MS-102 - Implement and Manage Identity and Access - Section 2.3

Implement and manage hybrid identity using Microsoft Entra Connect and cloud sync.

Compare Microsoft Entra Connect and Entra Cloud Sync as directory synchronisation solutions and select the appropriate one based on topology and supported scenarios. Distinguish password hash sync from pass-through authentication and understand the impact of each on sign-in behaviour.

Microsoft Entra Connectdirectory synchronizationpassword hash syncpass-through authenticationEntra Cloud Sync

Practice question for this objective

Free sampleImplement and Manage Identity and Accesshard

Which scenarios are documented as fitting Microsoft Entra Cloud Sync rather than Microsoft Entra Connect Sync? (Select 3 answers)

  • ASynchronising users from two disconnected Active Directory forests without first building a forest trust. Correct
  • BAn organisation eliminating a single on-premises sync server as the only synchronisation point of failure. Correct
  • CAn organisation that wants provisioning configuration managed in the Microsoft Entra admin center, not on-prem. Correct
  • DAn environment requiring AD FS device writeback to project registered Windows 10 devices into Active Directory.
  • EA 600,000-user directory where the sync engine must point at a remote customer-hosted SQL Server 2022 host.
Cloud Sync wins on disconnected forests, multi-agent HA, and cloud-managed config; Connect Sync still owns device writeback and external SQL. The Cloud Sync overview lists disconnected forest synchronisation, elimination of single points of failure, and cloud-managed configuration as flagship Cloud Sync scenarios. Device writeback and customer-hosted SQL Server remain in Microsoft Entra Connect Sync territory.

Why A is correct: Correct. Synchronising users from two disconnected Active Directory forests without first building a forest trust is one of the keyed answers. The Cloud Sync overview lists disconnected forest synchronisation, elimination of single points of failure, and cloud-managed configuration as flagship Cloud Sync scenarios.

Why B is correct: Correct. An organisation eliminating a single on-premises sync server as the only synchronisation point of failure is one of the keyed answers. The Cloud Sync overview lists disconnected forest synchronisation, elimination of single points of failure, and cloud-managed configuration as flagship Cloud Sync scenarios.

Why C is correct: Correct. An organisation that wants provisioning configuration managed in the Microsoft Entra admin center, not on-prem is one of the keyed answers. The Cloud Sync overview lists disconnected forest synchronisation, elimination of single points of failure, and cloud-managed configuration as flagship Cloud Sync scenarios.

Why D is wrong: Device writeback is a Microsoft Entra Connect Sync feature, not part of Cloud Sync's documented capabilities.

Why E is wrong: External SQL Server is a Microsoft Entra Connect Sync scaling pattern; Cloud Sync stores configuration in the cloud and does not use customer-hosted SQL.

See more MS-102 practice questions, answers explained.

More in this domain

Back to all Implement and Manage Identity and Access objectives, or the MS-102 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.