Configuring the 'Allow updates to status bar via script' Intranet Zone policy enables Microsoft Entra Seamless SSO via GPO

Answer Correct answer: B — Enable 'Allow updates to status bar via script' in the Local Intranet zone via GPO to roll out Microsoft Entra Seamless SSO.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. You plan to implement single sign-on (SSO) for Azure AD resources. You need to configure an Intranet Zone setting for all users by using a Group Policy Object (GPO). Which setting should you configure?

  1. Logon options
  2. Allow updates to status bar via script Correct Answer
  3. Allow active scripting
  4. Access data sources across domains

Community Votes

B
80%
A
20%

80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Seamless SSO relies on the AZUREADSSOACC computer account and a Kerberos ticket; the GPO step that matters here is the Intranet Zone policy permitting status-bar script updates, not MFA or Conditional Access.

To roll out Microsoft Entra Seamless SSO to all domain-joined users, you deploy a GPO that adds the autologon URL to the Local Intranet zone and enables the 'Allow updates to status bar via script' setting so the browser can update the status bar during silent sign-in.

Candidates confuse 'Logon options' (automatic logon with current credentials) with the specific Seamless SSO rollout policy; the question asks which Intranet Zone setting must be configured, and that is 'Allow updates to status bar via script'.

Community Discussion (8 comments)

ElaineChia 👍 12 Selected: B
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start Refer to this link above. the answer is B as stated in the supported Microsoft site. Did a research to find the actual answer. thanks you. hope it help to the exam taker.
moadabdou 👍 1 Selected: A
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start
golitech 👍 1 Selected: A
❌ B. Allow updates to status bar via script – This is unrelated to authentication or SSO. ❌ C. Allow active scripting – This controls script execution in browsers but is not required for SSO. ❌ D. Access data sources across domains – This controls how cross-domain resources are accessed, which is not related to seamless sign-in.
waqqy 👍 1 Selected: B
To configure single sign-on (SSO) for Azure AD resources using a Group Policy Object (GPO), you should configure the "Allow updates to status bar via script" setting in the Intranet Zone
crutester 👍 3 Selected: B
B is correct. Verified from this link https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start#roll-out-the-feature
xlex 👍 2 Selected: A
Logon options: This setting in the Group Policy Object is used to manage how users are authenticated in the Intranet zone. By configuring this setting, you can enable automatic logon with current username and password. This is a key requirement for seamless SSO as it allows users to access Azure AD resources without repeatedly entering their credentials when they are on the corporate network. The other options are less relevant to SSO configuration.
Yatikumar 👍 1
C. Allow active scripting Allowing active scripting is a common setting for the Intranet Zone to ensure that scripts can run seamlessly within the local network. This is important for various web-based applications and services, especially when implementing single sign-on (SSO) for Azure AD resources.
Vokuhila 👍 1
Answer is C. Allow active scripting

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Seamless SSO lets users sign in silently with their on-premises credentials. The documented GPO rollout adds https://autologon.microsoftazuread-sso.com to the Local Intranet zone and enables the 'Allow updates to status bar via script' policy so the browser can perform the silent token exchange. Without this Intranet Zone setting the status bar cannot be updated during the scripted sign-in and SSO fails. (Option B)

Why the Other Options Are Wrong

  • Option A (Logon options) controls automatic logon with the current username and password but is not the specific Seamless SSO rollout policy the question targets.
  • Option C (Allow active scripting) governs script execution in the browser and is unrelated to the SSO status-bar update.
  • Option D (Access data sources across domains) controls cross-domain data access and has no role in Seamless SSO.

Community Comment Notes

Multiple commenters cited the Microsoft Seamless SSO quick-start and confirmed B, noting that 'Allow active scripting' and 'Access data sources across domains' are unrelated to authentication.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide