You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra ID tenant by using password hash synchronization. You have a Microsoft 365 subscription. All devices are hybrid Microsoft Entra joined. Users report that they must enter their password manually when accessing Microsoft 365 applications. You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services. What should you do?
Correct Answer: C
Enabling Seamless Single Sign-On (SSO) in Microsoft Entra Connect, used alongside password hash synchronization, lets domain-joined users be automatically signed in when they access cloud apps from a corporate network or from a hybrid Microsoft Entra joined device, without repeatedly being prompted to re- enter credentials, because authentication is transparently completed using the device ' s existing Kerberos ticket against a Microsoft Entra service principal (AZUREADSSOACC) rather than requiring the user to type a password. A Conditional Access policy for the Microsoft 365 applications governs whether and under what conditions access is granted (device compliance, location, MFA requirements) but does not itself reduce password prompts. Creating an autodiscover DNS record only affects how Outlook and Exchange clients locate their mail server endpoint and has no bearing on Microsoft 365/Azure sign-in prompting. Configuring pass-through authentication is an alternative authentication method to password hash synchronization, not a single sign-on mechanism, and switching to it alone would not reduce repeated prompting. Therefore, enabling Seamless SSO in Microsoft Entra Connect is the correct action.
AZ-802 Exam Question 202
You have three servers named Server1, Server2, and Server3 that run Windows Server and have the Hyper-V server role installed. Server1 hosts an Azure Migrate appliance named Migrate1. You plan to migrate virtual machines to Azure. You need to ensure that any new virtual machines created on Server1, Server2, and Server3 are available in Azure Migrate. What should you do?
Correct Answer: A
The Azure Migrate appliance only continuously discovers the specific hosts and clusters that have been explicitly registered with it as discovery sources through the appliance ' s own configuration manager; it does not automatically expand its discovery scope to cover additional Hyper-V hosts on the network just because they exist. Migrate1 is currently hosted on Server1, but for virtual machines created on Server2 and Server3 to also show up and be tracked in Azure Migrate alongside those on Server1, an administrator must explicitly add Server2 and Server3, or their respective Hyper-V hosts, as additional discovery sources on Migrate1, which causes the appliance to begin enumerating and continuously tracking their virtual machine inventory as well. Creating a GlobalName zone on the DNS server, setting the Computer Browser service ' s startup type to Automatic, and deploying a WINS server are all legacy NetBIOS name-resolution mechanisms from an earlier era of Windows networking, and none of them has any role whatsoever in how the Azure Migrate appliance discovers hosts or virtual machines. Therefore, adding a discovery source on Migrate1 is the correct action to take.
AZ-802 Exam Question 203
You have five Azure virtual machines. You have a dedicated Azure Storage account to collect performance data. You need to send the collected data directly to the Azure Storage account. What should you install on the virtual machines?
Correct Answer: D
Sending collected performance data directly to a dedicated Azure Storage account is a specific capability of the Azure Diagnostics extension, often abbreviated WAD, which can be configured to write performance counter data and event log data straight into tables and blobs inside a specified storage account with no intermediate monitoring service required at all. The Azure Monitor Agent, by contrast, ships the data it collects through Data Collection Rules only to destinations such as a Log Analytics workspace, Azure Monitor Metrics, Azure Data Explorer, or Microsoft Fabric; it has no data flow destination that targets a general-purpose Azure Storage account directly, so it cannot satisfy this exact requirement even though it is the newer, more broadly capable agent overall. The Dependency agent exists to map process-level dependencies for VM insights rather than to collect performance counters, the Telegraf agent is used specifically to feed Linux VM metrics into Azure Monitor Metrics, and the Azure Connected Machine agent exists purely to onboard non-Azure servers to Azure Arc; none of those three routes performance data into Azure Storage at all. Therefore, installing the Azure Diagnostics extension on the five virtual machines is the correct action.
AZ-802 Exam Question 204
You have an Azure Automation account named AA1 in a resource group named RG1. You have an Azure Are-enabled server named Server! that runs Windows Server and is in a resource group named RG2. You have a User Hybrid Runbook Worker group named Group1. Server! is registered as a worker in Group1. You store the service URL required by the Hybrid Runbook Worker extension for AA1 in a variable named Jconnectionvalue. You need to install the Hybrid Worker extension on Server1. How should you complete the PowerShell script? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation: Settings key: AutomationAccountURL. Cmdlet: New-AzConnectedMachineExtension. Microsoft ' s documented method for installing the extension-based Hybrid Runbook Worker on a server requires the $settings hashtable passed to the extension to use the exact key AutomationAccountURL, mapped to the automation account ' s hybrid service URL, regardless of whether the target is a native Azure VM or an Arc-enabled server; AutomationAccountName, AutomationHybridServiceURL, and RegistrationUrl are not the key the extension ' s installer actually reads and would cause the extension to fail to register the worker correctly. The choice of cmdlet depends on what kind of Azure resource the target machine is: Server1 is described as an Azure Arc-enabled server, meaning it is represented in Azure Resource Manager as a Microsoft.HybridCompute/machines resource rather than a Microsoft.Compute/virtualMachines resource, and only New-AzConnectedMachineExtension, the cmdlet specifically designed to install VM extensions onto Arc-enabled (hybrid/on-premises) machines, can target that resource type; Set- AzVMExtension is used for native Azure VMs and would fail against an Arc machine resource, and Set- AzConnectedMachine and New-AzAutomationHybridRunbookWorker are unrelated cmdlets that respectively update general Arc machine properties and register a runbook worker group membership rather than deploy the VM extension itself. The combination of the AutomationAccountURL settings key with New- AzConnectedMachineExtension correctly installs and registers the Hybrid Worker extension on the Arc- enabled Server1.
AZ-802 Exam Question 205
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation: Statement 1: No. Statement 2: Yes. Statement 3: No. Password-policy (Account Policy) settings inside a GPO behave differently depending on where the GPO is linked. For domain user accounts, only Account Policy settings defined in a GPO linked at the domain level (or in a fine-grained Password Settings Object) take effect; Account Policy settings in a GPO linked to an OU are ignored for domain accounts and instead apply only to the local SAM password policy of computer objects located in that OU. GPO1 (minimum length 14) is linked to OU1, where Admin1 ' s user object resides, but because it is linked to an OU rather than the domain, it has no effect on Admin1 ' s domain account password requirement. Admin1 ' s domain password is governed only by the Default Domain Policy (minimum length 10), so statement 1 is false. User1 is likewise a domain account subject only to the Default Domain Policy ' s minimum length of 10, so statement 2 is true. GPO2 (minimum length 8) is linked to the Member Servers OU, which contains Server1 as a computer object; this makes GPO2 the effective local password policy for local accounts created on Server1 (overriding the Default Domain Policy locally), not the domain policy ' s 10-character minimum. Therefore a new local account on Server1 needs only eight characters, not ten, making statement 3 false.