Microsoft Entra Joined vs Hybrid Join for MD-102

Add devices to Microsoft Entra ID
Answer Correct answer: C — Use Microsoft Entra joined to manage device identity in the cloud while enabling SSO to on-premises resources.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to contoso.com. The solution must meet the following requirements: • Ensure that from the devices, users can access shares on an on-premises file server without being prompted for credentials. • Minimize reliance on the on-premises infrastructure for device identity management. Which join type should you use?

  1. Active Directory domain-joined
  2. Microsoft Entra hybrid joined
  3. Microsoft Entra joined Correct Answer
  4. Microsoft Entra registered

Community Votes

C
83%
B
17%

83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the trade-off between full cloud identity autonomy and legacy on-premises integration, with the common trap being the assumption that hybrid join is required for any on-premises resource access.

This page explains why Microsoft Entra joined is the correct join type to minimize on-premises reliance while maintaining single sign-on access to file shares. It clarifies the distinction between identity management models and authentication capabilities in a hybrid environment.

Many candidates choose Microsoft Entra hybrid joined (B) because they associate it with Kerberos/SSO for on-premises resources, failing to recognize that modern Entra ID can achieve this via Azure AD SSO without managing device identities on-premises.

Community Discussion (3 comments)

Knight_Of_Peace 👍 3 Selected: C
According to the following link, Entra joined devices can access on-prem with SSO. "With a Microsoft Entra joined device, your users already have an SSO experience to the cloud apps in your environment. If your environment has Microsoft Entra ID and on-premises AD DS, you might want to expand the scope of your SSO experience to your on-premises Line Of Business (LOB) apps, file shares, and printers." Ref: https://learn.microsoft.com/en-us/entra/identity/devices/device-sso-to-on-premises-resources#:~:text=With%20a%20Microsoft,shares%2C%20and%20printers.
f7d2595 👍 2 Selected: C
The question is very specific about the need to "Minimize reliance on the on-premises infrastructure for device identity management". Entra ID joined devices can access onprem resource with no problem and no prompts for credentials.
GamingFuntime1985 👍 1 Selected: B
B. From ChatGPT. I did not get anything else. Use Microsoft Entra hybrid joined to achieve: Seamless on-premises resource access via Kerberos authentication. A step toward reducing reliance on on-premises infrastructure by leveraging Microsoft Entra ID for cloud-based identity management.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra joined (C) is the correct choice because it fully decouples device identity management from the on-premises Active Directory infrastructure, satisfying the requirement to 'minimize reliance on the on-premises infrastructure.' While traditionally associated with cloud-only resources, Microsoft Entra joined devices can access on-premises file shares using Single Sign-On (SSO) via the Azure AD SSO feature or Kerberos Constrained Delegation if configured, without requiring the device itself to be managed by on-premises AD DS.

Why the Other Options Are Wrong

Active Directory domain-joined (A) requires full management by on-premises AD, violating the minimization constraint. Microsoft Entra hybrid joined (B) registers the device identity in both cloud and on-premises AD, which increases reliance on on-premises infrastructure rather than minimizing it. Microsoft Entra registered (D) is intended for personal/BYOD devices and does not provide the seamless enterprise SSO experience required for accessing shared resources without prompts.

Community Comment Notes

Community consensus strongly supports option C, noting that Entra joined devices support SSO to on-premises LOB apps and file shares when the environment has both Entra ID and AD DS. One commenter emphasized that the key phrase 'minimize reliance' points directly to the pure cloud identity model of Entra joined over hybrid. Another user referenced official documentation confirming that Entra joined expands the SSO experience to on-premises resources.

Exam Strategy

Focus on the specific wording of requirements: if the goal is to reduce on-premises dependency, avoid Hybrid Join. If the goal is pure cloud identity management, select Entra Joined, even if on-premises resources are mentioned, as modern features bridge this gap.

Frequently Asked Questions

Can Entra joined devices access on-premises file shares?

Yes, they can use Azure AD SSO or Kerberos delegation to access shares without credential prompts.

Why not use Hybrid Join for on-premises access?

Hybrid Join increases on-premises reliance by syncing device objects to AD DS, contradicting the requirement.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide