SC-300 · Question #173
How should the access be setup to the on-premises applications? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:
The correct answer is Configure the Azure AD Password Protection proxy service on:: SERVER2; Configure the password list:: In Azure AD. This case study hotspot tests your understanding of Azure AD Connect authentication modes and their impact on available security features, particularly how disabling password hash synchronization limits certain Azure AD Identity Protection and Microsoft Cloud App Security…
Question
Exhibit
Answer Area
- Configure the Azure AD Password Protection proxy service on:SERVER2DC1SERVER1SERVER2
- Configure the password list:In Azure ADIn Azure ADOn DC1On SERVER1On SERVER2
How the community answered
(1 responses)- SERVER2|In Azure AD100% (1)
Explanation
This case study hotspot tests your understanding of Azure AD Connect authentication modes and their impact on available security features, particularly how disabling password hash synchronization limits certain Azure AD Identity Protection and Microsoft Cloud App Security capabilities.
Approach. The critical detail is that Azure AD Connect uses pass-through authentication (PTA) with password hash synchronization (PHS) explicitly DISABLED. This matters because several security features require PHS to function: leaked credential detection in Azure AD Identity Protection cannot work without password hashes being synced to the cloud. For any hotspot row asking whether a feature like 'leaked credentials report' or 'risky sign-ins based on credential checks' is available, the answer is No because PHS is off. Features that DO work with PTA alone (like Conditional Access, MFA, sign-in risk based on behavioral signals) should be marked Yes. Guest accounts from fabrikam.com are governed by the litware.com tenant policies, so cross-tenant access controls apply to them as well.
Concept tested. Azure AD Connect authentication method trade-offs: Pass-Through Authentication vs Password Hash Synchronization, and specifically which Identity Protection and MCAS features are unavailable when PHS is disabled (e.g., leaked credential detection requires hashes in the cloud).
Topics
Community Discussion
No community discussion yet for this question.
