Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard
A company is planning to deploy Azure AD Connect. They have an existing on-premises Active Directory forest and want to ensure that user accounts created in Azure AD (cloud-only users) can also be authenticated against their on-premises Active Directory resources. Which Azure AD Connect feature or configuration is required to achieve this bi-directional authentication capability?
- ASeamless single sign-on
- BPass-through authentication
- CPassword writeback
- DPassword hash synchronization
Show answer & explanationAnswer & explanation
Correct answer: C. Password writeback
Password writeback is the Azure AD Connect feature that allows password changes made in Azure AD by cloud-only users to be written back to the on-premises Active Directory. This enables cloud-only users to authenticate against on-premises resources with their Azure AD password.
Why the other options are wrong
- A. Seamless single sign-on provides a smooth login experience for hybrid users but does not manage bi-directional password synchronization.
- B. PTA allows on-premises users to authenticate against on-premises AD via Azure AD, it doesn't enable cloud-only users to authenticate on-premises.
- D. PHS synchronizes hashes from on-premises to Azure AD, not the other way around for cloud-only users.
Password Writeback
An Azure AD Connect feature that allows password changes made in Azure AD (e.g., by cloud-only users or self-service password reset) to be synchronized back to the on-premises Active Directory.
- Crucial for enabling cloud-only users to authenticate against on-premises resources.
- Supports self-service password reset (SSPR) for hybrid users.
- Requires specific permissions for the Azure AD Connect service account in on-premises AD.
Memory trick: For cloud users to unlock 'on-prem doors', their 'cloud key' must be 'written back'.