MS-102 · Question #94
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. Implementing Password Hash Synchronization (PHS) may not fully meet the requirement for users to authenticate to Microsoft 365 services if Active Directory becomes unavailable, depending on specific hybrid configuration needs.
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory forest. You deploy Microsoft 365. You plan to implement directory synchronization. You need to recommend a security solution for the synchronized identities. The solution must meet the following requirements:
- Users must be able to authenticate successfully to Microsoft 365
services if Active Directory becomes unavailable.
- User passwords must be 10 characters or more.
Solution: Implement password hash synchronization and configure password protection in the Azure AD tenant. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(29 responses)- A24% (7)
- B76% (22)
Why each option
Implementing Password Hash Synchronization (PHS) may not fully meet the requirement for users to authenticate to Microsoft 365 services if Active Directory becomes unavailable, depending on specific hybrid configuration needs.
Password Hash Synchronization, while beneficial for cloud authentication resilience, might not cover all possible dependencies or real-time attribute lookups that specific Microsoft 365 services or hybrid applications might still require from on-premises Active Directory.
Although PHS stores password hashes in Azure AD, allowing cloud authentication even if on-premises Active Directory is down, some complex hybrid scenarios or specific legacy applications integrated with Microsoft 365 might still require connectivity to on-premises AD for full authentication or authorization attributes. Therefore, PHS alone might not ensure *all* Microsoft 365 services are accessible if AD is completely unavailable for an extended period, especially for dynamic identity management or certain federated resources.
Concept tested: Password Hash Synchronization (PHS) resilience
Source: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/whatis-phs
Topics
Community Discussion
No community discussion yet for this question.