Microsoft MS-102 Authentication Methods And Self Service Password Reset Practice Test

 

MS-102 skills 2.2 | 34 original questions

This MS-102 practice set focuses on authentication methods and self service password reset through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

During a tenant review at Fourth Coffee, the security operations analyst identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to control which modern authentication methods users are allowed or targeted to register and use. The control owner requires a review after 19 days and evidence from 15 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which administrative choice should be recommended?

  1. Configure the Microsoft Entra authentication methods policy
  2. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  3. Correct duplicate or invalid identity attributes before the first sync
  4. Check Cloud Sync agent health and provisioning logs
  5. Define how user risk and sign-in risk will trigger remediation actions

Correct answer: A

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q001: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 2

The messaging administrator at Fourth Coffee is designing the next phase of the Microsoft 365 rollout. Before the tenant expands to another business unit, the administrator must strengthen authentication against credential phishing rather than relying only on passwords. The affected scope contains 36 users across 5 administrative groups. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which approach most directly addresses the requirement?

  1. Use the sign-in correlation ID and failure details to trace the failed authentication
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Configure Conditional Access conditions and grant controls for the required scenario
  4. Run IdFix against the on-premises directory before synchronization
  5. Check synchronization logs and the affected object attributes

Correct answer: B

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q002: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 3

During a tenant review at Trey Research, the governance lead identifies one unresolved requirement. Security and operations teams agree on the target state: control which modern authentication methods users are allowed or targeted to register and use. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 53 users across 18 administrative groups. Which option best satisfies the requirement?

  1. Use Microsoft Entra Connect Health
  2. Review Microsoft Entra sign-in logs and authentication details
  3. Configure the Microsoft Entra authentication methods policy
  4. Exclude emergency access accounts from policies that could block all administrators
  5. Configure password writeback for supported hybrid SSPR scenarios

Correct answer: C

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

D: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q003: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 4

The operations team at Blue Yonder Airlines needs to resolve an issue without granting broader permissions than necessary. Audit evidence shows that the current process cannot reliably strengthen authentication against credential phishing rather than relying only on passwords. The design should minimize manual per-user administration where a scoped central control exists. The affected scope contains 70 users across 8 administrative groups. Which control should the team use?

  1. Configure the Microsoft Entra authentication methods policy
  2. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  3. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  4. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  5. Start a new Conditional Access policy in report-only mode

Correct answer: D

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q004: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 5

Lucerne Publishing is preparing a change requested by the identity administrator. The existing configuration works for normal operations but fails the new requirement to control which modern authentication methods users are allowed or targeted to register and use. The architecture board will reject a choice that solves a different problem from the one stated. The control owner requires a review after 87 days and evidence from 21 representative cases. Which administrative choice should be recommended?

  1. Use the Risky users and Risky sign-ins views to investigate identity risk
  2. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  3. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  4. Configure the custom banned password list in Microsoft Entra Password Protection
  5. Configure the Microsoft Entra authentication methods policy

Correct answer: E

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Learning point: MS102-T09-Q005: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 6

Fourth Coffee has completed a pilot and must now choose the production administration approach. The service owner wants a supportable design that will strengthen authentication against credential phishing rather than relying only on passwords. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 13 users across 11 administrative groups. Which control should the team use?

  1. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  2. Check Cloud Sync agent health and provisioning logs
  3. Define how user risk and sign-in risk will trigger remediation actions
  4. Require multifactor authentication with a Conditional Access grant control
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: A

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q006: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 7

During a tenant review at Fabrikam Health, the tenant administrator identifies one unresolved requirement. The current workaround is too manual. The replacement should control which modern authentication methods users are allowed or targeted to register and use. The control owner requires a review after 30 days and evidence from 24 representative cases. The change must be repeatable and supportable after the project team leaves. Which control should the team use?

  1. Run IdFix against the on-premises directory before synchronization
  2. Configure the Microsoft Entra authentication methods policy
  3. Check synchronization logs and the affected object attributes
  4. Pilot risk-based access controls with a scoped group before broad enforcement
  5. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement

Correct answer: B

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

C: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q007: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 8

Woodgrove Bank has completed a pilot and must now choose the production administration approach. The change advisory board wants the smallest supported control that can strengthen authentication against credential phishing rather than relying only on passwords. The control owner requires a review after 47 days and evidence from 14 representative cases. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?

  1. Exclude emergency access accounts from policies that could block all administrators
  2. Configure password writeback for supported hybrid SSPR scenarios
  3. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  4. Investigate a synchronization health alert in Microsoft Entra Connect Health
  5. Use the sign-in correlation ID and failure details to trace the failed authentication

Correct answer: C

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

D: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q008: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 9

Northwind Traders has completed a pilot and must now choose the production administration approach. A controlled pilot must demonstrate how to control which modern authentication methods users are allowed or targeted to register and use. The architecture board will reject a choice that solves a different problem from the one stated. The initial rollout covers 4 locations and approximately 640 managed identities or devices. Which control should the team use?

  1. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  2. Start a new Conditional Access policy in report-only mode
  3. Enable SSPR for the intended user scope
  4. Configure the Microsoft Entra authentication methods policy
  5. Use Microsoft Entra Connect Health

Correct answer: D

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q009: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 10

The operations team at Wingtip Services needs to resolve an issue without granting broader permissions than necessary. Audit evidence shows that the current process cannot reliably strengthen authentication against credential phishing rather than relying only on passwords. The administrator must avoid granting unrelated tenant-wide privilege. The service desk has 81 related tickets from 17 business units, so the team wants a targeted fix. Which option best satisfies the requirement?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Confirm user compromise only when investigation supports that conclusion
  4. Configure the Microsoft Entra authentication methods policy
  5. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance

Correct answer: E

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Learning point: MS102-T09-Q010: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 11

The operations team at Adventure Works needs to resolve an issue without granting broader permissions than necessary. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to control which modern authentication methods users are allowed or targeted to register and use. The control owner requires a review after 7 days and evidence from 7 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. What is the most appropriate next step?

  1. Configure the Microsoft Entra authentication methods policy
  2. Require multifactor authentication with a Conditional Access grant control
  3. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  4. Review synchronization scope and filtering before recreating objects
  5. Use the Risky users and Risky sign-ins views to investigate identity risk

Correct answer: A

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

B: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q011: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 12

Blue Yonder Airlines is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A post-incident action item requires the tenant to strengthen authentication against credential phishing rather than relying only on passwords. The affected scope contains 24 users across 20 administrative groups. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which control should the team use?

  1. Pilot risk-based access controls with a scoped group before broad enforcement
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  4. Correct duplicate or invalid identity attributes before the first sync
  5. Check Cloud Sync agent health and provisioning logs

Correct answer: B

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

C: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q012: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 13

During a tenant review at City Power & Light, the service desk lead identifies one unresolved requirement. The change advisory board wants the smallest supported control that can control which modern authentication methods users are allowed or targeted to register and use. The team will validate the change with 10 pilot groups before expanding it to 41 users. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?

  1. Investigate a synchronization health alert in Microsoft Entra Connect Health
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Configure the Microsoft Entra authentication methods policy
  4. Configure Conditional Access conditions and grant controls for the required scenario
  5. Run IdFix against the on-premises directory before synchronization

Correct answer: C

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q013: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 14

An incident review at VanArsdel Media produces a single administrative requirement for the messaging administrator. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to strengthen authentication against credential phishing rather than relying only on passwords. The initial rollout covers 23 locations and approximately 580 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?

  1. Enable SSPR for the intended user scope
  2. Use Microsoft Entra Connect Health
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  5. Exclude emergency access accounts from policies that could block all administrators

Correct answer: D

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q014: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 15

Litware Financial is preparing a change requested by the compliance administrator. The implementation review is focused on one outcome: control which modern authentication methods users are allowed or targeted to register and use. The initial rollout covers 13 locations and approximately 750 managed identities or devices. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?

  1. Confirm user compromise only when investigation supports that conclusion
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  5. Configure the Microsoft Entra authentication methods policy

Correct answer: E

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Learning point: MS102-T09-Q015: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 16

Wingtip Services is standardizing administration after several teams used inconsistent procedures. The project board will approve the next step only if it can strengthen authentication against credential phishing rather than relying only on passwords. The control owner requires a review after 92 days and evidence from 3 representative cases. The organization wants a reversible rollout with measurable verification before broad enforcement. What is the most appropriate next step?

  1. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  2. Review synchronization scope and filtering before recreating objects
  3. Use the Risky users and Risky sign-ins views to investigate identity risk
  4. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  5. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync

Correct answer: A

Why: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

Option review:

A: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. It directly addresses the stated requirement.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q016: Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance – Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow.

Question 17

During a tenant review at Humongous Insurance, the security operations analyst identifies one unresolved requirement. A production change is approved only if it can control which modern authentication methods users are allowed or targeted to register and use. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 16 locations and approximately 180 managed identities or devices. What is the most appropriate next step?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Configure the Microsoft Entra authentication methods policy
  3. Check Cloud Sync agent health and provisioning logs
  4. Define how user risk and sign-in risk will trigger remediation actions
  5. Require multifactor authentication with a Conditional Access grant control

Correct answer: B

Why: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. It directly addresses the stated requirement.

C: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q017: Configure the Microsoft Entra authentication methods policy – The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods.

Question 18

Margie Travel has completed a pilot and must now choose the production administration approach. The support team has reproduced the issue and narrowed it to this requirement: allow selected users to reset their own passwords after completing the required verification. The affected scope contains 35 users across 6 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What should the administrator configure first?

  1. Configure Conditional Access conditions and grant controls for the required scenario
  2. Run IdFix against the on-premises directory before synchronization
  3. Enable SSPR for the intended user scope
  4. Check synchronization logs and the affected object attributes
  5. Pilot risk-based access controls with a scoped group before broad enforcement

Correct answer: C

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q018: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 19

Northwind Traders is standardizing administration after several teams used inconsistent procedures. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to allow a cloud-initiated self-service password reset to update the on-premises directory password. The team will validate the change with 19 pilot groups before expanding it to 52 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which option best satisfies the requirement?

  1. Review Microsoft Entra sign-in logs and authentication details
  2. Exclude emergency access accounts from policies that could block all administrators
  3. Enable SSPR for the intended user scope
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: D

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q019: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 20

The operations team at Southridge Video needs to resolve an issue without granting broader permissions than necessary. The existing configuration works for normal operations but fails the new requirement to allow selected users to reset their own passwords after completing the required verification. The team must preserve a clear audit trail for the administrative decision. The service desk has 69 related tickets from 9 business units, so the team wants a targeted fix. Which administrative choice should be recommended?

  1. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Start a new Conditional Access policy in report-only mode
  4. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  5. Enable SSPR for the intended user scope

Correct answer: E

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Learning point: MS102-T09-Q020: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 21

Trey Research is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A production change is approved only if it can allow a cloud-initiated self-service password reset to update the on-premises directory password. The solution should use a native Microsoft control that matches the stated requirement. The affected scope contains 86 users across 22 administrative groups. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  3. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  4. Configure the custom banned password list in Microsoft Entra Password Protection
  5. Confirm user compromise only when investigation supports that conclusion

Correct answer: A

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

B: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q021: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 22

Fabrikam Health is preparing a change requested by the security operations analyst. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to allow selected users to reset their own passwords after completing the required verification. The administrator must avoid granting unrelated tenant-wide privilege. The service desk has 12 related tickets from 12 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Define how user risk and sign-in risk will trigger remediation actions
  2. Enable SSPR for the intended user scope
  3. Require multifactor authentication with a Conditional Access grant control
  4. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  5. Review synchronization scope and filtering before recreating objects

Correct answer: B

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

C: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q022: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 23

Trey Research is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A post-incident action item requires the tenant to allow a cloud-initiated self-service password reset to update the on-premises directory password. The service desk has 29 related tickets from 2 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Check synchronization logs and the affected object attributes
  2. Pilot risk-based access controls with a scoped group before broad enforcement
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  5. Correct duplicate or invalid identity attributes before the first sync

Correct answer: C

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

D: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q023: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 24

The operations team at Consolidated Messenger needs to resolve an issue without granting broader permissions than necessary. The support team has reproduced the issue and narrowed it to this requirement: allow selected users to reset their own passwords after completing the required verification. The team will validate the change with 15 pilot groups before expanding it to 46 users. The solution should use a native Microsoft control that matches the stated requirement. Which control should the team use?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Investigate a synchronization health alert in Microsoft Entra Connect Health
  3. Use the sign-in correlation ID and failure details to trace the failed authentication
  4. Enable SSPR for the intended user scope
  5. Configure Conditional Access conditions and grant controls for the required scenario

Correct answer: D

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q024: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 25

Litware Financial is preparing a change requested by the tenant administrator. The support team has reproduced the issue and narrowed it to this requirement: allow a cloud-initiated self-service password reset to update the on-premises directory password. The control owner requires a review after 63 days and evidence from 5 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which approach most directly addresses the requirement?

  1. Start a new Conditional Access policy in report-only mode
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Use Microsoft Entra Connect Health
  4. Review Microsoft Entra sign-in logs and authentication details
  5. Configure password writeback for supported hybrid SSPR scenarios

Correct answer: E

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Learning point: MS102-T09-Q025: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 26

The operations team at Adventure Works needs to resolve an issue without granting broader permissions than necessary. The existing configuration works for normal operations but fails the new requirement to allow selected users to reset their own passwords after completing the required verification. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 80 days and evidence from 18 representative cases. What is the most appropriate next step?

  1. Enable SSPR for the intended user scope
  2. Configure the custom banned password list in Microsoft Entra Password Protection
  3. Confirm user compromise only when investigation supports that conclusion
  4. Configure the Microsoft Entra authentication methods policy
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: A

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

B: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q026: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 27

The operations team at Alpine Ski House needs to resolve an issue without granting broader permissions than necessary. The existing configuration works for normal operations but fails the new requirement to allow a cloud-initiated self-service password reset to update the on-premises directory password. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 6 related tickets from 8 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Configure password writeback for supported hybrid SSPR scenarios
  3. Review synchronization scope and filtering before recreating objects
  4. Use the Risky users and Risky sign-ins views to investigate identity risk
  5. Use an authentication strength in Conditional Access when a specific strength of MFA is required

Correct answer: B

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

C: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q027: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 28

Trey Research is standardizing administration after several teams used inconsistent procedures. A production change is approved only if it can allow selected users to reset their own passwords after completing the required verification. The architecture board will reject a choice that solves a different problem from the one stated. The affected scope contains 23 users across 21 administrative groups. Which action should the administrator take?

  1. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Enable SSPR for the intended user scope
  4. Check Cloud Sync agent health and provisioning logs
  5. Define how user risk and sign-in risk will trigger remediation actions

Correct answer: C

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q028: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 29

During a tenant review at Humongous Insurance, the hybrid identity engineer identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to allow a cloud-initiated self-service password reset to update the on-premises directory password. The initial rollout covers 11 locations and approximately 400 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use the sign-in correlation ID and failure details to trace the failed authentication
  2. Configure Conditional Access conditions and grant controls for the required scenario
  3. Run IdFix against the on-premises directory before synchronization
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Check synchronization logs and the affected object attributes

Correct answer: D

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q029: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 30

During a tenant review at Litware Financial, the identity administrator identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to allow selected users to reset their own passwords after completing the required verification. The initial rollout covers 24 locations and approximately 570 managed identities or devices. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?

  1. Use Microsoft Entra Connect Health
  2. Review Microsoft Entra sign-in logs and authentication details
  3. Exclude emergency access accounts from policies that could block all administrators
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Enable SSPR for the intended user scope

Correct answer: E

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Learning point: MS102-T09-Q030: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 31

The identity administrator at Graphic Design Institute is designing the next phase of the Microsoft 365 rollout. The project board will approve the next step only if it can allow a cloud-initiated self-service password reset to update the on-premises directory password. The service desk has 74 related tickets from 14 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. What is the most appropriate next step?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Configure the Microsoft Entra authentication methods policy
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  5. Start a new Conditional Access policy in report-only mode

Correct answer: A

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q031: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 32

City Power & Light is standardizing administration after several teams used inconsistent procedures. Administrators have confirmed the present design does not allow selected users to reset their own passwords after completing the required verification. The initial rollout covers 4 locations and approximately 910 managed identities or devices. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which approach most directly addresses the requirement?

  1. Use the Risky users and Risky sign-ins views to investigate identity risk
  2. Enable SSPR for the intended user scope
  3. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: B

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

C: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q032: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Question 33

An incident review at Margie Travel produces a single administrative requirement for the security administrator. The existing configuration works for normal operations but fails the new requirement to allow a cloud-initiated self-service password reset to update the on-premises directory password. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 17 users across 17 administrative groups. What is the most appropriate next step?

  1. Check Cloud Sync agent health and provisioning logs
  2. Define how user risk and sign-in risk will trigger remediation actions
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Require multifactor authentication with a Conditional Access grant control
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: C

Why: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

Option review:

A: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. It directly addresses the stated requirement.

D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q033: Configure password writeback for supported hybrid SSPR scenarios – Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory.

Question 34

Graphic Design Institute is standardizing administration after several teams used inconsistent procedures. Administrators have confirmed the present design does not allow selected users to reset their own passwords after completing the required verification. The affected scope contains 34 users across 7 administrative groups. The administrator must avoid granting unrelated tenant-wide privilege. Which control should the team use?

  1. Run IdFix against the on-premises directory before synchronization
  2. Check synchronization logs and the affected object attributes
  3. Pilot risk-based access controls with a scoped group before broad enforcement
  4. Enable SSPR for the intended user scope
  5. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement

Correct answer: D

Why: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. It directly addresses the stated requirement.

E: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T09-Q034: Enable SSPR for the intended user scope – SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met.

Popular posts

img