1. Microsoft Entra ID Documentation. (2023). What is Microsoft Entra Connect cloud sync? Microsoft Learn. Retrieved from https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/what-is-cloud-sync.
Reference Details: Under the "Key benefits" section
it states
"Synchronize users in specific OUs: You can configure cloud sync to synchronize specific OUs. This allows you to synchronize only the users you need." This directly supports the use of cloud sync for OU-scoped synchronization.
2. Microsoft Entra ID Documentation. (2023). Microsoft Entra Connect: Staging server and disaster recovery. Microsoft Learn. Retrieved from https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-staging-server.
Reference Details: The "Staging mode" section clarifies
"A server in staging mode...does not write anything back to these connected directories. It is in a read-only state when it comes to writing." This confirms why option C is incorrect.
3. Microsoft Entra ID Documentation. (2023). What is federation with Microsoft Entra ID? Microsoft Learn. Retrieved from https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-fed.
Reference Details: This document explains that federation is an authentication option
stating
"With federation
you can enable users to access Microsoft Entra ID-based services with their on-premises passwords." It does not provision the user objects themselves
which is the primary step needed. This supports why option B is incorrect.