The domain uses Microsoft Entra Connect sync and Entra Password Protection with a custom banned password list. After deploying a new domain controller (DC2), the custom banned list is enforced inconsistently. To ensure the banned-password list is always enforced on DC2, what should you install on DC2?
Choose an answer
Tap an option to check your answer.
Correct answer: Install the Microsoft Entra Password Protection DC agent..
Why this is the answer
To ensure consistent enforcement of Microsoft Entra Password Protection's custom banned password list on a new domain controller (DC2), you must install the Microsoft Entra Password Protection DC agent directly on DC2. This agent is responsible for intercepting password changes on the domain controller and validating them against the banned password list synchronized from Microsoft Entra ID. Without the DC agent, the new domain controller cannot enforce the custom list. Installing the Microsoft Entra Password Protection proxy service is incorrect because the proxy service is used for on-premises password hash synchronization and communication with Microsoft Entra ID, not for enforcing password policies on individual DCs. Providing access to Microsoft Entra URLs is necessary for the overall functionality but doesn't install the enforcement mechanism. The Microsoft Entra provisioning agent is used for HR-driven provisioning or application provisioning, not password protection. The Azure Monitor Agent is for collecting monitoring data, unrelated to password enforcement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed