nerdexam
Microsoft

MS-900 · Question #158

Hotspot Question You are a Microsoft 365 administrator for a company. The company implements federated authentication and Azure AD Connect. For each of the following statements, select Yes if the…

The correct answer is Users have the same passwords in the cloud and on-premises. = No; Users sing in again to access Microsoft 365. = No; You can configure federated authentication to require a smart card. = Yes. Federated authentication provides Single Sign-On (SSO) using on-premises Active Directory credentials and supports advanced on-premises authentication methods like smart cards.

Submitted by brentm· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question You are a Microsoft 365 administrator for a company. The company implements federated authentication and Azure AD Connect. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #158 exhibit

Answer Area

  • Users have the same passwords in the cloud and on-premises.No
  • Users sing in again to access Microsoft 365.No
  • You can configure federated authentication to require a smart card.Yes

Explanation

Federated authentication provides Single Sign-On (SSO) using on-premises Active Directory credentials and supports advanced on-premises authentication methods like smart cards.

Approach. 1. 'Users have the same passwords in the cloud and on-premises' -> Yes. With federated authentication, Azure AD relies on the on-premises Active Directory to validate credentials. Users use their existing on-premises AD password to access cloud resources, meaning they have a single, unified password. 2. 'Users sign in again to access Microsoft 365' -> No. A primary benefit of federated authentication (such as AD FS) is Single Sign-On (SSO). When users are logged into a domain-joined device on the corporate network, Integrated Windows Authentication (IWA) can silently authenticate them to Microsoft 365 without prompting for credentials again. 3. 'You can configure federated authentication to require a smart card' -> Yes. AD FS supports certificate-based authentication, allowing organizations to enforce smart card usage for secure access.

Common mistakes.

  • common_mistake. A common mistake for the second statement is assuming that crossing the boundary from an on-premises device to a cloud service (Microsoft 365) always requires a distinct login prompt, ignoring the seamless Single Sign-On (SSO) capabilities provided by federation. For the first statement, some might confuse password storage (passwords aren't stored in Azure AD in pure federation without PHS) with the user experience (users still use the exact same password).

Concept tested. Azure AD Connect identity models, Federated Authentication (AD FS) features, Single Sign-On (SSO) behavior, and supported authentication methods.

Reference. https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-fed

Topics

#Federated authentication#Azure AD Connect#Single Sign-On (SSO)#Smart card authentication

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice