After synchronizing on-premises identities to Azure AD, you must prevent users whose givenName attribute begins with "LAB" from syncing. Which action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Use the Synchronization Rules Editor to create an attribute-based filtering rule..
Why this is the answer
To prevent specific users from synchronizing based on an attribute like givenName, you must use the Azure AD Connect Synchronization Rules Editor. This tool allows you to create custom inbound or outbound synchronization rules that define filtering criteria. By creating a new inbound rule with a scoping filter that excludes users where givenName starts with "LAB", you can prevent these identities from being provisioned to Azure AD. Configuring DNAT or network traffic filtering rules on a firewall is incorrect because these are network-level controls and have no impact on identity synchronization or attribute-based filtering within Azure AD Connect. Active Directory Users and Computers (ADUC) is an on-premises tool for managing Active Directory objects, but it cannot configure synchronization rules for Azure AD Connect.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed