Entra Registered vs Joined for Personal Device SSO
Your on-premises network contains an Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You need to enable users to connect to Microsoft 365 services from their personal Windows devices by using single sign-on (SSO). The solution must minimize organizational control of the devices. Which join type should you use?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is the distinction between device ownership and management levels in Microsoft Entra ID, with the common trap being the selection of 'Joined' which implies full organizational management.
This MD-102 exam question tests the correct Microsoft Entra device join type to enable Single Sign-On (SSO) on personal devices while minimizing organizational control. The solution requires identifying that Microsoft Entra registered is the appropriate choice over joined or hybrid options.
Many learners select 'Microsoft Entra joined' (Option B) because it provides stronger SSO capabilities, but this option violates the requirement to minimize organizational control on personal devices.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra registered (Option A) is the correct answer because it allows users to access cloud resources like Microsoft 365 via SSO without enrolling the device in Mobile Device Management (MDM). This join type is designed specifically for BYOD scenarios where the organization wants to provide identity-based access without managing the device's security policies or configuration, thus minimizing organizational control.Why the Other Options Are Wrong
Microsoft Entra joined (Option B) and Active Directory domain-joined (Option C) require the device to be fully managed by the organization, often involving MDM enrollment and strict compliance policies, which contradicts the "minimize control" constraint. Microsoft Entra hybrid joined (Option D) requires an on-premises AD DS environment and Intune/MDM integration, also imposing significant organizational oversight and infrastructure complexity not suitable for a minimal-control personal device scenario.Community Comment Notes
Community consensus strongly supports Option A, with multiple comments confirming that "registered" is the right choice for personal devices. One user noted "should that not be registered?", highlighting the nuance between registration and joining. Another user simply stated "i would say answer is A", reflecting the general agreement among peers that registration is the key to balancing SSO needs with privacy/control constraints.Exam Strategy
When dealing with BYOD and SSO questions, always prioritize the level of control required. If the goal is SSO with minimal management, look for 'Registered'. If full management and app deployment are needed, look for 'Joined' or 'Hybrid Joined'.
Frequently Asked Questions
Why not use Microsoft Entra joined for SSO?
Entra joined requires full device management and often MDM enrollment, which violates the requirement to minimize organizational control on personal devices.
What is the main benefit of Entra registered?
It allows users to sign in to Microsoft 365 services using their work credentials (SSO) without the organization having to manage or secure the device itself.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →