Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy

A company is configuring Azure AD Connect for an existing Active Directory forest. They need to ensure that user password changes made on-premises are immediately reflected in Azure Active Directory for cloud applications. Which feature of Azure AD Connect must be implemented to achieve this goal?

  1. APassword hash synchronization
  2. BPassword writeback
  3. CAzure AD Connect Health
  4. DSeamless single sign-on
Show answer & explanation

Correct answer: A. Password hash synchronization

Password hash synchronization (PHS) is the feature that synchronizes a hash of a user's password from on-premises Active Directory to Azure AD, allowing immediate reflection of password changes in the cloud.

Why the other options are wrong

  • B. Password writeback allows password changes in Azure AD to be written back to on-premises AD, which is the opposite of the requirement.
  • C. Azure AD Connect Health monitors the health of identity components, but doesn't directly synchronize password changes.
  • D. Seamless single sign-on provides a seamless login experience but does not manage password synchronization itself.

Password Hash Synchronization (PHS)

A method of hybrid identity that synchronizes a cryptographic hash of a user's password from on-premises Active Directory to Azure AD, enabling cloud authentication.

  • Simplest method for hybrid identity password synchronization.
  • Provides a form of cloud authentication.
  • Enables immediate reflection of on-premises password changes in Azure AD.

Memory trick: To reflect changes, you must sync the password's 'essence'.

More Implement and manage hybrid identities questions