How to Modify city Attribute for AD-Synced Entra Users?

Implement and manage identity synchronization with Microsoft Entra tenant
Answer Correct answer: A — Modify the on-premises Active Directory city attribute with Set-ADUser, because synced Entra users are mastered in adatum.com.

Your network contains an Active Directory domain named adatum.com that is synced to a Microsoft Entra tenant. The domain contains 100 user accounts. The city attribute for all the users is set to the city where the user resides. You need to modify the value of the city attribute to the three-letter airport code of each city. What should you do?

  1. From Windows PowerShell on a domain controller, run the Get-ADUser and Set-ADUser cmdlets. Correct Answer
  2. From Azure Cloud Shell, run the Get-MgUser and Update-MgUser cmdlets.
  3. From the Microsoft Entra admin center, select all the Microsoft Entra users, and then use the User settings blade.
  4. From the Microsoft 365 admin center, select the users, and then use the Bulk actions option.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests source-of-authority rules for synced attributes; the trap is trying to edit the value in Entra or Microsoft 365 portals, where synced attributes are read-only and overwritten by directory synchronization.

When Active Directory users are synced to Microsoft Entra, the on-premises AD object is the source of authority for attributes like city. This page confirms the city attribute must be changed with Set-ADUser on-premises, not through Entra or Microsoft 365 admin portals.

Selecting Azure Cloud Shell with Get-MgUser and Update-MgUser, because learners assume any Entra user attribute can be edited in the cloud, but synced values are mastered in on-premises AD.

Community Discussion (3 comments)

Khattak3143 👍 5 Selected: A
A final answer! It is because the user was synced from on-premise domain, we need to modify the user attribute at on-premise domain.
TonyManero 👍 1 Selected: A
Sync from onprem, so you have to modify from onprem.
examcrammer 👍 3 Selected: A
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because adatum.com is synced to Microsoft Entra, so each user object's source of authority remains the on-premises Active Directory domain. Changing the city attribute to a three-letter airport code therefore requires an AD DS write operation, and Set-ADUser is the cmdlet designed for that task. Get-ADUser retrieves the target objects, and Set-ADUser updates the city property for all 100 users. Running this from Windows PowerShell on a domain controller guarantees the Active Directory module is available and that the write occurs in the authoritative directory.

Why the Other Options Are Wrong

Option B is wrong because Update-MgUser against a synced user cannot permanently modify attributes mastered on-premises; the next synchronization cycle would overwrite the cloud value. Option C is wrong because the Microsoft Entra admin center User settings blade does not provide a bulk edit for the city attribute, and even if it did, the change would not be authoritative for synced users. Option D is wrong because Microsoft 365 admin center bulk actions manage cloud-side service attributes, not the on-premises city attribute that syncs into Entra. Only an on-premises AD DS modification propagates correctly to Entra.

Community Comment Notes

All learner votes and comments align with option A. Khattak3143 explained that the user was synced from the on-premises domain and concluded "we need to modify the user attribute at on-premise domain", while TonyManero summarized the rule as "Sync from onprem, so you have to modify from onprem." Another learner, examcrammer, simply marked the answer as correct. No commenter defended editing the city value from Entra or Microsoft 365, which reinforces the source-of-authority principle tested here.

Official Reference

Exam Strategy

Identify the source of authority before choosing an administration tool: if an object is synced from AD DS, changes to synchronized attributes must be made on-premises. Option A explicitly runs on a domain controller, which ensures the Active Directory PowerShell module is present and the write reaches the authoritative directory.

Frequently Asked Questions

Why can't I change city for synced users in the Microsoft Entra admin center?

Synced users are mastered on-premises, so Entra attributes such as city are read-only in the cloud and any direct change is overwritten by the next synchronization cycle.

Does Set-ADUser need to run on a domain controller?

No, but the Active Directory PowerShell module must be installed. Option A's domain controller wording is still valid because only on-premises AD is authoritative for the synced city attribute.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide