Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A global company has multiple Active Directory forests in different geographical locations. They plan to consolidate identity management using Azure AD. They need to ensure that user identities from all forests are synchronized to a single Azure AD tenant. Which Azure AD Connect deployment topology is most suitable for this scenario?

  1. AMultiple forests, single Azure AD tenant
  2. BMultiple forests, multiple Azure AD tenants
  3. CSingle forest, single Azure AD tenant
  4. DSingle forest, multiple Azure AD tenants
Show answer & explanation

Correct answer: A. Multiple forests, single Azure AD tenant

The 'Multiple forests, single Azure AD tenant' topology is designed for scenarios where an organization has several Active Directory forests and wants to synchronize all user identities into one centralized Azure AD tenant for management.

Why the other options are wrong

  • B. This involves multiple on-premises ADs synchronizing to multiple Azure AD tenants, which is more complex and not needed for a single consolidated Azure AD tenant.
  • C. This is for a single on-premises AD environment.
  • D. This is for synchronizing one on-premises AD to multiple Azure AD tenants, which is not the requirement.

Azure AD Connect Multi-Forest Topology

A deployment configuration where Azure AD Connect synchronizes identities from multiple on-premises Active Directory forests into a single Azure Active Directory tenant.

  • Supports various multi-forest scenarios (e.g., full mesh, account-resource).
  • Requires careful planning for object consolidation and attribute flow.
  • Facilitates centralized identity management in Azure AD for complex on-premises environments.

Memory trick: Forests of trees, one cloud to rule them all.

More Implement and manage hybrid identities questions