Microsoft MS-102 Microsoft Entra Password Protection And Authentication Troubleshooting Practice Test

 

MS-102 skills 2.2 | 31 original questions

This MS-102 practice set focuses on microsoft entra password protection and authentication troubleshooting through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Wingtip Services is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A post-incident action item requires the tenant to prevent users from choosing organization-specific weak or predictable password terms. The service desk has 51 related tickets from 20 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use the sign-in correlation ID and failure details to trace the failed authentication
  2. Investigate a synchronization health alert in Microsoft Entra Connect Health
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Configure Conditional Access conditions and grant controls for the required scenario
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: E

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Learning point: MS102-T10-Q001: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 2

A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to extend Entra banned-password protection to Active Directory Domain Services password changes. The team will validate the change with 10 pilot groups before expanding it to 68 users. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?

  1. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  2. Start a new Conditional Access policy in report-only mode
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Use Microsoft Entra Connect Health
  5. Enable SSPR for the intended user scope

Correct answer: A

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

B: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q002: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 3

Humongous Insurance is preparing a change requested by the service desk lead. The service owner wants a supportable design that will prevent users from choosing organization-specific weak or predictable password terms. The team must preserve a clear audit trail for the administrative decision. The team will validate the change with 23 pilot groups before expanding it to 85 users. Which option best satisfies the requirement?

  1. Configure the Microsoft Entra authentication methods policy
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Confirm user compromise only when investigation supports that conclusion
  4. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: B

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

C: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q003: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 4

Southridge Video is standardizing administration after several teams used inconsistent procedures. The next migration wave is blocked until the team can extend Entra banned-password protection to Active Directory Domain Services password changes. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 11 users across 13 administrative groups. Which action should the administrator take?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Review synchronization scope and filtering before recreating objects
  3. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  4. Use the Risky users and Risky sign-ins views to investigate identity risk
  5. Use an authentication strength in Conditional Access when a specific strength of MFA is required

Correct answer: C

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

D: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q004: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 5

During a tenant review at Contoso Retail, the tenant administrator identifies one unresolved requirement. A controlled pilot must demonstrate how to prevent users from choosing organization-specific weak or predictable password terms. The team must preserve a clear audit trail for the administrative decision. The team will validate the change with 3 pilot groups before expanding it to 28 users. Which administrative choice should be recommended?

  1. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Check Cloud Sync agent health and provisioning logs
  4. Configure the custom banned password list in Microsoft Entra Password Protection
  5. Define how user risk and sign-in risk will trigger remediation actions

Correct answer: D

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

E: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q005: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 6

An incident review at VanArsdel Media produces a single administrative requirement for the tenant administrator. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to extend Entra banned-password protection to Active Directory Domain Services password changes. The affected scope contains 45 users across 16 administrative groups. The change must be repeatable and supportable after the project team leaves. Which administrative choice should be recommended?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Configure Conditional Access conditions and grant controls for the required scenario
  3. Run IdFix against the on-premises directory before synchronization
  4. Check synchronization logs and the affected object attributes
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: E

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Learning point: MS102-T10-Q006: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 7

An incident review at Consolidated Messenger produces a single administrative requirement for the service desk lead. The current workaround is too manual. The replacement should prevent users from choosing organization-specific weak or predictable password terms. The initial rollout covers 6 locations and approximately 620 managed identities or devices. The design should minimize manual per-user administration where a scoped central control exists. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Configure the custom banned password list in Microsoft Entra Password Protection
  2. Use Microsoft Entra Connect Health
  3. Enable SSPR for the intended user scope
  4. Exclude emergency access accounts from policies that could block all administrators
  5. Use the sign-in correlation ID and failure details to trace the failed authentication

Correct answer: A

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q007: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 8

During a tenant review at Margie Travel, the tenant administrator identifies one unresolved requirement. The support team has reproduced the issue and narrowed it to this requirement: extend Entra banned-password protection to Active Directory Domain Services password changes. The initial rollout covers 19 locations and approximately 790 managed identities or devices. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?

  1. Configure the custom banned password list in Microsoft Entra Password Protection
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  5. Start a new Conditional Access policy in report-only mode

Correct answer: B

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q008: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 9

Proseware Logistics is standardizing administration after several teams used inconsistent procedures. The project board will approve the next step only if it can prevent users from choosing organization-specific weak or predictable password terms. The service desk has 5 related tickets from 9 business units, so the team wants a targeted fix. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which option best satisfies the requirement?

  1. Use the Risky users and Risky sign-ins views to investigate identity risk
  2. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  3. Configure the custom banned password list in Microsoft Entra Password Protection
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Configure the Microsoft Entra authentication methods policy

Correct answer: C

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q009: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 10

The service desk lead at Adventure Works is designing the next phase of the Microsoft 365 rollout. Security and operations teams agree on the target state: extend Entra banned-password protection to Active Directory Domain Services password changes. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The initial rollout covers 22 locations and approximately 220 managed identities or devices. What should the administrator configure first?

  1. Check Cloud Sync agent health and provisioning logs
  2. Define how user risk and sign-in risk will trigger remediation actions
  3. Require multifactor authentication with a Conditional Access grant control
  4. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: D

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q010: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 11

During a tenant review at Humongous Insurance, the Microsoft 365 administrator identifies one unresolved requirement. Audit evidence shows that the current process cannot reliably prevent users from choosing organization-specific weak or predictable password terms. The response must address the cause described in the scenario rather than simply suppressing the symptom. The initial rollout covers 12 locations and approximately 390 managed identities or devices. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Run IdFix against the on-premises directory before synchronization
  2. Check synchronization logs and the affected object attributes
  3. Pilot risk-based access controls with a scoped group before broad enforcement
  4. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: E

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Learning point: MS102-T10-Q011: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 12

A quarterly control review at Litware Financial identifies a gap that must be corrected before the next audit. A controlled pilot must demonstrate how to extend Entra banned-password protection to Active Directory Domain Services password changes. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 2 locations and approximately 560 managed identities or devices. Which administrative choice should be recommended?

  1. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  2. Exclude emergency access accounts from policies that could block all administrators
  3. Use the sign-in correlation ID and failure details to trace the failed authentication
  4. Investigate a synchronization health alert in Microsoft Entra Connect Health
  5. Configure password writeback for supported hybrid SSPR scenarios

Correct answer: A

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

B: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q012: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 13

Consolidated Messenger is standardizing administration after several teams used inconsistent procedures. The implementation review is focused on one outcome: prevent users from choosing organization-specific weak or predictable password terms. The affected scope contains 73 users across 15 administrative groups. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Start a new Conditional Access policy in report-only mode
  4. Review Microsoft Entra sign-in logs and authentication details
  5. Use Microsoft Entra Connect Health

Correct answer: B

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

C: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q013: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 14

An incident review at Lucerne Publishing produces a single administrative requirement for the service desk lead. The current workaround is too manual. The replacement should extend Entra banned-password protection to Active Directory Domain Services password changes. The control owner requires a review after 90 days and evidence from 5 representative cases. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Configure the Microsoft Entra authentication methods policy
  3. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  4. Confirm user compromise only when investigation supports that conclusion
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: C

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q014: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 15

During a tenant review at Trey Research, the identity administrator identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to prevent users from choosing organization-specific weak or predictable password terms. The team will validate the change with 18 pilot groups before expanding it to 16 users. The solution should use a native Microsoft control that matches the stated requirement. Which approach most directly addresses the requirement?

  1. Require multifactor authentication with a Conditional Access grant control
  2. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  3. Review synchronization scope and filtering before recreating objects
  4. Configure the custom banned password list in Microsoft Entra Password Protection
  5. Use the Risky users and Risky sign-ins views to investigate identity risk

Correct answer: D

Why: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

Option review:

A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. It directly addresses the stated requirement.

E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q015: Configure the custom banned password list in Microsoft Entra Password Protection – Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess.

Question 16

Fabrikam Health is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: extend Entra banned-password protection to Active Directory Domain Services password changes. The affected scope contains 33 users across 8 administrative groups. The team does not want to redesign unrelated workloads. Which control should the team use?

  1. Pilot risk-based access controls with a scoped group before broad enforcement
  2. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  3. Correct duplicate or invalid identity attributes before the first sync
  4. Check Cloud Sync agent health and provisioning logs
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: E

Why: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Option review:

A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. It directly addresses the stated requirement.

Learning point: MS102-T10-Q016: Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement – On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes.

Question 17

An incident review at City Power & Light produces a single administrative requirement for the security operations analyst. A controlled pilot must demonstrate how to determine why a user sign-in failed and which authentication step or policy affected it. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The control owner requires a review after 50 days and evidence from 21 representative cases. What is the most appropriate next step?

  1. Review Microsoft Entra sign-in logs and authentication details
  2. Investigate a synchronization health alert in Microsoft Entra Connect Health
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Configure Conditional Access conditions and grant controls for the required scenario
  5. Run IdFix against the on-premises directory before synchronization

Correct answer: A

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q017: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 18

An incident review at Wide World Importers produces a single administrative requirement for the hybrid identity engineer. The next migration wave is blocked until the team can connect a user-reported sign-in failure to the exact Entra sign-in event. The architecture board will reject a choice that solves a different problem from the one stated. The affected scope contains 67 users across 11 administrative groups. What is the most appropriate next step?

  1. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Use Microsoft Entra Connect Health
  4. Enable SSPR for the intended user scope
  5. Exclude emergency access accounts from policies that could block all administrators

Correct answer: B

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q018: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 19

Woodgrove Bank is preparing a change requested by the hybrid identity engineer. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to determine why a user sign-in failed and which authentication step or policy affected it. The service desk has 84 related tickets from 24 business units, so the team wants a targeted fix. The team must preserve a clear audit trail for the administrative decision. What should the administrator configure first?

  1. Confirm user compromise only when investigation supports that conclusion
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  5. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance

Correct answer: C

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

D: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q019: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 20

Adventure Works is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to connect a user-reported sign-in failure to the exact Entra sign-in event. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 10 users across 14 administrative groups. Which approach most directly addresses the requirement?

  1. Review synchronization scope and filtering before recreating objects
  2. Use the Risky users and Risky sign-ins views to investigate identity risk
  3. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync

Correct answer: D

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q020: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 21

The identity administrator at Lucerne Publishing is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: determine why a user sign-in failed and which authentication step or policy affected it. The service desk has 27 related tickets from 4 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. What is the most appropriate next step?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Check Cloud Sync agent health and provisioning logs
  3. Define how user risk and sign-in risk will trigger remediation actions
  4. Require multifactor authentication with a Conditional Access grant control
  5. Review Microsoft Entra sign-in logs and authentication details

Correct answer: E

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Learning point: MS102-T10-Q021: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 22

An incident review at Blue Yonder Airlines produces a single administrative requirement for the messaging administrator. The implementation review is focused on one outcome: connect a user-reported sign-in failure to the exact Entra sign-in event. The control owner requires a review after 44 days and evidence from 17 representative cases. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Use the sign-in correlation ID and failure details to trace the failed authentication
  2. Configure Conditional Access conditions and grant controls for the required scenario
  3. Run IdFix against the on-premises directory before synchronization
  4. Check synchronization logs and the affected object attributes
  5. Pilot risk-based access controls with a scoped group before broad enforcement

Correct answer: A

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q022: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 23

Litware Financial is preparing a change requested by the hybrid identity engineer. The implementation review is focused on one outcome: determine why a user sign-in failed and which authentication step or policy affected it. The affected scope contains 61 users across 7 administrative groups. The team does not want to redesign unrelated workloads. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Enable SSPR for the intended user scope
  2. Review Microsoft Entra sign-in logs and authentication details
  3. Exclude emergency access accounts from policies that could block all administrators
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: B

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q023: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 24

Adventure Works is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The service owner wants a supportable design that will connect a user-reported sign-in failure to the exact Entra sign-in event. The organization wants a reversible rollout with measurable verification before broad enforcement. The team will validate the change with 20 pilot groups before expanding it to 78 users. What should the administrator configure first?

  1. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Use the sign-in correlation ID and failure details to trace the failed authentication
  4. Start a new Conditional Access policy in report-only mode
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: C

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q024: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 25

The security administrator at City Power & Light is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: determine why a user sign-in failed and which authentication step or policy affected it. The control owner requires a review after 95 days and evidence from 10 representative cases. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?

  1. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  2. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  3. Configure the Microsoft Entra authentication methods policy
  4. Review Microsoft Entra sign-in logs and authentication details
  5. Confirm user compromise only when investigation supports that conclusion

Correct answer: D

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

E: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q025: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 26

Woodgrove Bank is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The current workaround is too manual. The replacement should connect a user-reported sign-in failure to the exact Entra sign-in event. The team will validate the change with 23 pilot groups before expanding it to 21 users. The team must preserve a clear audit trail for the administrative decision. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Define how user risk and sign-in risk will trigger remediation actions
  2. Require multifactor authentication with a Conditional Access grant control
  3. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  4. Review synchronization scope and filtering before recreating objects
  5. Use the sign-in correlation ID and failure details to trace the failed authentication

Correct answer: E

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Learning point: MS102-T10-Q026: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 27

During a tenant review at Wide World Importers, the Microsoft 365 administrator identifies one unresolved requirement. The change advisory board wants the smallest supported control that can determine why a user sign-in failed and which authentication step or policy affected it. The service desk has 38 related tickets from 13 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?

  1. Review Microsoft Entra sign-in logs and authentication details
  2. Check synchronization logs and the affected object attributes
  3. Pilot risk-based access controls with a scoped group before broad enforcement
  4. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  5. Correct duplicate or invalid identity attributes before the first sync

Correct answer: A

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q027: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 28

During a tenant review at Northwind Traders, the compliance administrator identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to connect a user-reported sign-in failure to the exact Entra sign-in event. The affected scope contains 55 users across 3 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?

  1. Review Microsoft Entra sign-in logs and authentication details
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Investigate a synchronization health alert in Microsoft Entra Connect Health
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Configure Conditional Access conditions and grant controls for the required scenario

Correct answer: B

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q028: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 29

The operations team at Tailspin Toys needs to resolve an issue without granting broader permissions than necessary. The existing configuration works for normal operations but fails the new requirement to determine why a user sign-in failed and which authentication step or policy affected it. The architecture board will reject a choice that solves a different problem from the one stated. The team will validate the change with 16 pilot groups before expanding it to 72 users. What is the most appropriate next step?

  1. Start a new Conditional Access policy in report-only mode
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Use Microsoft Entra Connect Health
  5. Enable SSPR for the intended user scope

Correct answer: C

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q029: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Question 30

Graphic Design Institute is standardizing administration after several teams used inconsistent procedures. A controlled pilot must demonstrate how to connect a user-reported sign-in failure to the exact Entra sign-in event. The architecture board will reject a choice that solves a different problem from the one stated. The control owner requires a review after 89 days and evidence from 6 representative cases. Which control should the team use?

  1. Configure the Microsoft Entra authentication methods policy
  2. Confirm user compromise only when investigation supports that conclusion
  3. Configure the custom banned password list in Microsoft Entra Password Protection
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: D

Why: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. It directly addresses the stated requirement.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T10-Q030: Use the sign-in correlation ID and failure details to trace the failed authentication – Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt.

Question 31

VanArsdel Media is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The current workaround is too manual. The replacement should determine why a user sign-in failed and which authentication step or policy affected it. The service desk has 15 related tickets from 19 business units, so the team wants a targeted fix. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which control should the team use?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Review synchronization scope and filtering before recreating objects
  3. Use the Risky users and Risky sign-ins views to investigate identity risk
  4. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  5. Review Microsoft Entra sign-in logs and authentication details

Correct answer: E

Why: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. It directly addresses the stated requirement.

Learning point: MS102-T10-Q031: Review Microsoft Entra sign-in logs and authentication details – Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting.

Popular posts

img