Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard

A company is planning to deploy Azure AD Connect. They have an existing on-premises Active Directory forest and want to ensure that user accounts created in Azure AD (cloud-only users) can also be authenticated against their on-premises Active Directory resources. Which Azure AD Connect feature or configuration is required to achieve this bi-directional authentication capability?

  1. ASeamless single sign-on
  2. BPass-through authentication
  3. CPassword writeback
  4. DPassword hash synchronization
Show answer & explanation

Correct answer: C. Password writeback

Password writeback is the Azure AD Connect feature that allows password changes made in Azure AD by cloud-only users to be written back to the on-premises Active Directory. This enables cloud-only users to authenticate against on-premises resources with their Azure AD password.

Why the other options are wrong

  • A. Seamless single sign-on provides a smooth login experience for hybrid users but does not manage bi-directional password synchronization.
  • B. PTA allows on-premises users to authenticate against on-premises AD via Azure AD, it doesn't enable cloud-only users to authenticate on-premises.
  • D. PHS synchronizes hashes from on-premises to Azure AD, not the other way around for cloud-only users.

Password Writeback

An Azure AD Connect feature that allows password changes made in Azure AD (e.g., by cloud-only users or self-service password reset) to be synchronized back to the on-premises Active Directory.

  • Crucial for enabling cloud-only users to authenticate against on-premises resources.
  • Supports self-service password reset (SSPR) for hybrid users.
  • Requires specific permissions for the Azure AD Connect service account in on-premises AD.

Memory trick: For cloud users to unlock 'on-prem doors', their 'cloud key' must be 'written back'.

More Implement and manage hybrid identities questions