Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium
A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They have a strict security policy that prohibits inbound connections from Azure to their on-premises network. Which authentication method should they choose to ensure that users can authenticate against their on-premises Active Directory without allowing inbound connections from Azure?
- APassword hash synchronization (PHS)
- BCloud authentication with Azure AD
- CFederation with Azure AD (AD FS)
- DPass-through authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: D. Pass-through authentication (PTA)
Pass-through authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory without requiring inbound connections from Azure. It uses lightweight agents installed on-premises to handle authentication requests.
Why the other options are wrong
- A. PHS synchronizes password hashes to Azure AD, allowing cloud authentication, but the question specifies authentication against on-premises AD.
- B. Cloud authentication means users authenticate directly against Azure AD, which contradicts the requirement to authenticate against on-premises Active Directory.
- C. Federation (AD FS) requires significant on-premises infrastructure and typically involves exposing AD FS servers to the internet, which might conflict with strict security policies.
Azure AD Pass-through Authentication
An Azure AD Connect feature that validates users' passwords directly against their on-premises Active Directory without storing passwords in Azure AD, using lightweight agents.
- Provides a simple password validation for users against on-premises AD.
- Requires no inbound firewall ports to the on-premises network.
- Uses lightweight agents installed on-premises to process authentication requests.
Memory trick: Choose the path that respects the 'no inbound' rule.