ms-100-14

Ace your homework & exams now with Quizwiz!

user1 cannot change password from any portal if the pw for user1 is changed in active directory, the pw will be synced to azure AD.

Your company has a hybrid deployment of Microsoft 365.An on-premises user named User1 is synced to Microsoft Azure Active Directory (Azure AD). Azure AD Connect is configured as shown in the following exhibit.

B. From the Exchange admin center, click mail flow, and then configure the email address policies. D. From Microsoft Exchange Online PowerShell, run the Set-EmailAddressPolicy policy command.

)Your company has a Microsoft 365 subscription. All identities are managed in the cloud. The company purchases a new domain name. You need to ensure that all new mailboxes use the new domain as their primary email address. What are two possible ways to achieve the goal? A. From Microsoft Exchange Online PowerShell, run the Update-EmailAddressPolicy policy command. B. From the Exchange admin center, click mail flow, and then configure the email address policies. C. From the Microsoft 365 admin center, click Setup, and then configure the domains. D. From Microsoft Exchange Online PowerShell, run the Set-EmailAddressPolicy policy command. E. From the Azure Active Directory admin center, configure the custom domain names. Answer: BD

D. a new service connection point (SCP) for each forest

)Your network contains two Active Directory forests. Each forest contains two domains. All client computers run Windows 10 and are domain-joined. You plan to configure Hybrid Azure AD join for the computers. You create Microsoft Azure Active Directory (Azure AD) tenant. You need to ensure that the computers can discover the Azure AD tenant. What should you create? A. a new computer account for each computer B. a new service connection point (SCP) for each domain C. a new trust relationship for each forest D. a new service connection point (SCP) for each forest

C. Modify the External collaboration settings.

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. An external user has a Microsoft account that uses an email address of [email protected]. An administrator named Admin1 attempts to create a user account for the external user and receives the error message shown in the following exhibit. You do not have permission to invite external users. You need to ensure that Admin1 can add the user. What should you do from the Azure Active Directory admin center? A. Add a custom domain name named outlook.com. B. Modify the Authentication methods. C. Modify the External collaboration settings. D. Assign Admin1 the Security administrator role

No

Your company has a main office and three branch offices. All the branch offices connect to the main office by using a WAN link. The main office has a high-speed Internet connection. All the branch offices connect to the Internet by using the main office connection. Users use Microsoft Outlook 2016 to connect to 4 Microsoft Exchange Server mailbox hosted in the main office. The users report that when the WAN link in their office becomes unavailable, they cannot access their mailbox. You create a Microsoft 365 subscription, and then migrate all the user data to Microsoft 365. You need to ensure that all the users can continue to use Outlook to receive email messages if a WAN link fails. Solution: You deploy a site-to-site VPN from each branch office to Microsoft Azure. Does this meet the goal?

A. cutover migration

Your company has an on-premises Microsoft Exchange Server 2013 organization. The company has 100 users. The company purchases Microsoft 365 and plans to move its entire.- infrastructure to the cloud. The company does NOT plan to sync the on-premises Active Directory domain to Microsoft Azure Active Directory (Azure AD).You need to recommend which type of migration to use to move all email messages, contacts, and calendar items to Exchange Online. What should you recommend? A. cutover migration B. IMAP migration C. remote move migration D. staged migration

C. Purchase a custom domain name.

Your network contains an Active Directory forest named contoso.local. You purchase a Microsoft 365 subscription. You plan to move to Microsoft and to implement a hybrid deployment solution for the next 12 months. You need to prepare for the planned move to Microsoft 365.What is the best action to perform before you implement directory synchronization? More than one answer choice may achieve the goal. Select the BEST answer. A. Purchase a third-party X.509 certificate. B. Rename the Active Directory forest. C. Purchase a custom domain name. D. Create an external forest trust

A. From Windows PowerShell, run the Convert-MsolDomaintoFederated-DomainName contoso.com -SupportMultipleDomain command. E. From the federation server, remove the Microsoft Office 365 relying party trust.

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and adatum.com. Your company recently purchased a Microsoft 365 subscription. You deploy a federated identity solution to the environment. You use the following command to configure contoso.com for federation: Convert-MsolDomaintoFederated -DomainName contoso.com In the Microsoft 365 tenant, an administrator adds and verifies the adatum.com domain name. You need to configure the adatum.com Active Directory domain for federated authentication. Which two actions should you perform before you run the Azure AD Connect wizard? A. From Windows PowerShell, run the Convert-MsolDomaintoFederated-DomainName contoso.com -SupportMultipleDomain command. B. From Windows PowerShell, run the New-MsolFederatedDomain-SupportMultipleDomain -DomainName contoso.com command. C. From Windows PowerShell, run the New-MsolFederatedDomain-DomainName adatum.com command. D. From Windows PowerShell, run the Update-MSOLFederatedDomain-DomainName contoso.com -SupportMultipleDomain command. E. From the federation server, remove the Microsoft Office 365 relying party trust.

A. From a domain controller, install the Azure AD Password Protection Proxy. C. From Custom banned passwords, modify the Enforce custom list setting. E. From all the domain controllers, install the Azure AD Password Protection DC Agent.

Your network contains an on-premises Active Directory domain. You have a Microsoft 365 subscription. You implement a directory synchronization solution that uses pass-through authentication. You configure Microsoft Azure Active Directory (Azure AD) smart lockout as shown in the following exhibit. You discover that Active Directory users can use the passwords in the custom banned passwords list. You need to ensure that banned passwords are effective fo rall users. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point. A. From a domain controller, install the Azure AD Password Protection Proxy. B. From a domain controller, install the Microsoft AAD Application Proxy connector. C. From Custom banned passwords, modify the Enforce custom list setting. D. From Password protection for Windows Server Active Directory, modify the Mode setting. E. From all the domain controllers, install the Azure AD Password Protection DC Agent. F. From Active Directory, modify the Default Domain Policy.


Related study sets

MGT-332-Exam #1: Modules 1-5 (Chapters 1, 3-6)

View Set

Database Management I: Section 4-6 Test

View Set

Chapter 32: Labor and Birth Complications

View Set

Accident and health insurance Basics questions

View Set

chapter 13 peripheral nervous system and reflex activity

View Set

Exponential And Logarithmic Functions

View Set