nerdexam
Microsoft

MS-102 · Question #142

Your network contains an on-premises Active Directory domain. You have a Microsoft 365 subscription. You implement a directory synchronization solution that uses pass-through authentication. You confi

Sign in or unlock MS-102 to reveal the answer and full explanation for question #142. The question stem and answer options stay visible for context.

Submitted by daniela_cl· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Your network contains an on-premises Active Directory domain. You have a Microsoft 365 subscription. You implement a directory synchronization solution that uses pass-through authentication. You configure Azure AD smart lockout as shown in the following exhibit. You discover that Active Directory users can use the passwords in the custom banned passwords list. You need to ensure that banned passwords are banned for all users. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Exhibit

MS-102 question #142 exhibit

Options

  • AFrom a domain controller, install the Azure AD Password Protection Proxy.
  • BFrom Active Directory, modify the Default Domain Policy.
  • CFrom a domain controller, install the Azure AD Application Proxy connector.
  • DFrom all the domain controllers, install the Azure AD Password Protection DC Agent.
  • EFrom Password protection for Windows Server Active Directory, modify the Mode setting.
  • FFrom Custom banned passwords, modify the Enforce custom list setting.

Unlock MS-102 to see the answer

You've previewed enough free MS-102 questions. Unlock MS-102 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Azure AD Password Protection#Hybrid Identity#Pass-through Authentication#Active Directory
Full MS-102 Practice