Microsoft MS-102 Hybrid Identity Preparation IdFix Connect Sync And Cloud Sync Practice Test

 

MS-102 skills 2.1 | 34 original questions

This MS-102 practice set focuses on hybrid identity preparation idfix connect sync and cloud sync through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

An incident review at Margie Travel produces a single administrative requirement for the security administrator. An internal assessment finds the control technically functional but unable to identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The team will validate the change with 21 pilot groups before expanding it to 6 users. The team must preserve a clear audit trail for the administrative decision. What is the most appropriate next step?

  1. Run IdFix against the on-premises directory before synchronization
  2. Pilot risk-based access controls with a scoped group before broad enforcement
  3. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  4. Use Microsoft Entra Connect Health
  5. Enable SSPR for the intended user scope

Correct answer: A

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

B: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q001: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 2

Humongous Insurance is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The administrator must avoid granting unrelated tenant-wide privilege. The initial rollout covers 11 locations and approximately 230 managed identities or devices. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Configure the Microsoft Entra authentication methods policy
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Use the sign-in correlation ID and failure details to trace the failed authentication
  4. Configure Conditional Access conditions and grant controls for the required scenario
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: B

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

C: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q002: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 3

The governance lead at Wide World Importers is designing the next phase of the Microsoft 365 rollout. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 40 days and evidence from 24 representative cases. What is the most appropriate next step?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Review synchronization scope and filtering before recreating objects
  3. Run IdFix against the on-premises directory before synchronization
  4. Review Microsoft Entra sign-in logs and authentication details
  5. Exclude emergency access accounts from policies that could block all administrators

Correct answer: C

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

D: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q003: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 4

Fabrikam Health is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Before the tenant expands to another business unit, the administrator must prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The control owner requires a review after 57 days and evidence from 14 representative cases. The change must be repeatable and supportable after the project team leaves. Which approach most directly addresses the requirement?

  1. Confirm user compromise only when investigation supports that conclusion
  2. Run IdFix against the on-premises directory before synchronization
  3. Check Cloud Sync agent health and provisioning logs
  4. Correct duplicate or invalid identity attributes before the first sync
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: D

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q004: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 5

The compliance administrator at Lucerne Publishing is designing the next phase of the Microsoft 365 rollout. The next migration wave is blocked until the team can identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 74 users across 4 administrative groups. Which control should the team use?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Use the Risky users and Risky sign-ins views to investigate identity risk
  3. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  4. Check synchronization logs and the affected object attributes
  5. Run IdFix against the on-premises directory before synchronization

Correct answer: E

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Learning point: MS102-T07-Q005: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 6

During a tenant review at Consolidated Messenger, the hybrid identity engineer identifies one unresolved requirement. Security and operations teams agree on the target state: prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The architecture board will reject a choice that solves a different problem from the one stated. The initial rollout covers 17 locations and approximately 910 managed identities or devices. Which administrative choice should be recommended?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Use Microsoft Entra Connect Health
  3. Enable SSPR for the intended user scope
  4. Define how user risk and sign-in risk will trigger remediation actions
  5. Require multifactor authentication with a Conditional Access grant control

Correct answer: A

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

B: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q006: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 7

Margie Travel is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The next migration wave is blocked until the team can identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The response must address the cause described in the scenario rather than simply suppressing the symptom. The control owner requires a review after 17 days and evidence from 7 representative cases. What should the administrator configure first?

  1. Configure Conditional Access conditions and grant controls for the required scenario
  2. Run IdFix against the on-premises directory before synchronization
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  5. Pilot risk-based access controls with a scoped group before broad enforcement

Correct answer: B

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q007: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 8

Wide World Importers is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Administrators have confirmed the present design does not prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The control owner requires a review after 34 days and evidence from 20 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Review Microsoft Entra sign-in logs and authentication details
  2. Exclude emergency access accounts from policies that could block all administrators
  3. Correct duplicate or invalid identity attributes before the first sync
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Configure the Microsoft Entra authentication methods policy

Correct answer: C

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q008: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 9

An incident review at Trey Research produces a single administrative requirement for the messaging administrator. The next migration wave is blocked until the team can identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The response must address the cause described in the scenario rather than simply suppressing the symptom. The affected scope contains 51 users across 10 administrative groups. What should the administrator configure first?

  1. Check Cloud Sync agent health and provisioning logs
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Start a new Conditional Access policy in report-only mode
  4. Run IdFix against the on-premises directory before synchronization
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: D

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q009: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 10

An incident review at Trey Research produces a single administrative requirement for the compliance administrator. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The control owner requires a review after 68 days and evidence from 23 representative cases. Which option best satisfies the requirement?

  1. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  2. Check synchronization logs and the affected object attributes
  3. Configure the custom banned password list in Microsoft Entra Password Protection
  4. Confirm user compromise only when investigation supports that conclusion
  5. Correct duplicate or invalid identity attributes before the first sync

Correct answer: E

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Learning point: MS102-T07-Q010: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 11

A quarterly control review at Datum Dynamics identifies a gap that must be corrected before the next audit. Audit evidence shows that the current process cannot reliably identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 85 users across 13 administrative groups. What should the administrator configure first?

  1. Run IdFix against the on-premises directory before synchronization
  2. Define how user risk and sign-in risk will trigger remediation actions
  3. Require multifactor authentication with a Conditional Access grant control
  4. Investigate a synchronization health alert in Microsoft Entra Connect Health
  5. Configure password writeback for supported hybrid SSPR scenarios

Correct answer: A

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

B: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q011: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 12

The operations team at Blue Yonder Airlines needs to resolve an issue without granting broader permissions than necessary. The administrator is comparing native Microsoft controls after documenting a requirement to prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The control owner requires a review after 11 days and evidence from 3 representative cases. The change must be repeatable and supportable after the project team leaves. Which approach most directly addresses the requirement?

  1. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  2. Correct duplicate or invalid identity attributes before the first sync
  3. Pilot risk-based access controls with a scoped group before broad enforcement
  4. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  5. Use Microsoft Entra Connect Health

Correct answer: B

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

C: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q012: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 13

During a tenant review at Alpine Ski House, the compliance administrator identifies one unresolved requirement. A controlled pilot must demonstrate how to identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The response must address the cause described in the scenario rather than simply suppressing the symptom. The service desk has 28 related tickets from 16 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Configure the Microsoft Entra authentication methods policy
  3. Run IdFix against the on-premises directory before synchronization
  4. Use the sign-in correlation ID and failure details to trace the failed authentication
  5. Configure Conditional Access conditions and grant controls for the required scenario

Correct answer: C

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

D: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q013: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 14

Litware Financial has completed a pilot and must now choose the production administration approach. A production change is approved only if it can prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 45 users across 6 administrative groups. Which approach most directly addresses the requirement?

  1. Start a new Conditional Access policy in report-only mode
  2. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  3. Review synchronization scope and filtering before recreating objects
  4. Correct duplicate or invalid identity attributes before the first sync
  5. Review Microsoft Entra sign-in logs and authentication details

Correct answer: D

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

E: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q014: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 15

The operations team at Datum Dynamics needs to resolve an issue without granting broader permissions than necessary. A controlled pilot must demonstrate how to identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The architecture board will reject a choice that solves a different problem from the one stated. The service desk has 62 related tickets from 19 business units, so the team wants a targeted fix. Which action should the administrator take?

  1. Configure the custom banned password list in Microsoft Entra Password Protection
  2. Confirm user compromise only when investigation supports that conclusion
  3. Correct duplicate or invalid identity attributes before the first sync
  4. Check Cloud Sync agent health and provisioning logs
  5. Run IdFix against the on-premises directory before synchronization

Correct answer: E

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Learning point: MS102-T07-Q015: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 16

Fabrikam Health is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The organization is replacing a manual process. The replacement must prevent known on-premises directory data quality problems from propagating into Microsoft Entra ID while remaining centrally manageable. The initial rollout covers 9 locations and approximately 790 managed identities or devices. The organization wants a reversible rollout with measurable verification before broad enforcement. What is the most appropriate next step?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Investigate a synchronization health alert in Microsoft Entra Connect Health
  3. Configure password writeback for supported hybrid SSPR scenarios
  4. Use the Risky users and Risky sign-ins views to investigate identity risk
  5. Use an authentication strength in Conditional Access when a specific strength of MFA is required

Correct answer: A

Why: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. It directly addresses the stated requirement.

B: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q016: Correct duplicate or invalid identity attributes before the first sync – Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts.

Question 17

The operations team at Proseware Logistics needs to resolve an issue without granting broader permissions than necessary. The service owner wants a supportable design that will identify directory attribute problems such as duplicates or formatting issues before enabling synchronization. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 22 locations and approximately 50 managed identities or devices. Which approach most directly addresses the requirement?

  1. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  2. Run IdFix against the on-premises directory before synchronization
  3. Use Microsoft Entra Connect Health
  4. Enable SSPR for the intended user scope
  5. Define how user risk and sign-in risk will trigger remediation actions

Correct answer: B

Why: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

Option review:

A: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. It directly addresses the stated requirement.

C: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q017: Run IdFix against the on-premises directory before synchronization – IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems.

Question 18

During a tenant review at Woodgrove Bank, the hybrid identity engineer identifies one unresolved requirement. The service owner wants a supportable design that will synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The response must address the cause described in the scenario rather than simply suppressing the symptom. The affected scope contains 22 users across 12 administrative groups. Which option best satisfies the requirement?

  1. Use the sign-in correlation ID and failure details to trace the failed authentication
  2. Configure Conditional Access conditions and grant controls for the required scenario
  3. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  4. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  5. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance

Correct answer: C

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

D: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q018: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 19

An incident review at A. Datum Manufacturing produces a single administrative requirement for the identity administrator. A post-incident action item requires the tenant to retain synchronization functionality that requires the full Connect Sync engine. The affected scope contains 39 users across 2 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. Which option best satisfies the requirement?

  1. Review synchronization scope and filtering before recreating objects
  2. Review Microsoft Entra sign-in logs and authentication details
  3. Exclude emergency access accounts from policies that could block all administrators
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: D

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q019: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

Question 20

An incident review at Margie Travel produces a single administrative requirement for the tenant administrator. The change advisory board wants the smallest supported control that can avoid having both synchronization engines manage the same objects or attributes unexpectedly. The initial rollout covers 15 locations and approximately 560 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which administrative choice should be recommended?

  1. Run IdFix against the on-premises directory before synchronization
  2. Check Cloud Sync agent health and provisioning logs
  3. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  4. Start a new Conditional Access policy in report-only mode
  5. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel

Correct answer: E

Why: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Option review:

A: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Learning point: MS102-T07-Q020: Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel – Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes.

Question 21

A quarterly control review at Tailspin Toys identifies a gap that must be corrected before the next audit. Administrators have confirmed the present design does not synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The team will validate the change with 5 pilot groups before expanding it to 73 users. The administrator must avoid granting unrelated tenant-wide privilege. Which administrative choice should be recommended?

  1. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  2. Use the Risky users and Risky sign-ins views to investigate identity risk
  3. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  4. Check synchronization logs and the affected object attributes
  5. Configure the custom banned password list in Microsoft Entra Password Protection

Correct answer: A

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

B: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q021: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 22

  1. Datum Manufacturing is standardizing administration after several teams used inconsistent procedures. Audit evidence shows that the current process cannot reliably retain synchronization functionality that requires the full Connect Sync engine. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The service desk has 90 related tickets from 18 business units, so the team wants a targeted fix. What should the administrator configure first?
  2. Enable SSPR for the intended user scope
  3. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  4. Define how user risk and sign-in risk will trigger remediation actions
  5. Require multifactor authentication with a Conditional Access grant control
  6. Investigate a synchronization health alert in Microsoft Entra Connect Health

Correct answer: B

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

C: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q022: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

Question 23

Wingtip Services is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: avoid having both synchronization engines manage the same objects or attributes unexpectedly. The team will validate the change with 8 pilot groups before expanding it to 16 users. The team does not want to redesign unrelated workloads. Which administrative choice should be recommended?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  3. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  4. Pilot risk-based access controls with a scoped group before broad enforcement
  5. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement

Correct answer: C

Why: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

D: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q023: Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel – Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes.

Question 24

Blue Yonder Airlines is standardizing administration after several teams used inconsistent procedures. The project board will approve the next step only if it can synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The team will validate the change with 21 pilot groups before expanding it to 33 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Exclude emergency access accounts from policies that could block all administrators
  2. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  3. Configure the Microsoft Entra authentication methods policy
  4. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  5. Use the sign-in correlation ID and failure details to trace the failed authentication

Correct answer: D

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

E: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q024: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 25

  1. Datum Manufacturing has completed a pilot and must now choose the production administration approach. The organization is replacing a manual process. The replacement must retain synchronization functionality that requires the full Connect Sync engine while remaining centrally manageable. The affected scope contains 50 users across 11 administrative groups. The architecture board will reject a choice that solves a different problem from the one stated. Which approach most directly addresses the requirement?
  2. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement
  3. Start a new Conditional Access policy in report-only mode
  4. Correct duplicate or invalid identity attributes before the first sync
  5. Review synchronization scope and filtering before recreating objects
  6. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync

Correct answer: E

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Report-only mode lets administrators assess policy impact and sign-in results without immediately blocking or challenging users. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Learning point: MS102-T07-Q025: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

Question 26

Datum Dynamics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The existing configuration works for normal operations but fails the new requirement to avoid having both synchronization engines manage the same objects or attributes unexpectedly. The architecture board will reject a choice that solves a different problem from the one stated. The initial rollout covers 24 locations and approximately 670 managed identities or devices. Which approach most directly addresses the requirement?

  1. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  2. Check synchronization logs and the affected object attributes
  3. Configure the custom banned password list in Microsoft Entra Password Protection
  4. Confirm user compromise only when investigation supports that conclusion
  5. Run IdFix against the on-premises directory before synchronization

Correct answer: A

Why: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Option review:

A: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

B: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom banned passwords supplement global protection by blocking tenant-specific words that attackers could easily guess. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q026: Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel – Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes.

Question 27

Graphic Design Institute is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The change advisory board wants the smallest supported control that can synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The initial rollout covers 14 locations and approximately 840 managed identities or devices. The design should minimize manual per-user administration where a scoped central control exists. Which approach most directly addresses the requirement?

  1. Require multifactor authentication with a Conditional Access grant control
  2. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  3. Investigate a synchronization health alert in Microsoft Entra Connect Health
  4. Configure password writeback for supported hybrid SSPR scenarios
  5. Use the Risky users and Risky sign-ins views to investigate identity risk

Correct answer: B

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

C: Connect Health surfaces health and alert information that helps administrators distinguish service or agent problems from configuration issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q027: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 28

Fabrikam Health is standardizing administration after several teams used inconsistent procedures. A production change is approved only if it can retain synchronization functionality that requires the full Connect Sync engine. The change must be repeatable and supportable after the project team leaves. The initial rollout covers 4 locations and approximately 100 managed identities or devices. Which option best satisfies the requirement?

  1. Pilot risk-based access controls with a scoped group before broad enforcement
  2. Use Conditional Access rather than separate ad hoc application-specific rules when a centralized access policy can express the requirement
  3. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  4. Use Microsoft Entra Connect Health
  5. Enable SSPR for the intended user scope

Correct answer: C

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Conditional Access provides centralized policy evaluation for Entra-authenticated applications and supports consistent access controls across the selected scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

D: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q028: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

Question 29

A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. The administrator is comparing native Microsoft controls after documenting a requirement to avoid having both synchronization engines manage the same objects or attributes unexpectedly. The initial rollout covers 17 locations and approximately 270 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?

  1. Configure the Microsoft Entra authentication methods policy
  2. Use the sign-in correlation ID and failure details to trace the failed authentication
  3. Configure Conditional Access conditions and grant controls for the required scenario
  4. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  5. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync

Correct answer: D

Why: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Option review:

A: The authentication methods policy is the central Entra control for enabling and scoping supported authentication methods. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Correlation IDs and failure details help locate the precise sign-in event and avoid troubleshooting an unrelated authentication attempt. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

E: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q029: Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel – Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes.

Question 30

City Power & Light is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Before the tenant expands to another business unit, the administrator must synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The initial rollout covers 7 locations and approximately 440 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. What should the administrator configure first?

  1. Correct duplicate or invalid identity attributes before the first sync
  2. Review synchronization scope and filtering before recreating objects
  3. Review Microsoft Entra sign-in logs and authentication details
  4. Exclude emergency access accounts from policies that could block all administrators
  5. Use Microsoft Entra Cloud Sync with cloud provisioning agents

Correct answer: E

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: Preparing the directory before synchronization reduces avoidable provisioning errors and object conflicts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: OU, group, or attribute scoping can intentionally exclude objects; scope should be verified before treating absence as a data-corruption problem. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sign-in logs provide result details, authentication information, Conditional Access evaluation, and correlation data that support authentication troubleshooting. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Emergency access accounts are typically excluded from broad Conditional Access enforcement so administrators retain a recovery path. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Learning point: MS102-T07-Q030: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 31

The operations team at Southridge Video needs to resolve an issue without granting broader permissions than necessary. The project board will approve the next step only if it can retain synchronization functionality that requires the full Connect Sync engine. The team will validate the change with 20 pilot groups before expanding it to 61 users. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which administrative choice should be recommended?

  1. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  2. Confirm user compromise only when investigation supports that conclusion
  3. Run IdFix against the on-premises directory before synchronization
  4. Check Cloud Sync agent health and provisioning logs
  5. Deploy the Microsoft Entra Password Protection proxy and DC agents for on-premises enforcement

Correct answer: A

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

B: Confirming compromise is a deliberate risk-state action and should be based on evidence rather than used as a generic way to clear a detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: IdFix is intended to detect and help remediate directory attributes that can cause synchronization or Microsoft 365 identity problems. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud Sync troubleshooting should include the provisioning agent state and cloud provisioning logs rather than only Connect Sync tooling. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: On-premises Password Protection enforcement requires the supported proxy and domain-controller agents to evaluate AD DS password changes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q031: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

Question 32

An incident review at Trey Research produces a single administrative requirement for the compliance administrator. Before the tenant expands to another business unit, the administrator must avoid having both synchronization engines manage the same objects or attributes unexpectedly. The team will validate the change with 10 pilot groups before expanding it to 78 users. The administrator must avoid granting unrelated tenant-wide privilege. What should the administrator configure first?

  1. Configure password writeback for supported hybrid SSPR scenarios
  2. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  3. Use the Risky users and Risky sign-ins views to investigate identity risk
  4. Use an authentication strength in Conditional Access when a specific strength of MFA is required
  5. Check synchronization logs and the affected object attributes

Correct answer: B

Why: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

Option review:

A: Password writeback is required when hybrid users must have an SSPR change written back to on-premises Active Directory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. It directly addresses the stated requirement.

C: Identity Protection surfaces risky users and risky sign-ins so administrators can investigate detections and choose appropriate remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Authentication strengths let Conditional Access require stronger, explicitly allowed authentication methods when generic MFA is not sufficient. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Object-level synchronization failures are best investigated by examining sync/provisioning logs and the source attributes or rules involved. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q032: Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel – Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes.

Question 33

During a tenant review at Fabrikam Health, the security administrator identifies one unresolved requirement. An internal assessment finds the control technically functional but unable to synchronize supported directory objects using lightweight agents with cloud-managed synchronization configuration. The team will validate the change with 23 pilot groups before expanding it to 95 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft Entra Connect Health
  2. Enable SSPR for the intended user scope
  3. Use Microsoft Entra Cloud Sync with cloud provisioning agents
  4. Define how user risk and sign-in risk will trigger remediation actions
  5. Require multifactor authentication with a Conditional Access grant control

Correct answer: C

Why: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

Option review:

A: Connect Health centralizes health monitoring and alerts for supported Entra Connect components. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: SSPR can be enabled for selected groups or all eligible users and lets users reset passwords without help-desk intervention when configured requirements are met. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments. It directly addresses the stated requirement.

D: Identity Protection planning should connect detected risk levels to actions such as secure password change, MFA, or blocking according to organizational risk policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A Conditional Access policy can require MFA as a grant control so the additional factor is enforced only for the intended policy scope. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q033: Use Microsoft Entra Cloud Sync with cloud provisioning agents – Cloud Sync uses cloud provisioning agents and cloud-managed configuration, making it suitable for supported hybrid identity scenarios and distributed agent deployments.

Question 34

During a tenant review at Contoso Retail, the Microsoft 365 administrator identifies one unresolved requirement. The next migration wave is blocked until the team can retain synchronization functionality that requires the full Connect Sync engine. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 21 users across 13 administrative groups. Which control should the team use?

  1. Configure Conditional Access conditions and grant controls for the required scenario
  2. Use mutually exclusive scoping if Connect Sync and Cloud Sync run in parallel
  3. Use a phishing-resistant authentication method such as passkeys or FIDO2 security keys when the requirement demands phishing resistance
  4. Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync
  5. Pilot risk-based access controls with a scoped group before broad enforcement

Correct answer: D

Why: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

Option review:

A: Conditional Access combines assignments and conditions with grant or session controls to enforce context-aware access requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Parallel synchronization can be used in supported scenarios, but scoping must prevent conflicting management of the same objects or attributes. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Phishing-resistant methods use cryptographic authentication that is not satisfied by replaying a stolen password or simple OTP in a phishing flow. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set. It directly addresses the stated requirement.

E: Risk-based controls can affect authentication significantly, so a scoped deployment helps validate policy behavior while reducing rollout risk. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T07-Q034: Use Microsoft Entra Connect Sync when the required scenario depends on a feature not yet supported by Cloud Sync – Connect Sync remains appropriate when a required hybrid identity capability is outside the supported Cloud Sync feature set.

img