Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A multinational corporation with a complex on-premises Active Directory infrastructure needs to consolidate its identity management. They want to synchronize users, groups, and contacts from multiple on-premises AD forests, some with non-routable UPN suffixes, into a single Microsoft Entra ID tenant while maintaining a single user identity across both environments. Which component of Microsoft Entra Connect is specifically designed to handle this complexity?
- AMicrosoft Entra Pass-through Authentication
- BMicrosoft Entra Connect Health
- CMicrosoft Entra Connect Cloud Sync
- DMicrosoft Entra Connect Sync
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Entra Connect Sync
Microsoft Entra Connect Sync (often referred to simply as Microsoft Entra Connect) is the on-premises robust synchronization engine designed for complex hybrid environments, including multiple AD forests, custom attribute flows, and handling non-routable UPN suffixes to create a single identity in Microsoft Entra ID.
Why the other options are wrong
- A. Pass-through Authentication is an authentication method, not a synchronization component.
- B. Connect Health monitors the health of sync services, it doesn't perform the sync.
- C. Cloud Sync is a lightweight agent for simple single-forest to single-tenant synchronization, not designed for complex multi-forest scenarios with UPN suffix challenges.
Microsoft Entra Connect Sync
The core synchronization service within Microsoft Entra Connect that manages the flow of identity data between on-premises Active Directory and Microsoft Entra ID.
- Handles complex multi-forest Active Directory topologies
- Supports advanced attribute filtering, transformations, and custom rules
- Manages identity object lifecycle including users, groups, and contacts
Memory trick: Connect Sync unifies your tangled forests into one cloud identity.