Microsoft Entra Joined vs Hybrid Join for MD-102
Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named contoso.com. You need to deploy 100 Windows 11 devices to contoso.com. The solution must meet the following requirements: • Ensure that from the devices, users can access shares on an on-premises file server without being prompted for credentials. • Minimize reliance on the on-premises infrastructure for device identity management. Which join type should you use?
Community Votes
83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the trade-off between full cloud identity autonomy and legacy on-premises integration, with the common trap being the assumption that hybrid join is required for any on-premises resource access.
This page explains why Microsoft Entra joined is the correct join type to minimize on-premises reliance while maintaining single sign-on access to file shares. It clarifies the distinction between identity management models and authentication capabilities in a hybrid environment.
Many candidates choose Microsoft Entra hybrid joined (B) because they associate it with Kerberos/SSO for on-premises resources, failing to recognize that modern Entra ID can achieve this via Azure AD SSO without managing device identities on-premises.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra joined (C) is the correct choice because it fully decouples device identity management from the on-premises Active Directory infrastructure, satisfying the requirement to 'minimize reliance on the on-premises infrastructure.' While traditionally associated with cloud-only resources, Microsoft Entra joined devices can access on-premises file shares using Single Sign-On (SSO) via the Azure AD SSO feature or Kerberos Constrained Delegation if configured, without requiring the device itself to be managed by on-premises AD DS.Why the Other Options Are Wrong
Active Directory domain-joined (A) requires full management by on-premises AD, violating the minimization constraint. Microsoft Entra hybrid joined (B) registers the device identity in both cloud and on-premises AD, which increases reliance on on-premises infrastructure rather than minimizing it. Microsoft Entra registered (D) is intended for personal/BYOD devices and does not provide the seamless enterprise SSO experience required for accessing shared resources without prompts.Community Comment Notes
Community consensus strongly supports option C, noting that Entra joined devices support SSO to on-premises LOB apps and file shares when the environment has both Entra ID and AD DS. One commenter emphasized that the key phrase 'minimize reliance' points directly to the pure cloud identity model of Entra joined over hybrid. Another user referenced official documentation confirming that Entra joined expands the SSO experience to on-premises resources.Exam Strategy
Focus on the specific wording of requirements: if the goal is to reduce on-premises dependency, avoid Hybrid Join. If the goal is pure cloud identity management, select Entra Joined, even if on-premises resources are mentioned, as modern features bridge this gap.
Frequently Asked Questions
Can Entra joined devices access on-premises file shares?
Yes, they can use Azure AD SSO or Kerberos delegation to access shares without credential prompts.
Why not use Hybrid Join for on-premises access?
Hybrid Join increases on-premises reliance by syncing device objects to AD DS, contradicting the requirement.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →