Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They have a strict security policy that prohibits inbound connections from Azure to their on-premises network. Which authentication method should they choose to ensure that users can authenticate against their on-premises Active Directory without allowing inbound connections from Azure?

  1. APassword hash synchronization (PHS)
  2. BCloud authentication with Azure AD
  3. CFederation with Azure AD (AD FS)
  4. DPass-through authentication (PTA)
Show answer & explanation

Correct answer: D. Pass-through authentication (PTA)

Pass-through authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory without requiring inbound connections from Azure. It uses lightweight agents installed on-premises to handle authentication requests.

Why the other options are wrong

  • A. PHS synchronizes password hashes to Azure AD, allowing cloud authentication, but the question specifies authentication against on-premises AD.
  • B. Cloud authentication means users authenticate directly against Azure AD, which contradicts the requirement to authenticate against on-premises Active Directory.
  • C. Federation (AD FS) requires significant on-premises infrastructure and typically involves exposing AD FS servers to the internet, which might conflict with strict security policies.

Azure AD Pass-through Authentication

An Azure AD Connect feature that validates users' passwords directly against their on-premises Active Directory without storing passwords in Azure AD, using lightweight agents.

  • Provides a simple password validation for users against on-premises AD.
  • Requires no inbound firewall ports to the on-premises network.
  • Uses lightweight agents installed on-premises to process authentication requests.

Memory trick: Choose the path that respects the 'no inbound' rule.

More Implement and manage hybrid identities questions