Option review:

A: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Learning point: MS102-T08-Q021: Check Cloud Sync agent health and provisioning logs – Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling.

Question 22

The service desk lead at Litware Financial is designing the next phase of the Microsoft 365 rollout. The next migration wave is blocked until the team can determine why an otherwise valid user never enters the synchronization pipeline. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 31 days and evidence from 23 representative cases. Which option best satisfies the requirement?

  1. Review synchronization scope and filtering before recreating objects
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Configure Conditional Access conditions and grant controls for the required scenario
  4. Check Cloud Sync agent health and provisioning logs
  5. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance

Correct answer: A

Why: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Option review:

A: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q022: Review synchronization scope and filtering before recreating objects – OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem.

Question 23

A quarterly control review at Blue Yonder Airlines identifies a gap that must be corrected before the next audit. The implementation review is focused on one outcome: troubleshoot why a specific hybrid identity object failed to synchronize. The initial rollout covers 13 locations and approximately 480 managed identities or devices. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  2. Check synchronization logs and the affected object attributes
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Exclude emergency access accounts from policies that could block all administrators
  5. Check Cloud Sync agent health and provisioning logs

Correct answer: B

Why: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Option review:

A: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q023: Check synchronization logs and the affected object attributes – Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved.

Question 24

An incident review at Wingtip Services produces a single administrative requirement for the governance lead. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to troubleshoot a Cloud Sync flow that stopped provisioning scoped users. The team will validate the change with 3 pilot groups before expanding it to 65 users. The organization wants a reversible rollout with measurable verification before broad enforcement. What should the administrator configure first?

  1. Use Microsoft Entra Connect Health
  2. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  3. Check Cloud Sync agent health and provisioning logs
  4. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  5. Start a new Conditional Access policy in report-only mode

Correct answer: C

Why: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Option review:

A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q024: Check Cloud Sync agent health and provisioning logs – Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling.

Question 25

The operations team at Margie Travel needs to resolve an issue without granting broader permissions than necessary. Security and operations teams agree on the target state: determine why an otherwise valid user never enters the synchronization pipeline. The response must address the cause described in the scenario rather than simply suppressing the symptom. The service desk has 82 related tickets from 16 business units, so the team wants a targeted fix. Which option best satisfies the requirement?

  1. Use the Risky users and Risky sign-ins views to investigate identity risk
  2. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  3. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  4. Review synchronization scope and filtering before recreating objects
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: D

Why: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Option review:

A: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q025: Review synchronization scope and filtering before recreating objects – OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem.

Question 26

During a tenant review at Fourth Coffee, the hybrid identity engineer identifies one unresolved requirement. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to troubleshoot why a specific hybrid identity object failed to synchronize. The change must be repeatable and supportable after the project team leaves. The service desk has 8 related tickets from 6 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Enable SSPR for the intended user scope
  2. Define how user risk and sign-in risk will trigger remediation actions
  3. Require multifactor authentication with a Conditional Access grant control
  4. Correct duplicate or invalid identity attributes before the first sync
  5. Check synchronization logs and the affected object attributes

Correct answer: E

Why: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Option review:

A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Learning point: MS102-T08-Q026: Check synchronization logs and the affected object attributes – Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved.

Question 27

The Microsoft 365 administrator at Proseware Logistics is designing the next phase of the Microsoft 365 rollout. Audit evidence shows that the current process cannot reliably troubleshoot a Cloud Sync flow that stopped provisioning scoped users. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 25 related tickets from 19 business units, so the team wants a targeted fix. Which control should the team use?

  1. Check Cloud Sync agent health and provisioning logs
  2. Review synchronization scope and filtering before recreating objects
  3. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  4. Pilot risk-based access controls with a scoped group before broad enforcement
  5. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement

Correct answer: A

Why: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Option review:

A: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q027: Check Cloud Sync agent health and provisioning logs – Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling.

Question 28

During a tenant review at Adventure Works, the hybrid identity engineer identifies one unresolved requirement. A controlled pilot must demonstrate how to determine why an otherwise valid user never enters the synchronization pipeline. The architecture board will reject a choice that solves a different problem from the one stated. The team will validate the change with 9 pilot groups before expanding it to 42 users. Which administrative choice should be recommended?

  1. Exclude emergency access accounts from policies that could block all administrators
  2. Review synchronization scope and filtering before recreating objects
  3. Check synchronization logs and the affected object attributes
  4. Configure the Microsoft Entra authentication methods policy
  5. Use the sign-in correlation ID and failure details to trace the failed authentication

Correct answer: B

Why: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Option review:

A: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

C: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q028: Review synchronization scope and filtering before recreating objects – OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem.

Question 29

Wingtip Services is standardizing administration after several teams used inconsistent procedures. The organization is replacing a manual process. The replacement must troubleshoot why a specific hybrid identity object failed to synchronize while remaining centrally manageable. The initial rollout covers 22 locations and approximately 590 managed identities or devices. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which administrative choice should be recommended?

  1. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  2. Start a new Conditional Access policy in report-only mode
  3. Check synchronization logs and the affected object attributes
  4. Investigate a synchronization health alert in Microsoft Entra Connect Health
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: C

Why: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. It directly addresses the stated requirement.

D: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q029: Check synchronization logs and the affected object attributes – Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved.

Question 30

During a tenant review at Lucerne Publishing, the governance lead identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to troubleshoot a Cloud Sync flow that stopped provisioning scoped users. The affected scope contains 76 users across 12 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which administrative choice should be recommended?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Confirm user compromise only when investigation supports that conclusion
  4. Check Cloud Sync agent health and provisioning logs
  5. Use Microsoft Entra Connect Health

Correct answer: D

Why: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. It directly addresses the stated requirement.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T08-Q030: Check Cloud Sync agent health and provisioning logs – Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling.

Question 31

The operations team at Alpine Ski House needs to resolve an issue without granting broader permissions than necessary. An internal assessment finds the control technically functional but unable to determine why an otherwise valid user never enters the synchronization pipeline. The service desk has 93 related tickets from 2 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which option best satisfies the requirement?

  1. Require multifactor authentication with a Conditional Access grant control
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Use the Risky users and Risky sign-ins views to investigate identity risk
  5. Review synchronization scope and filtering before recreating objects

Correct answer: E

Why: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Option review:

A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. It directly addresses the stated requirement.

Learning point: MS102-T08-Q031: Review synchronization scope and filtering before recreating objects – OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem.

Popular posts

img