Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard

A company is using Azure AD Connect with Password Hash Synchronization (PHS) enabled. They have an on-premises security policy that requires users to change their passwords every 90 days. Users are complaining that their Azure AD passwords are not expiring, even though they change them on-premises. What is the most likely cause for this discrepancy?

  1. AAzure AD's default password policy is overriding the on-premises policy.
  2. BPassword Hash Synchronization does not synchronize password expiration dates.
  3. CPassword writeback is not enabled in Azure AD Connect.
  4. DThe 'Password never expires' attribute is set on the user objects in Azure AD.
Show answer & explanation

Correct answer: B. Password Hash Synchronization does not synchronize password expiration dates.

Password Hash Synchronization (PHS) only synchronizes the hash of the user's password, not the password expiration date or policy. Azure AD has its own password policy, and unless password writeback is configured to enforce on-premises policies (which is not directly related to PHS itself), the on-premises expiration policy will not be applied to Azure AD.

Why the other options are wrong

  • A. Azure AD's default policy *does* apply, but the core issue is that PHS doesn't transfer the on-premises expiration date for Azure AD to enforce.
  • C. Password writeback allows password changes in Azure AD to be written back to on-premises AD, but it doesn't directly synchronize on-premises expiration policies to Azure AD.
  • D. While possible, it's less likely to be the *most likely* cause for a general policy discrepancy across many users, especially if the on-premises policy is active.

PHS and Password Policy

Password Hash Synchronization (PHS) transfers password hashes to Azure AD but does not inherently synchronize on-premises password policies or expiration dates.

  • Azure AD applies its own password policy to synced users.
  • On-premises password expiration is not directly enforced by PHS in Azure AD.
  • Password writeback is for writing Azure AD password changes back to on-premises AD.

Memory trick: Hash is Sent, Policy Stays, Expiration's Own Way.

More Implement and manage hybrid identities questions