Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesEasy
A company is planning to implement Azure AD Connect to synchronize users from their on-premises Active Directory to Azure AD. They want to ensure that user passwords are never stored in the cloud in plain text and that users can authenticate against their on-premises Active Directory domain controllers directly when accessing cloud resources. Which authentication method should they choose for Azure AD Connect?
- APass-through Authentication (PTA)
- BPassword Hash Synchronization (PHS)
- CFederation with AD FS
- DCloud-only authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to Azure AD using the same passwords as their on-premises Active Directory. It achieves this by validating passwords directly against the on-premises AD domain controllers, ensuring passwords are never stored in the cloud.
Why the other options are wrong
- B. PHS synchronizes a hash of the password to Azure AD, which is not the same as direct on-premises validation.
- C. Federation with AD FS involves an on-premises federation server, which adds complexity and may not be the most straightforward solution for direct on-premises validation without storing passwords in Azure AD.
- D. Cloud-only authentication means users are managed directly in Azure AD, which doesn't allow authentication against on-premises AD.
Pass-through Authentication (PTA)
An Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory domain controllers.
- Passwords are never stored in Azure AD, even in hashed form.
- Requires lightweight agents installed on-premises.
- Provides a seamless sign-in experience for users.
Memory trick: Connect, Authenticate, Secure Your Cloud Path.