Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard

A company is configuring Azure AD Connect. They have users with on-premises UPNs ending in '.local' (e.g., user@contoso.local) and want these users to sign in to Azure AD with a routable UPN (e.g., user@contoso.com). They have already added 'contoso.com' as a custom domain in Azure AD. Which step is necessary in Azure AD Connect to achieve this desired UPN suffix for cloud sign-ins?

  1. AConfigure Pass-through Authentication for all users.
  2. BModify the inbound synchronization rule for the UPN attribute.
  3. CEnable Password Writeback in Azure AD Connect.
  4. DAdd 'contoso.com' as an alternate UPN suffix in on-premises Active Directory.
Show answer & explanation

Correct answer: D. Add 'contoso.com' as an alternate UPN suffix in on-premises Active Directory.

For users to sign in with a routable UPN (like user@contoso.com) that differs from their on-premises non-routable UPN (user@contoso.local), the routable suffix must be added as an alternate UPN suffix in the on-premises Active Directory. Azure AD Connect can then synchronize this alternate UPN, or you can configure it to replace the '.local' suffix with '.com' during synchronization.

Why the other options are wrong

  • A. The authentication method (PTA in this case) does not directly control the UPN format used for sign-in; it only controls how the password is validated.
  • B. While modifying inbound sync rules *can* be used to transform UPNs, the most robust and recommended approach for routable UPNs when the on-premises UPN is non-routable is to first add the routable suffix to on-premises AD and assign it to users. This avoids potential issues with UPN conflicts or identity mismatches.
  • C. Password Writeback is for writing Azure AD password changes back to on-premises AD, not for UPN formatting.

Routable UPN for Hybrid Identity

Ensuring users can sign in to Azure AD with a UPN that is publicly routable, even if their on-premises UPN is non-routable.

  • Requires adding the routable domain as a custom domain in Azure AD.
  • Requires adding the routable domain as an alternate UPN suffix in on-premises AD.
  • Users can then be assigned the routable UPN in on-premises AD.

Memory trick: Local's Not Cloud, Add the Domain, Then Sync Again.

More Implement and manage hybrid identities questions