Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A large e-commerce company is migrating its on-premises applications to Azure. They have a significant investment in on-premises Active Directory and want to extend its capabilities to Azure without deploying new domain controllers in the cloud. Users should authenticate against their existing on-premises credentials for Azure-hosted applications. Which authentication method should be used for Azure AD Connect?

  1. APass-through Authentication (PTA)
  2. BPassword Hash Synchronization (PHS)
  3. CFederation with AD FS
  4. DAzure AD Domain Services (AAD DS)
Show answer & explanation

Correct answer: A. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) is designed for scenarios where organizations want to validate user passwords against their on-premises Active Directory without exposing their domain controllers to the internet or setting up a complex federation infrastructure. This meets the requirement of using existing on-premises credentials without new domain controllers in Azure.

Why the other options are wrong

  • B. PHS synchronizes password hashes to Azure AD, meaning users authenticate directly against Azure AD, not on-premises AD.
  • C. Federation with AD FS involves deploying and managing AD FS servers, which the company explicitly wants to avoid (no new domain controllers in the cloud implies avoiding additional server infrastructure).
  • D. AAD DS provides managed domain services in Azure, but users authenticate against AAD DS, not directly against on-premises AD for this specific setup.

Azure AD Connect Pass-through Authentication (PTA)

Azure AD Connect Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating passwords directly against your on-premises Active Directory.

  • Provides a simple way to achieve single sign-on with on-premises AD.
  • Does not store user passwords in Azure AD; only the hash of the password is sent for comparison.
  • Requires lightweight agents on-premises to forward authentication requests.

Memory trick: PTA: Your password 'passes through' to its home for verification.

More Design identity, governance, and monitoring solutions questions