Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium
A company is preparing to deploy Azure AD Connect. Their on-premises Active Directory environment consists of multiple separate forests, each with its own UPN suffix and distinct user populations. They need to synchronize users from all forests into a single Azure AD tenant. What is the recommended Azure AD Connect topology for this scenario?
- ASingle forest, single Azure AD tenant
- BMultiple forests, multiple Azure AD tenants
- CSingle forest, multiple Azure AD tenants
- DMultiple forests, single Azure AD tenant
Show answer & explanationAnswer & explanation
Correct answer: D. Multiple forests, single Azure AD tenant
Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests into a single Azure AD tenant. This is a common scenario for organizations with complex on-premises environments and is fully supported by the tool.
Why the other options are wrong
- A. This topology is for simpler environments with only one on-premises forest.
- B. This topology involves multiple Azure AD tenants, which is not stated as a requirement and adds unnecessary complexity for a single Azure AD tenant goal.
- C. Synchronizing a single forest to multiple Azure AD tenants is not directly supported by a single Azure AD Connect instance.
Azure AD Connect Multi-Forest Topology
Azure AD Connect can synchronize user identities from multiple disparate on-premises Active Directory forests into a single Azure Active Directory tenant.
- Requires network connectivity to all forests.
- Can handle different UPNs and attributes across forests.
- Supports various authentication methods (PHS, PTA, Federation).
Memory trick: Many forests can lead to one Azure AD cloud.