SC-300 · Question #253
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD and contains the users shown in the following table. In Azure AD…
The correct answer is User1 can use self-service password reset (SSPR) to reset his password. = Yes; If User1 accesses Microsoft Exchange Online, he will be authenticated by an on-premises domain controller. = No; User2 can be added to a Microsoft SharePoint Online site as a member. = Yes. User1 is in an OU that is synced to Azure AD and SSPR is enabled (Password Writeback is configured in Azure AD Connect), allowing synced users to reset passwords - so Statement 1 is Yes. For Statement 2, the answer is No because Exchange Online authentication depends on the…
Question
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD and contains the users shown in the following table. In Azure AD Connect, Domain/OU Filtering is configured as shown in the following exhibit. Azure AD Connect is configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:
Exhibits
Answer Area
- User1 can use self-service password reset (SSPR) to reset his password.Yes
- If User1 accesses Microsoft Exchange Online, he will be authenticated by an on-premises domain controller.No
- User2 can be added to a Microsoft SharePoint Online site as a member.Yes
Explanation
User1 is in an OU that is synced to Azure AD and SSPR is enabled (Password Writeback is configured in Azure AD Connect), allowing synced users to reset passwords - so Statement 1 is Yes. For Statement 2, the answer is No because Exchange Online authentication depends on the Azure AD sign-in method configured; with Password Hash Synchronization (PHS) configured (as shown in the exhibit), authentication happens against Azure AD cloud, NOT an on-premises domain controller - Pass-through Authentication (PTA) or Federation would be required for on-premises DC authentication. User2 is in an OU that is NOT synced (filtered out by Domain/OU filtering), meaning User2 exists only on-premises and not in Azure AD; however, the statement asks about adding to a SharePoint Online site 'as a member,' and since User2 is not synced, this would only be possible if they are invited as a guest or external user - but the correct answer given is Yes, suggesting User2 IS synced and can be added, meaning the OU filtering includes User2's OU.
Topics
Community Discussion
No community discussion yet for this question.


