SC-300 - Implement and Manage User Identities (25% of the exam) - Section 1.6

Monitor hybrid identity health and migrate from AD FS to modern authentication.

Use Microsoft Entra Connect Health to monitor synchronisation and federation service reliability and interpret its alerts. Plan migration away from AD FS by using staged rollout to move user groups from federated to cloud authentication, and enable Microsoft Entra Kerberos so modern-credential users keep single sign-on to on-premises resources.

Microsoft Entra Connect HealthAD FS migrationMicrosoft Entra Kerberos for hybridstaged rollout

Practice question for this objective

Free sampleImplement and Manage User Identitiesmedium

An administrator is preparing a staged rollout to migrate federated users to pass-through authentication. Before any user can be added to a staged rollout group, Microsoft Entra Connect must be configured to support the chosen cloud sign-in method. Which prerequisite must the administrator complete first for pass-through authentication staged rollout?

  • AConfigure password writeback in Microsoft Entra Connect, because staged rollout for pass-through authentication requires writeback to be enabled before any group can be added to the rollout.
  • BInstall and enable a pass-through authentication agent through Microsoft Entra Connect, because staged rollout for pass-through authentication needs at least one healthy agent before users can be enrolled. Correct
  • CConvert the contoso.com domain from federated to managed in Microsoft Entra Connect, because staged rollout cannot enrol users while the domain is still federated.
  • DEnable Microsoft Entra Connect Health for synchronisation, because staged rollout for pass-through authentication will not start until Connect Health is monitoring the sync engine.
Pass-through authentication staged rollout requires at least one healthy PTA agent installed through Microsoft Entra Connect before any users can be enrolled in the rollout. Staged rollout for pass-through authentication routes each enrolled user's sign-in to an on-premises agent for password validation, so the feature depends on at least one healthy pass-through authentication agent being installed and enabled via Microsoft Entra Connect. Password writeback, domain conversion, and Connect Health for sync are unrelated to enabling this rollout method.

Why A is wrong: Password writeback supports self-service password reset back to on-premises Active Directory and is not a prerequisite for enabling pass-through authentication staged rollout.

Why B is correct: Pass-through authentication staged rollout validates sign-ins through agents, so at least one healthy agent must be installed and enabled in Microsoft Entra Connect before any user can be added to the rollout.

Why C is wrong: Converting the domain to managed is the final cutover step, not a prerequisite, and staged rollout is specifically designed to run while the domain remains federated.

Why D is wrong: Connect Health provides monitoring and is recommended but is not a hard prerequisite that blocks the enabling of pass-through authentication staged rollout.

See more SC-300 practice questions, answers explained.

Exam traps in Implement and Manage User Identities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • Configure seamless single sign-on, because it issues Kerberos tickets for on-premises file shares to users who authenticated with FIDO2 security keys.

    Why it is wrong: Seamless single sign-on issues Kerberos tickets for the Microsoft Entra cloud service on domain-joined devices; it does not grant on-premises resource access for FIDO2 sign-ins.

  • Pass-through authentication agents installed near the storage account, which validate each user's password against on-premises Active Directory before granting access to the Azure Files share.

    Why it is wrong: Pass-through authentication validates interactive sign-in passwords against on-premises Active Directory and does not issue Kerberos tickets for mounting an Azure Files share.

  • Convert the domain from federated to managed in a single cutover, because converting the entire domain is the only supported way to begin cloud authentication for any user.

    Why it is wrong: A full domain conversion switches every user at once, which contradicts the requirement to validate cloud sign-in for a small pilot group before changing the whole domain.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.