Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company is planning to migrate from an on-premises Active Directory Federation Services (AD FS) deployment to Pass-through Authentication (PTA) for their hybrid identity solution. They need to ensure a smooth transition with minimal downtime for users. Which of the following is a key step to prepare for this migration?

  1. AInstall and configure at least two PTA agents on separate servers.
  2. BDecommission all AD FS servers before installing PTA agents.
  3. CSynchronize all user passwords to Azure AD using PHS first.
  4. DDisable password writeback in Azure AD Connect.
Show answer & explanation

Correct answer: A. Install and configure at least two PTA agents on separate servers.

Before switching from AD FS to PTA, it's crucial to deploy and configure the PTA agents. Deploying at least two agents ensures high availability and allows for testing before the final cutover, minimizing downtime during the migration.

Why the other options are wrong

  • B. Decommissioning AD FS servers prematurely would cause a service outage before PTA is ready.
  • C. While PHS can coexist, it's not a required step for migrating from AD FS to PTA; PTA directly validates against on-premises AD.
  • D. Disabling password writeback is unrelated to the migration from AD FS to PTA and could disrupt services that rely on it.

AD FS to PTA Migration

The process of transitioning from using Active Directory Federation Services to Pass-through Authentication for hybrid identity.

  • Requires deploying PTA agents before switching authentication.
  • Allows for a phased migration strategy.
  • Reduces on-premises infrastructure complexity compared to AD FS.

Memory trick: Switching Authentication? Agents First, Then Flip the Switch.

More Implement and manage hybrid identities questions