Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy
A company is configuring Azure AD Connect for an existing Active Directory forest. They need to ensure that user password changes made on-premises are immediately reflected in Azure Active Directory for cloud applications. Which feature of Azure AD Connect must be implemented to achieve this goal?
- APassword hash synchronization
- BPassword writeback
- CAzure AD Connect Health
- DSeamless single sign-on
Show answer & explanationAnswer & explanation
Correct answer: A. Password hash synchronization
Password hash synchronization (PHS) is the feature that synchronizes a hash of a user's password from on-premises Active Directory to Azure AD, allowing immediate reflection of password changes in the cloud.
Why the other options are wrong
- B. Password writeback allows password changes in Azure AD to be written back to on-premises AD, which is the opposite of the requirement.
- C. Azure AD Connect Health monitors the health of identity components, but doesn't directly synchronize password changes.
- D. Seamless single sign-on provides a seamless login experience but does not manage password synchronization itself.
Password Hash Synchronization (PHS)
A method of hybrid identity that synchronizes a cryptographic hash of a user's password from on-premises Active Directory to Azure AD, enabling cloud authentication.
- Simplest method for hybrid identity password synchronization.
- Provides a form of cloud authentication.
- Enables immediate reflection of on-premises password changes in Azure AD.
Memory trick: To reflect changes, you must sync the password's 'essence'.