nerdexam
Microsoft

MD-102 · Question #533

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to…

The correct answer is B. Microsoft Entra hybrid joined. To provide seamless access to on-premises file shares without re-prompting credentials, while minimizing reliance on on-premises infrastructure for device identity, Microsoft Entra hybrid joined devices are the correct solution.

Submitted by omar99· Apr 18, 2026Prepare infrastructure for devices

Question

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to contoso.com. The solution must meet the following requirements:

  • Ensure that from the devices, users can access shares on an on-

premises file server without being prompted for credentials.

  • Minimize reliance on the on-premises infrastructure for device

identity management. Which join type should you use?

Options

  • AActive Directory domain-joined
  • BMicrosoft Entra hybrid joined
  • CMicrosoft Entra joined
  • DMicrosoft Entra registered

How the community answered

(50 responses)
  • A
    18% (9)
  • B
    64% (32)
  • C
    6% (3)
  • D
    12% (6)

Why each option

To provide seamless access to on-premises file shares without re-prompting credentials, while minimizing reliance on on-premises infrastructure for device identity, Microsoft Entra hybrid joined devices are the correct solution.

AActive Directory domain-joined

Active Directory domain-joined devices fully rely on on-premises infrastructure for device identity management, which contradicts the requirement to minimize this reliance.

BMicrosoft Entra hybrid joinedCorrect

Microsoft Entra hybrid joined devices are joined to both on-premises Active Directory and Microsoft Entra ID, enabling seamless single sign-on to both on-premises resources, such as file shares, and cloud resources. This setup fulfills the requirement for accessing on-premises shares without credential prompts, while still leveraging Microsoft Entra ID for device identity management, thereby reducing exclusive reliance on the on-premises infrastructure.

CMicrosoft Entra joined

Microsoft Entra joined devices are primarily for cloud-only or cloud-first environments and would require additional configuration (like Kerberos cloud trust) to access on-premises file shares seamlessly, which is not implied as the primary solution and wouldn't be as direct for existing on-premises shares.

DMicrosoft Entra registered

Microsoft Entra registered devices are typically personal devices and do not provide the necessary deep integration for seamless access to on-premises domain-joined resources like file shares without additional prompts.

Concept tested: Microsoft Entra hybrid join for on-premises resource access and cloud identity

Source: https://learn.microsoft.com/en-us/entra/identity/devices/concept-directory-ad-azure-and-hybrid-joined

Topics

#Entra hybrid join#device identity#Windows 11 deployment#on-premises SSO

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice