Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard
A company is migrating from an on-premises Active Directory Federation Services (AD FS) deployment to a managed authentication method in Azure AD. They want to ensure a smooth transition with minimal user impact and retain the ability to validate user credentials against their on-premises Active Directory. Which authentication method should they choose for the migration?
- APassword Hash Synchronization (PHS)
- BPass-through Authentication (PTA)
- CCloud-only authentication
- DAzure AD B2C
Show answer & explanationAnswer & explanation
Correct answer: B. Pass-through Authentication (PTA)
Migrating from AD FS while retaining on-premises credential validation points directly to Pass-through Authentication (PTA). PTA allows users to authenticate against their on-premises Active Directory without the complexity of AD FS or synchronizing password hashes to Azure AD.
Why the other options are wrong
- A. PHS would involve synchronizing password hashes to Azure AD, which is a change from validating directly against on-premises AD, and might not be preferred if on-premises validation is a strong requirement.
- C. Cloud-only authentication means all user accounts are managed directly in Azure AD, which contradicts the requirement to validate against on-premises Active Directory.
- D. Azure AD B2C is for customer-facing applications and external identities, not for enterprise employee identity migration.
AD FS to PTA Migration
The process of transitioning from an on-premises Active Directory Federation Services (AD FS) deployment to Azure AD Pass-through Authentication (PTA) for hybrid identity.
- PTA allows on-premises credential validation without AD FS infrastructure.
- Simplifies hybrid authentication while maintaining on-premises security policies.
- Offers a smoother transition than PHS if direct on-premises validation is required.
Memory trick: From the 'federated temple' to the 'cloud gateway', keep the 'on-prem guard'.