nerdexam
Microsoft

MS-102 · Question #94

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Implementing Password Hash Synchronization (PHS) may not fully meet the requirement for users to authenticate to Microsoft 365 services if Active Directory becomes unavailable, depending on specific hybrid configuration needs.

Submitted by omar99· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory forest. You deploy Microsoft 365. You plan to implement directory synchronization. You need to recommend a security solution for the synchronized identities. The solution must meet the following requirements:

  • Users must be able to authenticate successfully to Microsoft 365

services if Active Directory becomes unavailable.

  • User passwords must be 10 characters or more.

Solution: Implement password hash synchronization and configure password protection in the Azure AD tenant. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(29 responses)
  • A
    24% (7)
  • B
    76% (22)

Why each option

Implementing Password Hash Synchronization (PHS) may not fully meet the requirement for users to authenticate to Microsoft 365 services if Active Directory becomes unavailable, depending on specific hybrid configuration needs.

AYes

Password Hash Synchronization, while beneficial for cloud authentication resilience, might not cover all possible dependencies or real-time attribute lookups that specific Microsoft 365 services or hybrid applications might still require from on-premises Active Directory.

BNoCorrect

Although PHS stores password hashes in Azure AD, allowing cloud authentication even if on-premises Active Directory is down, some complex hybrid scenarios or specific legacy applications integrated with Microsoft 365 might still require connectivity to on-premises AD for full authentication or authorization attributes. Therefore, PHS alone might not ensure *all* Microsoft 365 services are accessible if AD is completely unavailable for an extended period, especially for dynamic identity management or certain federated resources.

Concept tested: Password Hash Synchronization (PHS) resilience

Source: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/whatis-phs

Topics

#Password Hash Synchronization (PHS)#Hybrid Identity#Password Policies#Azure AD Password Protection

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice