MS-102 · Question #578
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Entra Connect Sync and use Microsoft…
The correct answer is B. Password Hash Synchronization. To enable Microsoft Entra ID Protection to detect leaked credentials for hybrid users, configure Microsoft Entra Connect Sync to enable Password Hash Synchronization (PHS). This allows Entra ID to compare on-premises credential hashes against known leaked credentials, enabling…
Question
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Entra Connect Sync and use Microsoft Entra ID Protection. You need to configure Microsoft Entra Connect Sync to ensure that Microsoft Entra ID Protection can detect leaked credentials. What should you select?
Options
- APassword writeback
- BPassword Hash Synchronization
- CConfigure Hybrid Microsoft Entra join
- DPass-through authentication
- EEnable single sign-on
How the community answered
(33 responses)- A3% (1)
- B82% (27)
- D6% (2)
- E9% (3)
Explanation
To enable Microsoft Entra ID Protection to detect leaked credentials for hybrid users, configure Microsoft Entra Connect Sync to enable Password Hash Synchronization (PHS). This allows Entra ID to compare on-premises credential hashes against known leaked credentials, enabling risk-based, automated remediation or alerts. Steps to Configure: Install/Upgrade Entra Connect: Ensure the latest version of Microsoft Entra Connect is installed. Enable PHS: During installation, select Express Settings, which automatically enables password hash synchronization. Custom Installation: If using custom settings, enable Password Hash Synchronization on the "User sign-in" page. Verify Sync: Verify that password hashes are synchronizing by checking the Synchronization Service Manager. Enable ID Protection Policies: In the Microsoft Entra admin center, configure Identity Protection policies to require password changes for users with leaked credentials. While PHS is required for this detection, you may also consider setting up Microsoft Entra Connect Health for additional monitoring, ensuring the synchronization service is running on a https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-password-hash-
Topics
Community Discussion
No community discussion yet for this question.