nerdexam
Microsoft

MS-102 · Question #39

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is A. Yes. This question presents the same User2/fabrikam.com authentication failure scenario but with a different proposed solution. For User2 to sign in as [email protected], the correct fix requires: (1) adding fabrikam.com as a verified domain in the Azure AD tenant, and (2) updating…

Submitted by wei.xz· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table. The domain syncs to an Azure AD tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.) User2 fails to authenticate to Azure AD when signing in as [email protected]. You need to ensure that User2 can access the resources in Azure AD. Solution: From the Microsoft Entra admin center, you add fabrikam.com as a custom domain. You instruct User2 to sign in as [email protected]. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    18% (6)

Explanation

This question presents the same User2/fabrikam.com authentication failure scenario but with a different proposed solution. For User2 to sign in as [email protected], the correct fix requires: (1) adding fabrikam.com as a verified domain in the Azure AD tenant, and (2) updating User2's UPN in on-premises AD to [email protected] so it syncs correctly via Azure AD Connect. The solution in this question correctly addresses both requirements - verifying the domain in Azure AD and updating the user's UPN - which allows Azure AD to recognize and authenticate the user with the fabrikam.com suffix. Hence the answer is Yes.

Topics

#Azure AD Custom Domains#Hybrid Identity#User Principal Name (UPN)#Authentication

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice