Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy
A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They require that authentication requests for cloud resources are always handled by the on-premises Active Directory domain controllers, even if a user's password hash is synchronized to Azure AD. Which authentication method should be configured in Azure AD Connect to meet this requirement?
- ACloud-only authentication
- BFederation with AD FS
- CPass-through Authentication (PTA)
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: C. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) is designed to validate user passwords directly against on-premises Active Directory domain controllers. This ensures that authentication requests for cloud resources are always processed by the on-premises AD, fulfilling the company's requirement.
Why the other options are wrong
- A. Cloud-only authentication means users are managed directly in Azure AD and authenticate there, which does not use on-premises AD for authentication.
- B. Federation with AD FS also handles authentication on-premises, but PTA is a simpler, more direct method for this specific requirement without needing a full AD FS infrastructure.
- D. PHS synchronizes password hashes, allowing Azure AD to authenticate users, which does not meet the requirement of always using on-premises domain controllers.
Pass-through Authentication (PTA)
Azure AD Pass-through Authentication (PTA) provides simple password validation for Azure AD services by forwarding authentication requests to an on-premises agent that validates the credentials against the local Active Directory.
- No password hashes stored in Azure AD.
- Requires Lightweight PTA Agents on-premises.
- Simplifies hybrid identity without complex federation infrastructure.
Memory trick: Pass-through means the password goes THROUGH to the on-prem AD.