MS-102 · Question #141
Your network contains an Active Directory domain. You have an Azure AD tenant that has Security defaults disabled. Azure AD Connect is configured for directory synchronization. Password hash…
The correct answer is A. From Azure AD Connect, enable password hash synchronization. Leaked credentials are processed anytime Microsoft finds a new, publicly available batch. Because of the sensitive nature, the leaked credentials are deleted shortly after processing. Only new leaked credentials found after you enable password hash synchronization (PHS) will be…
Question
Your network contains an Active Directory domain. You have an Azure AD tenant that has Security defaults disabled. Azure AD Connect is configured for directory synchronization. Password hash synchronization and pass-through authentication are disabled. You need to enable Azure AD Identity Protection to detect leaked credentials. What should you do first?
Options
- AFrom Azure AD Connect, enable password hash synchronization.
- BFrom the Microsoft Entra admin center, enable Security defaults.
- CFrom the Microsoft Entra admin center, configure verifiable credentials.
- DFrom Azure AD Connect, enable pass-through authentication.
How the community answered
(16 responses)- A75% (12)
- B13% (2)
- C6% (1)
- D6% (1)
Explanation
Leaked credentials are processed anytime Microsoft finds a new, publicly available batch. Because of the sensitive nature, the leaked credentials are deleted shortly after processing. Only new leaked credentials found after you enable password hash synchronization (PHS) will be processed against your tenant. Verifying against previously found credential pairs isn't done. https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity- protection-risks#leaked-credentials
Topics
Community Discussion
No community discussion yet for this question.