nerdexam
Microsoft

AZ-104 · Question #180

You configure Azure AD Connect for Azure Active Directory Seamless Single Sign-On (Azure AD Seamless SSO) for an on-premises network. Users report that when they attempt to access myapps.microsoft.com

The correct answer is B. From Azure AD, add and verify a custom domain name.. Azure AD Connect lists the UPN suffixes that are defined for the domains and tries to match them custom domain in Azure AD. Then it helps you with the appropriate action that needs to be taken. The Azure AD sign-in page lists the UPN suffixes that are defined for on-premises Acti

Submitted by zhang_li· Mar 4, 2026Manage identities and governance

Question

You configure Azure AD Connect for Azure Active Directory Seamless Single Sign-On (Azure AD Seamless SSO) for an on-premises network. Users report that when they attempt to access myapps.microsoft.com, they are prompted multiple times to sign in and are forced to use an account name that ends with onmicrosoft.com. You discover that there is a UPN mismatch between Azure AD and the on-premises Active Directory. You need to ensure that the users can use single-sign on (SSO) to access Azure resources. What should you do first?

Options

  • AFrom the on-premises network, deploy Active Directory Federation Services (AD FS).
  • BFrom Azure AD, add and verify a custom domain name.
  • CFrom the on-premises network, request a new certificate that contains the Active Directory
  • DFrom the server that runs Azure AD Connect, modify the filtering options.

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    74% (14)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Azure AD Connect lists the UPN suffixes that are defined for the domains and tries to match them custom domain in Azure AD. Then it helps you with the appropriate action that needs to be taken. The Azure AD sign-in page lists the UPN suffixes that are defined for on-premises Active Directory and displays the corresponding status against each suffix. The status values can be one of the following: State: Verified Azure AD Connect found a matching verified domain in Azure AD. All users for this domain can sign in by using their on-premises credentials. State: Not verified Azure AD Connect found a matching custom domain in Azure AD, but it isn't verified. The UPN suffix of the users of this domain will be changed to the default .onmicrosoft.com suffix after synchronization if the domain isn't verified. Action Required: Verify the custom domain in Azure AD.

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice