nerdexam
Microsoft

SC-300 · Question #253

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD and contains the users shown in the following table. In Azure AD…

The correct answer is User1 can use self-service password reset (SSPR) to reset his password. = Yes; If User1 accesses Microsoft Exchange Online, he will be authenticated by an on-premises domain controller. = No; User2 can be added to a Microsoft SharePoint Online site as a member. = Yes. User1 is in an OU that is synced to Azure AD and SSPR is enabled (Password Writeback is configured in Azure AD Connect), allowing synced users to reset passwords - so Statement 1 is Yes. For Statement 2, the answer is No because Exchange Online authentication depends on the…

Submitted by hassan_iq· Mar 6, 2026Implement and Manage Identity Synchronization with Azure AD Connect - covering authentication methods (PHS, PTA, Federation), SSPR with Password Writeback, and OU/Domain filtering to control which on-premises objects are synchronized to Azure AD.

Question

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD and contains the users shown in the following table. In Azure AD Connect, Domain/OU Filtering is configured as shown in the following exhibit. Azure AD Connect is configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-300 question #253 exhibit 1
SC-300 question #253 exhibit 2
SC-300 question #253 exhibit 3

Answer Area

  • User1 can use self-service password reset (SSPR) to reset his password.Yes
  • If User1 accesses Microsoft Exchange Online, he will be authenticated by an on-premises domain controller.No
  • User2 can be added to a Microsoft SharePoint Online site as a member.Yes

Explanation

User1 is in an OU that is synced to Azure AD and SSPR is enabled (Password Writeback is configured in Azure AD Connect), allowing synced users to reset passwords - so Statement 1 is Yes. For Statement 2, the answer is No because Exchange Online authentication depends on the Azure AD sign-in method configured; with Password Hash Synchronization (PHS) configured (as shown in the exhibit), authentication happens against Azure AD cloud, NOT an on-premises domain controller - Pass-through Authentication (PTA) or Federation would be required for on-premises DC authentication. User2 is in an OU that is NOT synced (filtered out by Domain/OU filtering), meaning User2 exists only on-premises and not in Azure AD; however, the statement asks about adding to a SharePoint Online site 'as a member,' and since User2 is not synced, this would only be possible if they are invited as a guest or external user - but the correct answer given is Yes, suggesting User2 IS synced and can be added, meaning the OU filtering includes User2's OU.

Topics

#Azure AD Connect#Self-Service Password Reset (SSPR)#Password Hash Synchronization#OU Filtering

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice