A company is migrating from a legacy on-premises application that uses LDAP authentication to a modern cloud-based application that integrates with Azure AD. They need to ensure that user accounts and passwords are synchronized to Azure AD. However, they have a strict security policy prohibiting any on-premises passwords from leaving their network in any form, including hashes. Which authentication method, if any, could support this requirement while enabling cloud application access?
- ANone of the above
- BFederation with AD FS
- CPass-through Authentication (PTA)
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: A. None of the above
If a strict policy prohibits *any* form of on-premises passwords (including hashes) from leaving the network, then neither PHS nor PTA can be used, as PHS sends hashes to Azure AD and PTA requires agents to forward password validation requests through the internet to Azure AD. Federation (AD FS) keeps passwords on-premises but still involves sending security tokens to Azure AD for authentication, which might be deemed a 'form' of authentication information leaving the network, depending on the interpretation of 'any form'. If the policy is absolutely airtight against *any* on-premises password-derived information (even validation requests or tokens) leaving the network, then hybrid identity might not be fully achievable for on-premises accounts, or cloud-only accounts would be required.
Why the other options are wrong
- B. Federation with AD FS keeps passwords on-premises, but it issues security tokens that are sent to Azure AD. Depending on the interpretation of 'any form' of password information, this might also violate the policy.
- C. PTA agents forward password validation requests to Azure AD, which then facilitates the validation against on-premises AD, meaning some form of password-related traffic (the validation request) leaves the network.
- D. PHS sends password hashes to Azure AD, violating the 'no hashes leaving network' policy.
Strict Password Sovereignty
A security policy that prohibits any form of on-premises password information, including hashes or validation requests, from leaving the on-premises network.
- Challenges standard hybrid identity authentication methods.
- PHS sends hashes.
- PTA sends validation requests through Azure AD.
- AD FS sends security tokens to Azure AD.
Memory trick: No Password Leaves, No Cloud Access for On-Premise Peace.