Entra Registered vs Joined for Personal Device SSO

Add devices to Microsoft Entra ID
Answer Correct answer: A — Use Microsoft Entra registered to enable SSO on personal devices while minimizing organizational control.

Your on-premises network contains an Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You need to enable users to connect to Microsoft 365 services from their personal Windows devices by using single sign-on (SSO). The solution must minimize organizational control of the devices. Which join type should you use?

  1. Microsoft Entra registered Correct Answer
  2. Microsoft Entra joined
  3. Active Directory domain-joined
  4. Microsoft Entra hybrid joined

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is the distinction between device ownership and management levels in Microsoft Entra ID, with the common trap being the selection of 'Joined' which implies full organizational management.

This MD-102 exam question tests the correct Microsoft Entra device join type to enable Single Sign-On (SSO) on personal devices while minimizing organizational control. The solution requires identifying that Microsoft Entra registered is the appropriate choice over joined or hybrid options.

Many learners select 'Microsoft Entra joined' (Option B) because it provides stronger SSO capabilities, but this option violates the requirement to minimize organizational control on personal devices.

Community Discussion (3 comments)

Seek12 👍 6 Selected: A
i would say answer is A
diazed 👍 4 Selected: A
I will go with A Option
8a0766b 👍 1 Selected: A
should that not be registered?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra registered (Option A) is the correct answer because it allows users to access cloud resources like Microsoft 365 via SSO without enrolling the device in Mobile Device Management (MDM). This join type is designed specifically for BYOD scenarios where the organization wants to provide identity-based access without managing the device's security policies or configuration, thus minimizing organizational control.

Why the Other Options Are Wrong

Microsoft Entra joined (Option B) and Active Directory domain-joined (Option C) require the device to be fully managed by the organization, often involving MDM enrollment and strict compliance policies, which contradicts the "minimize control" constraint. Microsoft Entra hybrid joined (Option D) requires an on-premises AD DS environment and Intune/MDM integration, also imposing significant organizational oversight and infrastructure complexity not suitable for a minimal-control personal device scenario.

Community Comment Notes

Community consensus strongly supports Option A, with multiple comments confirming that "registered" is the right choice for personal devices. One user noted "should that not be registered?", highlighting the nuance between registration and joining. Another user simply stated "i would say answer is A", reflecting the general agreement among peers that registration is the key to balancing SSO needs with privacy/control constraints.

Exam Strategy

When dealing with BYOD and SSO questions, always prioritize the level of control required. If the goal is SSO with minimal management, look for 'Registered'. If full management and app deployment are needed, look for 'Joined' or 'Hybrid Joined'.

Frequently Asked Questions

Why not use Microsoft Entra joined for SSO?

Entra joined requires full device management and often MDM enrollment, which violates the requirement to minimize organizational control on personal devices.

What is the main benefit of Entra registered?

It allows users to sign in to Microsoft 365 services using their work credentials (SSO) without the organization having to manage or secure the device itself.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide