nerdexam
Microsoft

MS-102 · Question #71

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. The scenario involves User2 whose UPN (user principal name) uses the suffix @fabrikam.com, but the Azure AD tenant is named contoso.com. For a user to authenticate to Azure AD with a UPN suffix like @fabrikam.com, that domain must be added to and verified in the Azure AD tenant…

Submitted by saadiq_pk· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table. The domain syncs to an Azure AD tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.) User2 fails to authenticate to Azure AD when signing in as [email protected]. You need to ensure that User2 can access the resources in Azure AD. Solution: From the on-premises Active Directory domain, you assign User2 the Allow logon locally user right. You instruct User2 to sign in as [email protected]. Does this meet the goal?

Exhibit

MS-102 question #71 exhibit

Options

  • AYes
  • BNo

How the community answered

(31 responses)
  • A
    19% (6)
  • B
    81% (25)

Explanation

The scenario involves User2 whose UPN (user principal name) uses the suffix @fabrikam.com, but the Azure AD tenant is named contoso.com. For a user to authenticate to Azure AD with a UPN suffix like @fabrikam.com, that domain must be added to and verified in the Azure AD tenant as a custom domain. The solution being evaluated in this question does not include adding and verifying the fabrikam.com domain in the Azure AD tenant, which is the root cause of the authentication failure. Without the custom domain being present in the tenant's verified domains list, Azure AD will not recognize [email protected] as a valid sign-in identity, so the proposed solution does not meet the stated goals - the answer is No (B).

Topics

#Azure AD authentication#Hybrid identity#User Principal Name (UPN)#On-premises AD permissions

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice