SC-300 - Implement and Manage User Identities - Section 1.6

Monitor hybrid identity health and migrate from AD FS to modern authentication.

Use Microsoft Entra Connect Health to monitor synchronisation and federation service reliability and interpret its alerts. Plan migration away from AD FS by using staged rollout to move user groups from federated to cloud authentication, and enable Microsoft Entra Kerberos so modern-credential users keep single sign-on to on-premises resources.

Microsoft Entra Connect HealthAD FS migrationMicrosoft Entra Kerberos for hybridstaged rollout

Practice question for this objective

Free sampleImplement and Manage User Identitiesmedium

An administrator is preparing a staged rollout to migrate federated users to pass-through authentication. Before any user can be added to a staged rollout group, Microsoft Entra Connect must be configured to support the chosen cloud sign-in method. Which prerequisite must the administrator complete first for pass-through authentication staged rollout?

  • AConfigure password writeback in Microsoft Entra Connect, because staged rollout for pass-through authentication requires writeback to be enabled before any group can be added to the rollout.
  • BInstall and enable a pass-through authentication agent through Microsoft Entra Connect, because staged rollout for pass-through authentication needs at least one healthy agent before users can be enrolled. Correct
  • CConvert the contoso.com domain from federated to managed in Microsoft Entra Connect, because staged rollout cannot enrol users while the domain is still federated.
  • DEnable Microsoft Entra Connect Health for synchronisation, because staged rollout for pass-through authentication will not start until Connect Health is monitoring the sync engine.
Pass-through authentication staged rollout requires at least one healthy PTA agent installed through Microsoft Entra Connect before any users can be enrolled in the rollout. Staged rollout for pass-through authentication routes each enrolled user's sign-in to an on-premises agent for password validation, so the feature depends on at least one healthy pass-through authentication agent being installed and enabled via Microsoft Entra Connect. Password writeback, domain conversion, and Connect Health for sync are unrelated to enabling this rollout method.

Why A is wrong: Password writeback supports self-service password reset back to on-premises Active Directory and is not a prerequisite for enabling pass-through authentication staged rollout.

Why B is correct: Pass-through authentication staged rollout validates sign-ins through agents, so at least one healthy agent must be installed and enabled in Microsoft Entra Connect before any user can be added to the rollout.

Why C is wrong: Converting the domain to managed is the final cutover step, not a prerequisite, and staged rollout is specifically designed to run while the domain remains federated.

Why D is wrong: Connect Health provides monitoring and is recommended but is not a hard prerequisite that blocks the enabling of pass-through authentication staged rollout.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Implement and Manage User Identities objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.