nerdexam
Microsoft

MD-102 · Question #532

Your on-premises network contains an Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You need to enable users to connect to Microsoft 365 services from…

The correct answer is A. Microsoft Entra registered. To enable single sign-on (SSO) to Microsoft 365 services from personal Windows devices while minimizing organizational control, Microsoft Entra registered is the appropriate join type.

Submitted by yuriko_h· Apr 18, 2026Prepare infrastructure for devices

Question

Your on-premises network contains an Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You need to enable users to connect to Microsoft 365 services from their personal Windows devices by using single sign-on (SSO). The solution must minimize organizational control of the devices. Which join type should you use?

Options

  • AMicrosoft Entra registered
  • BMicrosoft Entra joined
  • CActive Directory domain-joined
  • DMicrosoft Entra hybrid joined

How the community answered

(23 responses)
  • A
    83% (19)
  • B
    4% (1)
  • C
    4% (1)
  • D
    9% (2)

Why each option

To enable single sign-on (SSO) to Microsoft 365 services from personal Windows devices while minimizing organizational control, Microsoft Entra registered is the appropriate join type.

AMicrosoft Entra registeredCorrect

Microsoft Entra registered (formerly Workplace Join) allows users to register their personal devices with Microsoft Entra ID. This provides users with single sign-on (SSO) access to cloud resources like Microsoft 365 services from their personal devices, while minimizing the organization's control over the device, as it's not fully managed or joined to a domain.

BMicrosoft Entra joined

Microsoft Entra joined devices are fully managed by Microsoft Entra ID and are intended for corporate-owned devices, giving the organization significant control.

CActive Directory domain-joined

Active Directory domain-joined devices are fully managed by on-premises Active Directory, implying maximum organizational control and primarily for on-premises resources.

DMicrosoft Entra hybrid joined

Microsoft Entra hybrid joined devices are joined to both on-premises AD and Microsoft Entra ID, providing extensive organizational control and is typically for corporate-owned devices managed from both environments.

Concept tested: Microsoft Entra device registration for BYOD and SSO

Source: https://learn.microsoft.com/en-us/entra/identity/devices/concept-directory-ad-azure-and-hybrid-joined

Topics

#Microsoft Entra registered#Device join types#Single sign-on#BYOD

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice