MD-102 · Question #533
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to…
The correct answer is B. Microsoft Entra hybrid joined. To provide seamless access to on-premises file shares without re-prompting credentials, while minimizing reliance on on-premises infrastructure for device identity, Microsoft Entra hybrid joined devices are the correct solution.
Question
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to contoso.com. The solution must meet the following requirements:
- Ensure that from the devices, users can access shares on an on-
premises file server without being prompted for credentials.
- Minimize reliance on the on-premises infrastructure for device
identity management. Which join type should you use?
Options
- AActive Directory domain-joined
- BMicrosoft Entra hybrid joined
- CMicrosoft Entra joined
- DMicrosoft Entra registered
How the community answered
(50 responses)- A18% (9)
- B64% (32)
- C6% (3)
- D12% (6)
Why each option
To provide seamless access to on-premises file shares without re-prompting credentials, while minimizing reliance on on-premises infrastructure for device identity, Microsoft Entra hybrid joined devices are the correct solution.
Active Directory domain-joined devices fully rely on on-premises infrastructure for device identity management, which contradicts the requirement to minimize this reliance.
Microsoft Entra hybrid joined devices are joined to both on-premises Active Directory and Microsoft Entra ID, enabling seamless single sign-on to both on-premises resources, such as file shares, and cloud resources. This setup fulfills the requirement for accessing on-premises shares without credential prompts, while still leveraging Microsoft Entra ID for device identity management, thereby reducing exclusive reliance on the on-premises infrastructure.
Microsoft Entra joined devices are primarily for cloud-only or cloud-first environments and would require additional configuration (like Kerberos cloud trust) to access on-premises file shares seamlessly, which is not implied as the primary solution and wouldn't be as direct for existing on-premises shares.
Microsoft Entra registered devices are typically personal devices and do not provide the necessary deep integration for seamless access to on-premises domain-joined resources like file shares without additional prompts.
Concept tested: Microsoft Entra hybrid join for on-premises resource access and cloud identity
Source: https://learn.microsoft.com/en-us/entra/identity/devices/concept-directory-ad-azure-and-hybrid-joined
Topics
Community Discussion
No community discussion yet for this question.