nerdexam
Microsoft

MS-900 · Question #437

Drag and Drop Question A company deploys Azure App Services apps in Azure. Users authenticate to the apps by using single sign-on (SSO). The company requires access to the apps from the following type

The correct answer is Azure AD registered device; Hybrid Azure AD joined device. Azure AD Registered devices are designed for personal (BYOD) devices where users sign in with a personal account rather than an organizational account, allowing access to company resources without requiring the device to be domain-joined. Hybrid Azure AD Joined devices are the co

Submitted by jaden.t· Mar 5, 2026Implement and manage Azure Active Directory identities - specifically device identity types including Azure AD Registered, Azure AD Joined, and Hybrid Azure AD Joined devices (Microsoft Identity and Access Administrator / AZ-500 / SC-300)

Question

Drag and Drop Question A company deploys Azure App Services apps in Azure. Users authenticate to the apps by using single sign-on (SSO). The company requires access to the apps from the following types of devices: - Personal devices that do not require an organizational account to sign in to the device. - Company devices in on-premises Active Directory that are automatically provisioned in Azure Active Directory (Azure AD). You need to identify how the devices will be provisioned in Azure AD. What should you use? To answer, drag the appropriate Azure AD device identities to the correct requirements. Each Azure AD device identity may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #437 exhibit

Answer Area

Drag items

Azure AD joined deviceAzure AD registered deviceHybrid Azure AD joined device

Correct arrangement

  • Azure AD registered device
  • Hybrid Azure AD joined device

Explanation

Azure AD Registered devices are designed for personal (BYOD) devices where users sign in with a personal account rather than an organizational account, allowing access to company resources without requiring the device to be domain-joined. Hybrid Azure AD Joined devices are the correct choice for company-owned devices already joined to on-premises Active Directory, as this configuration automatically syncs and provisions them in Azure AD using Azure AD Connect, satisfying the requirement for automatic provisioning. Azure AD Joined devices are cloud-only joined devices that require an organizational account at sign-in and are not automatically provisioned from on-premises AD, making them unsuitable for either scenario described.

Topics

#Azure AD Device Identity#Hybrid Azure AD Join#Azure AD Registration#Identity Management

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice