An on-premises AD DS domain hosts Server1, which runs an app (App1) that uses Active Directory authentication. You configured Microsoft Entra Connect with password sync, and a Microsoft Entra user named User1 cannot authenticate to App1. What must you do to allow User1 to authenticate to App1?
Choose an answer
Tap an option to check your answer.
Correct answer: In the AD DS domain, create a new user account named User1..
Why this is the answer
The correct answer is to create a new user account named User1 in the AD DS domain. App1 uses Active Directory authentication, meaning it authenticates directly against the on-premises AD DS. If User1 is a Microsoft Entra user and does not have a corresponding account in the on-premises AD DS, App1 cannot authenticate them. Microsoft Entra Connect with password sync only synchronizes passwords from on-premises AD DS to Microsoft Entra ID; it does not create on-premises AD DS accounts for cloud-only Microsoft Entra users. Enabling BlockCloudObjectTakeoverThroughHardMatch is for preventing accidental identity mismatches during synchronization, not for creating new on-premises accounts. Enabling password writeback allows users to change their Microsoft Entra password and have it written back to on-premises AD DS, but it doesn't create the initial on-premises account. Disabling soft match is related to how objects are matched during synchronization, not to the creation of new on-premises user accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed