A global conglomerate with numerous subsidiaries is migrating its on-premises applications to Azure. Each subsidiary has its own Active Directory forest, and they all need to authenticate users to Azure AD with a single sign-on experience. The solution must ensure that users authenticate against their respective on-premises Active Directory forests, and credentials are never synchronized to Azure AD. Which Azure AD authentication method should be recommended?
- AFederation with Active Directory Federation Services (AD FS)
- BPassword Hash Synchronization (PHS)
- CAzure AD Domain Services (AAD DS)
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: A. Federation with Active Directory Federation Services (AD FS)
Federation with AD FS allows organizations to use their on-premises Active Directory for authentication while providing single sign-on to Azure AD-connected applications. This method specifically keeps credentials on-premises and does not synchronize them to Azure AD, aligning with the requirement for multiple on-premises AD forests.
Why the other options are wrong
- B. PHS synchronizes a hash of user passwords to Azure AD, which violates the requirement that credentials are never synchronized.
- C. AAD DS provides managed domain services in Azure, but it doesn't directly address authenticating users against existing on-premises AD forests without synchronizing credentials.
- D. PTA uses agents to validate user credentials directly against on-premises AD, but it's typically for a single forest and doesn't inherently support the complex multi-forest federation scenario as robustly as AD FS.
Azure AD Federation
Azure AD Federation allows organizations to use an on-premises identity provider, such as Active Directory Federation Services (AD FS), to authenticate users against their on-premises Active Directory and provide single sign-on to Azure AD-connected applications, without synchronizing password hashes.
- Uses an on-premises identity provider (e.g., AD FS).
- Credentials remain on-premises, never synchronized to Azure AD.
- Provides single sign-on (SSO) experience.
- Ideal for complex multi-forest or security-sensitive environments.
Memory trick: Credentials stay home, but everyone gets a key to the cloud castle.