An on-premises AD domain syncs to Azure AD using password hash synchronization. Devices are hybrid Azure AD–joined, but users must repeatedly type their password to access Microsoft 365. What should you enable to reduce password prompts?
Choose an answer
Tap an option to check your answer.
Correct answer: From Azure AD Connect, enable single sign-on (SSO)..
Why this is the answer
Enabling single sign-on (SSO) from Azure AD Connect is the correct solution. This allows users to seamlessly access Microsoft 365 services without re-entering their credentials after signing into their domain-joined devices. Azure AD Connect offers two SSO methods: Password Hash Synchronization (PHS) SSO and Pass-through Authentication (PTA) SSO. Since the environment already uses PHS, enabling SSO will integrate with this existing synchronization method. Configuring a Conditional Access policy would control access based on conditions but wouldn't eliminate password prompts for legitimate access. Creating an autodiscover record in DNS is relevant for Exchange services but doesn't address general Microsoft 365 SSO. Configuring pass-through authentication would change the primary authentication method from PHS, which is not necessary to achieve SSO in this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed