nerdexam
Microsoft

MS-102 · Question #28

Your network contains an on-premises Active Directory domain named contoso.local. The domain contains five domain controllers. Your company purchases Microsoft 365 and creates an Azure AD tenant…

The correct answer is C. From Active Directory Domains and Trusts, add a UPN suffix. E. From the Microsoft Entra admin center, add a custom domain name. F. Modify the User logon name for each user account. As the local ADDS name is "contoso.local", we need to make some few steps/prerequisites before being able to set up account synchronization: -> Add a custom domain name on the Azure AD / MS Entra portal (ex. contoso.com) -> Add a local UPN suffix at the ADDS Forest level…

Submitted by hassan_iq· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Your network contains an on-premises Active Directory domain named contoso.local. The domain contains five domain controllers. Your company purchases Microsoft 365 and creates an Azure AD tenant named contoso.onmicrosoft.com. You plan to install Azure AD Connect on a member server and implement pass-through authentication. You need to prepare the environment for the planned implementation of pass-through authentication. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AFrom a domain controller, install an Authentication Agent.
  • BFrom the Microsoft Entra admin center, configure an authentication method.
  • CFrom Active Directory Domains and Trusts, add a UPN suffix.
  • DModify the email address attribute for each user account.
  • EFrom the Microsoft Entra admin center, add a custom domain name.
  • FModify the User logon name for each user account.

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    8% (5)
  • C
    83% (49)
  • D
    3% (2)

Explanation

As the local ADDS name is "contoso.local", we need to make some few steps/prerequisites before being able to set up account synchronization: -> Add a custom domain name on the Azure AD / MS Entra portal (ex. contoso.com) -> Add a local UPN suffix at the ADDS Forest level (contoso.com) -> Modify all user account UPN from [email protected] to [email protected] Then comes the Azure AD Connect deployment & the PTA configuration.

Topics

#Azure AD Connect#Hybrid Identity#Pass-through Authentication#Custom Domains

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice