nerdexam
Microsoft

AZ-500 · Question #564

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. You have a Microsoft Entra tenant that syncs with the domain. You create an app registration named App1. You…

The correct answer is D. Token configuration. https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-group-claims

Submitted by anjalisingh· Mar 6, 2026Secure identity and access

Question

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. You have a Microsoft Entra tenant that syncs with the domain. You create an app registration named App1. You need to configure App1 to support claims-based authorization and include the default group objectID attributes synced from the domain. Which settings should you configure?

Options

  • ARoles and administrators
  • BApp roles
  • CCertificates and secrets
  • DToken configuration

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    10% (4)
  • D
    83% (34)

Explanation

https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-group-claims

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice