Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy

A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They require that authentication requests for cloud resources are always handled by the on-premises Active Directory domain controllers, even if a user's password hash is synchronized to Azure AD. Which authentication method should be configured in Azure AD Connect to meet this requirement?

  1. ACloud-only authentication
  2. BFederation with AD FS
  3. CPass-through Authentication (PTA)
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: C. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) is designed to validate user passwords directly against on-premises Active Directory domain controllers. This ensures that authentication requests for cloud resources are always processed by the on-premises AD, fulfilling the company's requirement.

Why the other options are wrong

  • A. Cloud-only authentication means users are managed directly in Azure AD and authenticate there, which does not use on-premises AD for authentication.
  • B. Federation with AD FS also handles authentication on-premises, but PTA is a simpler, more direct method for this specific requirement without needing a full AD FS infrastructure.
  • D. PHS synchronizes password hashes, allowing Azure AD to authenticate users, which does not meet the requirement of always using on-premises domain controllers.

Pass-through Authentication (PTA)

Azure AD Pass-through Authentication (PTA) provides simple password validation for Azure AD services by forwarding authentication requests to an on-premises agent that validates the credentials against the local Active Directory.

  • No password hashes stored in Azure AD.
  • Requires Lightweight PTA Agents on-premises.
  • Simplifies hybrid identity without complex federation infrastructure.

Memory trick: Pass-through means the password goes THROUGH to the on-prem AD.

More Implement and manage hybrid identities questions