Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy

A company is planning to implement Azure AD Connect to synchronize users from their on-premises Active Directory to Azure AD. They want to ensure that user passwords are never stored in the cloud in plain text and that users can authenticate against their on-premises Active Directory domain controllers directly when accessing cloud resources. Which authentication method should they choose for Azure AD Connect?

  1. APass-through Authentication (PTA)
  2. BPassword Hash Synchronization (PHS)
  3. CFederation with AD FS
  4. DCloud-only authentication
Show answer & explanation

Correct answer: A. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) allows users to sign in to Azure AD using the same passwords as their on-premises Active Directory. It achieves this by validating passwords directly against the on-premises AD domain controllers, ensuring passwords are never stored in the cloud.

Why the other options are wrong

  • B. PHS synchronizes a hash of the password to Azure AD, which is not the same as direct on-premises validation.
  • C. Federation with AD FS involves an on-premises federation server, which adds complexity and may not be the most straightforward solution for direct on-premises validation without storing passwords in Azure AD.
  • D. Cloud-only authentication means users are managed directly in Azure AD, which doesn't allow authentication against on-premises AD.

Pass-through Authentication (PTA)

An Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory domain controllers.

  • Passwords are never stored in Azure AD, even in hashed form.
  • Requires lightweight agents installed on-premises.
  • Provides a seamless sign-in experience for users.

Memory trick: Connect, Authenticate, Secure Your Cloud Path.

More Implement and manage hybrid identities questions