Microsoft
SC-300 · Question #286
Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a certification authority (CA) named CA1. You have an Azure AD tenant. You need to implement…
The correct answer is B. Add CA1 as a Certificate Authority to the Microsoft Entra ID tenant. https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-
Submitted by khalil_dz· Mar 6, 2026Implement authentication and access management
Question
Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a certification authority (CA) named CA1. You have an Azure AD tenant. You need to implement certificate-based authentication in Azure AD. The solution must ensure that users can sign in by using certificates issued by CA1. What should you do first?
Options
- ADeploy an Azure key vault.
- BAdd CA1 as a Certificate Authority to the Microsoft Entra ID tenant.
- CEnable auto-enrollment for CA1.
- DDeploy Windows Hello for Business.
How the community answered
(37 responses)- A3% (1)
- B84% (31)
- C5% (2)
- D8% (3)
Explanation
https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-
Topics
#certificate-based authentication#Certificate Authority#Azure AD CBA#CA trust
Community Discussion
No community discussion yet for this question.