Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium
A large e-commerce company is migrating its on-premises applications to Azure. They have a significant investment in on-premises Active Directory and want to extend its capabilities to Azure without deploying new domain controllers in the cloud. Users should authenticate against their existing on-premises credentials for Azure-hosted applications. Which authentication method should be used for Azure AD Connect?
- APass-through Authentication (PTA)
- BPassword Hash Synchronization (PHS)
- CFederation with AD FS
- DAzure AD Domain Services (AAD DS)
Show answer & explanationAnswer & explanation
Correct answer: A. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) is designed for scenarios where organizations want to validate user passwords against their on-premises Active Directory without exposing their domain controllers to the internet or setting up a complex federation infrastructure. This meets the requirement of using existing on-premises credentials without new domain controllers in Azure.
Why the other options are wrong
- B. PHS synchronizes password hashes to Azure AD, meaning users authenticate directly against Azure AD, not on-premises AD.
- C. Federation with AD FS involves deploying and managing AD FS servers, which the company explicitly wants to avoid (no new domain controllers in the cloud implies avoiding additional server infrastructure).
- D. AAD DS provides managed domain services in Azure, but users authenticate against AAD DS, not directly against on-premises AD for this specific setup.
Azure AD Connect Pass-through Authentication (PTA)
Azure AD Connect Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating passwords directly against your on-premises Active Directory.
- Provides a simple way to achieve single sign-on with on-premises AD.
- Does not store user passwords in Azure AD; only the hash of the password is sent for comparison.
- Requires lightweight agents on-premises to forward authentication requests.
Memory trick: PTA: Your password 'passes through' to its home for verification.