MS-102 · Question #143
Your network contains an Active Directory domain and an Azure AD tenant. The network uses a firewall that contains a list of allowed outbound domains. You begin to implement directory…
The correct answer is A. From the firewall, modify the list of allowed outbound domains. Azure AD Connect needs to be able to connect to various Microsoft domains such as login.microsoftonline.com. Therefore, you need to modify the list of allowed outbound domains on https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-ports
Question
Your network contains an Active Directory domain and an Azure AD tenant. The network uses a firewall that contains a list of allowed outbound domains. You begin to implement directory synchronization. You discover that the firewall configuration contains only the following domain names in the list of allowed domains:
- *.microsoft.com
- *.office.com
Directory synchronization fails. You need to ensure that directory synchronization completes successfully. What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.
Options
- AFrom the firewall, modify the list of allowed outbound domains.
- BFrom Azure AD Connect, modify the Customize synchronization options task.
- CFrom the firewall, create a list of allowed inbound domains.
- DDeploy an Azure AD Connect sync server in staging mode.
- EFrom the firewall, allow the IP address range of the Azure data center for outbound
How the community answered
(67 responses)- A76% (51)
- B6% (4)
- C1% (1)
- D13% (9)
- E3% (2)
Explanation
Azure AD Connect needs to be able to connect to various Microsoft domains such as login.microsoftonline.com. Therefore, you need to modify the list of allowed outbound domains on https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-ports
Topics
Community Discussion
No community discussion yet for this question.