Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium
A global manufacturing company with existing on-premises Active Directory (AD) requires a hybrid identity solution for its Azure environment. Users must be able to log in to Azure resources using their existing on-premises credentials. The solution must support single sign-on (SSO) and synchronize user accounts and password hashes to Azure AD, without requiring any dedicated servers in the perimeter network (DMZ) for authentication. Which authentication solution should be implemented?
- AAzure AD Connect with Password Hash Synchronization (PHS)
- BAzure AD Domain Services
- CAzure AD Connect with Federation (AD FS)
- DAzure AD Connect with Pass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect with Password Hash Synchronization (PHS)
Azure AD Connect with Password Hash Synchronization (PHS) synchronizes a hash of the user's on-premises AD password hash to Azure AD. This allows users to sign in with the same credentials and supports SSO, while not requiring dedicated servers in the DMZ for authentication, as Azure AD handles the authentication directly.
Why the other options are wrong
- B. Azure AD Domain Services provides managed domain services for Azure VMs but is not an identity synchronization and authentication solution for on-premises AD users accessing Azure AD directly.
- C. Federation (AD FS) requires on-premises AD FS servers, often in a DMZ, which contradicts the 'no dedicated servers in DMZ' requirement.
- D. PTA requires agents in the internal network to validate passwords against on-premises AD, but it doesn't synchronize password hashes to Azure AD for direct Azure AD authentication.
Password Hash Synchronization (PHS)
A hybrid identity method where a hash of the user's on-premises Active Directory password hash is synchronized to Azure Active Directory. This allows users to sign in to Azure AD with the same credentials they use on-premises.
- Simplest to implement for hybrid identity
- Provides cloud authentication if on-premises AD is unavailable
- Supports seamless SSO
Memory trick: Sync PASSWORDS, Pass-THRU, or FEDERATE.