Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium
A company is utilizing Azure AD Connect to synchronize users from an on-premises Active Directory to Azure AD. They have configured Password Hash Synchronization (PHS). Recently, some users reported issues with accessing cloud applications, specifically that their password changes made on-premises are not being recognized in Azure AD. You need to identify the most likely cause of this issue.
- AThe user's UPN suffix does not match a verified custom domain in Azure AD.
- BThe Password Hash Synchronization feature is disabled in Azure AD Connect.
- CThe Azure AD Connect server is not running on a domain controller.
- DThe Azure AD Connect Health agent is not installed on the synchronization server.
Show answer & explanationAnswer & explanation
Correct answer: B. The Password Hash Synchronization feature is disabled in Azure AD Connect.
If Password Hash Synchronization is enabled but password changes are not being recognized, the most direct cause would be that the PHS feature itself has been disabled or is not functioning correctly within Azure AD Connect.
Why the other options are wrong
- A. While UPN suffixes are important for user sign-in, they don't directly prevent password hash synchronization from occurring.
- C. Azure AD Connect can run on a member server; it does not need to be installed on a domain controller.
- D. Azure AD Connect Health monitors the sync process but does not directly prevent PHS from working if it's configured.
Azure AD Connect PHS Troubleshooting
Identifying and resolving issues related to Password Hash Synchronization (PHS) between on-premises Active Directory and Azure AD.
- Verify PHS feature is enabled in Azure AD Connect.
- Check Azure AD Connect synchronization service for errors related to password hash synchronization.
- Ensure network connectivity to Azure AD is functional for the sync server.
Memory trick: When the password 'key' doesn't reach the 'cloud lock', check the sync mechanism.