AZ-801 / Assessment
An administrator has established synchronization between their AD DS and Azure AD environments. Users whose accounts are synced appear able to sign in, but none seem to be able to access cloud resources. What's the likely problem?
AZ-801 / Q11 / T1
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant by using password hash synchronization.
You have a Microsoft 365 subscription.
All devices are hybrid Azure AD-joined.
Users report that they must enter their password manually when accessing Microsoft 365 applications.
You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services.
What should you do?
AZ-800 / Q11 / MS
Your network contains an on-premises Active Directory Domain Services (AD DS) domain and a Microsoft Entra tenant.
You need to configure synchronization between the AD DS domain and the Microsoft Entra tenant.
What should you do?
AZ-800 / Q10 / MS
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and a Microsoft Entra tenant named contoso.com that sync by using Microsoft Entra Connect.
Microsoft Entra Connect sync is configured to use pass-through authentication with seamless single sign-on (SSO).
You need to deploy a Microsoft Entra Domain Services domain named fabrikam.com that will be integrated with the Microsoft Entra tenant.
What should you do first?
AZ-800 / Q9 / MS
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.
You need to ensure that when an on-premises user signs in to Microsoft Entra, the authentication request is validated by an on-premises AD DS domain controller. The solution must minimize administrative effort.
What should you enable?
AZ-800 / Q65 / T1
Which Microsoft Entra Connect feature should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-800 / Q54 / T1
Your on-premises network contains a single-domain Active Directory Domain Services (AD DS) forest. You have an Azure AD tenant named contoso.com. The
AD DS forest syncs with the Azure AD tenant by using Azure AD Connect.
You need to ensure that users in the forest that have a custom attribute of NoSync are excluded from synchronization.
How should you configure the Azure AD Connect cloudFiltered attribute, and which tool should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-800 / Q48 / T1
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.
You deploy an app that adds custom attributes to the domain.
From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.
You need to ensure that the custom attributes are available in Azure AD.
Which task should you perform from Microsoft Azure Active Directory Connect first?
AZ-800 / Q42 / T1
Your on-premises network contains an Active Directory Domain Services (AD DS) domain.
You plan to sync the domain with an Azure AD tenant by using Azure AD Connect cloud sync.
You need to meet the following requirements:
• Install the software required to sync the domain and Azure AD.
• Enable password hash synchronization.
What should you install, and what should you use to enable password hash synchronization? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-800 / Q41 / T1
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure AD tenant. The tenant contains a group named Group1 and the users shown in the following table.
Domain/OU filtering in Azure AD Connect is configured as shown in the Filtering exhibit. (Click the Filtering tab.)