Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium
A company has a complex on-premises Active Directory environment with two separate forests, ForestA and ForestB. Both forests contain user accounts that need to be synchronized to a single Azure AD tenant. Users in ForestA should authenticate using Pass-through Authentication (PTA), while users in ForestB should use Password Hash Synchronization (PHS). Which Azure AD Connect deployment topology supports this requirement?
- AStaging server topology
- BMultiple forests, multiple Azure AD tenants
- CMultiple forests, single Azure AD tenant
- DSingle forest, single Azure AD tenant
Show answer & explanationAnswer & explanation
Correct answer: C. Multiple forests, single Azure AD tenant
Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests to a single Azure AD tenant. This allows for a consolidated view of users in the cloud while accommodating different authentication methods per forest.
Why the other options are wrong
- A. A staging server topology is a deployment method for Azure AD Connect itself, providing redundancy or allowing for testing, but it's not a forest-to-tenant topology type.
- B. This topology involves multiple Azure AD tenants, which is not stated as a requirement and would complicate the scenario.
- D. This topology is for a single on-premises forest, not two separate forests.
Azure AD Connect Multi-Forest Topology
A configuration where Azure AD Connect synchronizes identities from two or more on-premises Active Directory forests to a single Azure AD tenant.
- Supports different authentication methods for different forests.
- Requires unique Source Anchors across forests for user objects.
- Consolidates identities into one Azure AD tenant.
Memory trick: Forests Merge, Tenant One, Identity's Journey's Begun.