Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company is preparing to deploy Azure AD Connect. Their on-premises Active Directory environment consists of multiple separate forests, each with its own UPN suffix and distinct user populations. They need to synchronize users from all forests into a single Azure AD tenant. What is the recommended Azure AD Connect topology for this scenario?

  1. ASingle forest, single Azure AD tenant
  2. BMultiple forests, multiple Azure AD tenants
  3. CSingle forest, multiple Azure AD tenants
  4. DMultiple forests, single Azure AD tenant
Show answer & explanation

Correct answer: D. Multiple forests, single Azure AD tenant

Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests into a single Azure AD tenant. This is a common scenario for organizations with complex on-premises environments and is fully supported by the tool.

Why the other options are wrong

  • A. This topology is for simpler environments with only one on-premises forest.
  • B. This topology involves multiple Azure AD tenants, which is not stated as a requirement and adds unnecessary complexity for a single Azure AD tenant goal.
  • C. Synchronizing a single forest to multiple Azure AD tenants is not directly supported by a single Azure AD Connect instance.

Azure AD Connect Multi-Forest Topology

Azure AD Connect can synchronize user identities from multiple disparate on-premises Active Directory forests into a single Azure Active Directory tenant.

  • Requires network connectivity to all forests.
  • Can handle different UPNs and attributes across forests.
  • Supports various authentication methods (PHS, PTA, Federation).

Memory trick: Many forests can lead to one Azure AD cloud.

More Implement and manage hybrid identities questions