Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company has implemented Azure AD Connect with Password Hash Synchronization (PHS). They have a requirement that users must be able to change their on-premises Active Directory password from the Azure AD self-service password reset (SSPR) portal. Which Azure AD Connect feature must be enabled to allow this functionality?

  1. APass-through Authentication
  2. BFederation with AD FS
  3. CPassword writeback
  4. DSeamless Single Sign-on
Show answer & explanation

Correct answer: C. Password writeback

Password writeback is an Azure AD Connect feature that allows password changes initiated in Azure AD (such as through Self-Service Password Reset) to be written back to the on-premises Active Directory. This is essential for users to change their on-premises password from the cloud.

Why the other options are wrong

  • A. Pass-through Authentication is an authentication method, not a feature for writing passwords back to on-premises AD.
  • B. Federation with AD FS is an authentication method that relies on AD FS for authentication, and while it can support SSPR, password writeback is the specific feature for writing changes back to on-premises AD.
  • D. Seamless Single Sign-on provides a seamless authentication experience but does not enable password changes to be written back to on-premises AD.

Password Writeback

Password writeback is an Azure AD Connect feature that enables self-service password reset (SSPR) and password change events in Azure AD to update users' on-premises Active Directory passwords.

  • Requires Azure AD Connect to be installed.
  • Enables SSPR to update on-premises passwords.
  • Requires specific permissions for the Azure AD Connect service account.

Memory trick: Writeback is like a boomerang, sending password changes back home.

More Implement and manage hybrid identities questions