Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard

A company has a complex on-premises Active Directory environment with multiple forests and uses a full mesh trust topology. They plan to implement Azure AD Connect to synchronize users to a single Azure AD tenant. They need to ensure that users are represented as a single identity in Azure AD, even if their account and resource objects reside in different forests. Which Azure AD Connect feature is crucial for achieving this object consolidation?

  1. APassword hash synchronization
  2. BAttribute filtering
  3. CJoin rules
  4. DOrganizational unit (OU) filtering
Show answer & explanation

Correct answer: C. Join rules

In multi-forest scenarios, especially with account-resource forests or full mesh trusts, 'join rules' (part of synchronization rules) are crucial. They define how objects from different forests that represent the same real-world entity are identified and combined into a single metaverse object, which then synchronizes to Azure AD as a single identity.

Why the other options are wrong

  • A. Password hash synchronization is an authentication method, not a mechanism for object consolidation.
  • B. Attribute filtering controls which attributes are synchronized, not how objects are consolidated.
  • D. OU filtering controls which OUs are synchronized, not how objects from different OUs/forests are consolidated.

Azure AD Connect Join Rules

Synchronization rules within Azure AD Connect that define how objects from different connected directories (e.g., multiple AD forests) are matched and combined into a single object in the metaverse.

  • Essential for object consolidation in multi-forest environments.
  • Uses attributes (e.g., mail, employeeID) to match objects.
  • Helps create a single, unified identity in Azure AD from disparate sources.

Memory trick: To 'join' two 'forest entities' into one 'cloud person', use 'join rules'.

More Implement and manage hybrid identities questions