nerdexam
Microsoft

MS-102 · Question #578

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Entra Connect Sync and use Microsoft…

The correct answer is B. Password Hash Synchronization. To enable Microsoft Entra ID Protection to detect leaked credentials for hybrid users, configure Microsoft Entra Connect Sync to enable Password Hash Synchronization (PHS). This allows Entra ID to compare on-premises credential hashes against known leaked credentials, enabling…

Submitted by klara.se· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Entra Connect Sync and use Microsoft Entra ID Protection. You need to configure Microsoft Entra Connect Sync to ensure that Microsoft Entra ID Protection can detect leaked credentials. What should you select?

Options

  • APassword writeback
  • BPassword Hash Synchronization
  • CConfigure Hybrid Microsoft Entra join
  • DPass-through authentication
  • EEnable single sign-on

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    82% (27)
  • D
    6% (2)
  • E
    9% (3)

Explanation

To enable Microsoft Entra ID Protection to detect leaked credentials for hybrid users, configure Microsoft Entra Connect Sync to enable Password Hash Synchronization (PHS). This allows Entra ID to compare on-premises credential hashes against known leaked credentials, enabling risk-based, automated remediation or alerts. Steps to Configure: Install/Upgrade Entra Connect: Ensure the latest version of Microsoft Entra Connect is installed. Enable PHS: During installation, select Express Settings, which automatically enables password hash synchronization. Custom Installation: If using custom settings, enable Password Hash Synchronization on the "User sign-in" page. Verify Sync: Verify that password hashes are synchronizing by checking the Synchronization Service Manager. Enable ID Protection Policies: In the Microsoft Entra admin center, configure Identity Protection policies to require password changes for users with leaked credentials. While PHS is required for this detection, you may also consider setting up Microsoft Entra Connect Health for additional monitoring, ensuring the synchronization service is running on a https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-password-hash-

Topics

#Password Hash Synchronization#Microsoft Entra ID Protection#Credential Detection#Microsoft Entra Connect

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice