SC-300 Exam QuestionsBrowse all questions from this exam

SC-300 Exam - Question 16


Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the users shown in the following table.

Exam SC-300 Question 16

All the users work remotely.

Azure AD Connect is configured in Azure AD as shown in the following exhibit.

Exam SC-300 Question 16

Connectivity from the on-premises domain to the internet is lost.

Which users can sign in to Azure AD?

Show Answer
Correct Answer: A

In the given scenario, User2 cannot sign in because Pass-through Authentication (PTA) requires connectivity to the on-premises domain, which is currently lost. Password Hash Synchronization (PHS) is enabled but switching the authentication method from PTA to PHS is not automatic and requires manual intervention through Azure AD Connect. In the absence of this manual switch, User2 will not be able to authenticate. User1 and User3, however, are not synced with the on-premises domain and can authenticate directly with Azure AD. Therefore, User1 and User3 only can sign in.

Discussion

28 comments
Sign in to comment
examkid
Jul 23, 2021

I think the answer is correct. When the connection to on-premise is lost, PTA will not work anymore. The failover to Password Hash Synchronization is not automatic and needs to be configured manually in AD Connect. If the connection to on-premise is lost, and the AD Connect server runs un-premise, user 2 cannot login. -~~~~~- Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Azure AD Connect. If the server running Azure AD Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication.

AmazingKies
Sep 16, 2021

Pass-through authentication is configured, Sync user will try to authenticate on local AD and unable to authenticate due to internet outage only cloud users ( User 1 and User 3) can be authenticated Correct Answer : A

rachee
Sep 23, 2024

C. Per https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-current-limitations, Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. The diagram shows Pasword Hash Synchronization is enabled.

Tuvshinjargal
Feb 6, 2024

I agree with that. Since the Password Hash Synchronization is enabled, it must have been synched an hour ago, and also the password is saved in Azure AD. It remains when the on-premise AD lost the connection to the internet. See below article. https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-faq When you use Microsoft Entra Connect to switch the sign-in method from password hash synchronization to Pass-through Authentication, Pass-through Authentication becomes the primary sign-in method for your users in managed domains. All users' password hashes that are previously synchronized by password hash synchronization remain stored on Microsoft Entra ID.

RahulX
Feb 11, 2024

If password hash synchronization is enabled, all synced users can login with an AD pwd hash value if DC connectivity is lost, and if any user changes their pwd during this period, the hash will remain until the connection is restored. If you have enabled PTA earlier or have installed the PTA DC agent, it will show the pass-through authentication. Enabled 1 or 2 agents under User Sign-In status in azure ad portal.

RahulX
Feb 11, 2024

If password hash synchronization is enabled, all synced users can login with an AD pwd hash value if DC connectivity is lost, and if any user changes their pwd during this period, the hash will remain until the connection is restored. If you have enabled PTA earlier or have installed the PTA DC agent, it will show the pass-through authentication. Enabled 1 or 2 agents under User Sign-In status in azure ad portal.

EmnCoursOption: A
Aug 10, 2023

Correct Answer : A

hhaywood
Jun 7, 2021

I must be missing something here? As only User 2 is synced to AAD with password has then sure this is the only user who can logon?

yaniys
Jun 8, 2021

User2's authentication still involves the AD. And as the connection is lost he is the only one who wouldn't be able to login as both the other users are cloud only

hhaywood
Jun 8, 2021

Ah yes! I was reading 'not synced' the wrong way round and assumed they were on-prem users. Thanks yaniys!

Azuredude123
Jun 8, 2021

They have to sign in through on-prem, on-prem is down so they cannot sign in. Pass Hash sync and Pass through enabled.

hhaywood
Jun 8, 2021

Ah yes! I was reading 'not synced' the wrong way round and assumed they were on-prem users. Thanks yaniys!

Anonymous
Jun 21, 2021

correct; both password hash sync and passthrough are enabled, but no mention of failover initiated; thus user2 can't authenticate https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq#does-password-hash-synchronization-act-as-a-fallback-to-pass-through-authentication

smosmoOption: A
Dec 13, 2021

A is right. For the synced User no authentication will take place. Password hash synchronization does not act as a fallback to Pass-through Authentication. Pass-through Authentication does not apply to cloud-only users. So they can login.

dule27Option: A
May 22, 2023

A. User1 and User3 only

simonseztechOption: A
Sep 23, 2024

Does password hash synchronization act as a fallback to Pass-through Authentication? No. Pass-through Authentication does not automatically failover to password hash synchronization. To avoid user sign-in failures, you should configure Pass-through Authentication for high availability.

f2bf85aOption: A
Sep 23, 2024

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-current-limitations#unsupported-scenarios Read the Note: Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Azure AD Connect. If the server running Azure AD Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication. Since the Password Hash sync failover is not automatic, in this case the answer is A. User2 that is directory sync will need Pass-Through Authentication, which will be unavailable at that moment.

[Removed]Option: A
Sep 23, 2024

Answer A is correct. PTA cannot be used for directory synchronised objects when the connectivity is lost.

Olami
Oct 7, 2024

Connectivity to on-prems directory to the internet is lost, not the users' connectivity to the internet. I think User 1 and User 3 are not syncing with the on-prems directory. They are on the Azure AD. Only User 2 will have difficulty to sign in to Azure AD because of the Password Hash Sync btw on-prems and Azure AD. Answer is A

AlexBrazilOption: A
Oct 29, 2024

According to https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-current-limitations: Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Microsoft Entra Connect. If the server running Microsoft Entra Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication.

test123123Option: C
Jan 6, 2025

By enabling Password Hash sync, you ensure that password hashes are synchronized to Azure AD, allowing users to authenticate even if the on-premises environment is unavailable. Password Hash sync is enabled, so answer is C.

test123123
Jan 10, 2025

if your Azure AD Connect sync status shows "Password Hash Sync Enabled" and "Pass-Through Authentication Enabled," it means that users can still log on to Microsoft 365 even if the on-premises Active Directory loses internet connection.

Frank9020Option: C
Jan 14, 2025

User1: Can sign in because they are not directory-synced and their account exists solely in Azure AD. User2: Can sign in because Password Hash Sync is enabled, allowing authentication to Azure AD even without on-premises connectivity. User3: Can sign in because guest accounts authenticate directly with their own identity provider and do not rely on the on-premises domain.

AS007
Jun 7, 2021

Correct - pass hash sync enable so # 2 won’t authenticate

Sh1rub10Option: A
Mar 28, 2022

only cloud users ( User 1 and User 3) can be authenticated

bleedinging
May 24, 2022

Correct. Only domain-synced users will be affected. Cloud users can still access cloud resources.

Tokiki
Jun 26, 2022

Agree .A

estyj
Nov 4, 2022

Correct A. https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-current-limitations

Sango
Jul 3, 2023

Answer A is correct. PTA is enabled which means no AD synced user auth will work until the issue is resolved. If both PHS and PTA are enabled (as per config) it is still a manual process (not mentioned in the question) to roll back to PHS. Microsoft: "Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Azure AD Connect. If the server running Azure AD Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication."

RahulX
Feb 11, 2024

A. User1 and User3 only correct ans.

RahulX
Feb 11, 2024

Sorry, The correct ans will be C. User1, User2, and User3.

NotanAdmin
May 20, 2024

I got correct answer, but maybe my logic is off? All users work remotely, so wouldnt they log in to AAD, not on prem? Assuming User 2 uses a VPN to login through AD on-prem, I read it as User 2 is already synced. Therefore, A.

melatocaroca
Sep 23, 2024

Answer C Both password hash sync and pass-through are enabled, no password change in the question, just login Only on-premises domain to the internet is lost User1 and User 3 are users that will log in with their hash in AAD, User3 is an AAD guest will log with his own credentials created guest on AAD, so IMHO answer must be C Pass-through Authentication does not automatically failover to password hash synchronization. To avoid user sign-in failures, you should configure Pass-through Authentication for high availability. The password hash synchronization process runs every 2 minutes. When a user attempts to sign into Azure AD and enters their password, the password is run through the same MD4+salt+PBKDF2+HMAC-SHA256 process. If the resulting hash matches the hash stored in Azure AD, the user has entered the correct password and is authenticated.

Jonasweimar
Sep 24, 2022

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-current-limitations "Enabling Password Hash Synchronization gives you the option to failover authentication if your on-premises infrastructure is disrupted. This failover from Pass-through Authentication to Password Hash Synchronization is not automatic. You'll need to switch the sign-in method manually using Azure AD Connect. If the server running Azure AD Connect goes down, you'll require help from Microsoft Support to turn off Pass-through Authentication."

SebArgyOption: C
Dec 19, 2024

Reponse C. 1 - The password is sync 2 - TPHS ensures that users can authenticate to cloud services even if the on-premises AD is down. 3 - The tenant is not Federate, that means that tenant is Managed. Like that, you can directly authenticate with Entra.

kruteshOption: C
Feb 18, 2025

Pass-through Authentication (PTA) validates users' passwords directly against on-premises Active Directory. It ensures on-premises security policies are enforced and does not store passwords in the cloud. Password Hash Synchronization (PHS) synchronizes a hash of user's password from on-premises Active Directory to Azure AD. It allows users to sign in to Azure AD using the same password they use on-premises. If both methods are enabled, PTA will take precedence for authentication. PHS can act as a backup, allowing users to sign in even if the PTA agent is temporarily unavailable.

stefwandersOption: A
Mar 15, 2025

Microsoft FAQ states: "No. Pass-through Authentication doesn't automatically failover to password hash synchronization. To avoid user sign-in failures, you should configure Pass-through Authentication for high availability." https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-pta-faq#does-password-hash-synchronization-act-as-a-fallback-to-pass-through-authentication-

Yassine1988Option: A
Apr 16, 2025

User1 (Cloud-only user): Authenticates directly against Azure AD (no dependency on on-premises infrastructure). Can sign in. User2 (Synced user): Normally authenticates via PTA, which fails due to lost connectivity. Cannot sign in (unless PHS is used as a fallback, but PTA takes precedence here). User3 (Guest user): Authenticates via their home tenant (no dependency on on-premises infrastructure). Can sign in.