Your organization synchronizes a single on-premises Active Directory forest to Microsoft Entra ID using Azure AD Connect. You want users to be able to reset their passwords in the cloud and have those changes written back to on-premises AD. You also plan to use AD FS device authentication to enable device-based access control for on-premises web apps. Which two Azure AD Connect optional features should you enable? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Password writeback, Device writeback.
Why this is the answer
Password writeback is essential for users to reset their passwords in the cloud (Microsoft Entra ID) and have those changes reflected in the on-premises Active Directory. Without it, password changes made in the cloud would not synchronize back to on-premises AD, leading to authentication issues for on-premises resources. Device writeback is required to enable AD FS device authentication. This feature writes device objects from Microsoft Entra ID back to on-premises Active Directory, allowing AD FS to leverage these objects for device-based access control. Group writeback is for writing Microsoft 365 groups back to on-premises AD, which is not a requirement here. Pass-through authentication is an authentication method, not a feature for writing changes back to on-premises AD. Directory extension attribute sync is for synchronizing custom attributes, not for password or device writeback.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed