Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company has a complex on-premises Active Directory environment with two separate forests, ForestA and ForestB. Both forests contain user accounts that need to be synchronized to a single Azure AD tenant. Users in ForestA should authenticate using Pass-through Authentication (PTA), while users in ForestB should use Password Hash Synchronization (PHS). Which Azure AD Connect deployment topology supports this requirement?

  1. AStaging server topology
  2. BMultiple forests, multiple Azure AD tenants
  3. CMultiple forests, single Azure AD tenant
  4. DSingle forest, single Azure AD tenant
Show answer & explanation

Correct answer: C. Multiple forests, single Azure AD tenant

Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests to a single Azure AD tenant. This allows for a consolidated view of users in the cloud while accommodating different authentication methods per forest.

Why the other options are wrong

  • A. A staging server topology is a deployment method for Azure AD Connect itself, providing redundancy or allowing for testing, but it's not a forest-to-tenant topology type.
  • B. This topology involves multiple Azure AD tenants, which is not stated as a requirement and would complicate the scenario.
  • D. This topology is for a single on-premises forest, not two separate forests.

Azure AD Connect Multi-Forest Topology

A configuration where Azure AD Connect synchronizes identities from two or more on-premises Active Directory forests to a single Azure AD tenant.

  • Supports different authentication methods for different forests.
  • Requires unique Source Anchors across forests for user objects.
  • Consolidates identities into one Azure AD tenant.

Memory trick: Forests Merge, Tenant One, Identity's Journey's Begun.

More Implement and manage hybrid identities questions