Exam
Answer confirmed
Question
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and a Microsoft Entra tenant named contoso.com that sync by using Microsoft Entra Connect.
Microsoft Entra Connect sync is configured to use pass-through authentication with seamless single sign-on (SSO).
You need to deploy a Microsoft Entra Domain Services domain named fabrikam.com that will be integrated with the Microsoft Entra tenant.
What should you do first?
Proposed answer
- A) Add fabrikam.com as a verified domain to the contoso.com
- B) Enablie Security defaults in the contoso.com
- C) Disable SSO
- D) Modify Microsoft Entra Connect sync to use password hash synchronization.
Correct answer
Modify Microsoft Entra Connect sync to use password hash synchronization.
- A) Incorrect - Adding fabrikam.com as a verified domain to the contoso.com Microsoft Entra tenant is not required to deploy a Microsoft Entra Domain Services domain.
- B) Incorrect - Enabling Security defaults in the contoso.com Microsoft Entra tenant is not required to deploy a Microsoft Entra Domain services domain.
- C) Incorrect - Disabling SSO is not required to deploy a Microsoft Entra Domain services domain.
- D) Correct – Microsoft Entra Domain services requires that tenants have password hash synchronization enabled, so tenants that use only pass-through authentication will not work in this scenario.
Implement Seamless Single Sign-On - Training | Microsoft Learn