Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A global conglomerate with numerous subsidiaries is migrating its on-premises applications to Azure. Each subsidiary has its own Active Directory forest, and they all need to authenticate users to Azure AD with a single sign-on experience. The solution must ensure that users authenticate against their respective on-premises Active Directory forests, and credentials are never synchronized to Azure AD. Which Azure AD authentication method should be recommended?

  1. AFederation with Active Directory Federation Services (AD FS)
  2. BPassword Hash Synchronization (PHS)
  3. CAzure AD Domain Services (AAD DS)
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: A. Federation with Active Directory Federation Services (AD FS)

Federation with AD FS allows organizations to use their on-premises Active Directory for authentication while providing single sign-on to Azure AD-connected applications. This method specifically keeps credentials on-premises and does not synchronize them to Azure AD, aligning with the requirement for multiple on-premises AD forests.

Why the other options are wrong

  • B. PHS synchronizes a hash of user passwords to Azure AD, which violates the requirement that credentials are never synchronized.
  • C. AAD DS provides managed domain services in Azure, but it doesn't directly address authenticating users against existing on-premises AD forests without synchronizing credentials.
  • D. PTA uses agents to validate user credentials directly against on-premises AD, but it's typically for a single forest and doesn't inherently support the complex multi-forest federation scenario as robustly as AD FS.

Azure AD Federation

Azure AD Federation allows organizations to use an on-premises identity provider, such as Active Directory Federation Services (AD FS), to authenticate users against their on-premises Active Directory and provide single sign-on to Azure AD-connected applications, without synchronizing password hashes.

  • Uses an on-premises identity provider (e.g., AD FS).
  • Credentials remain on-premises, never synchronized to Azure AD.
  • Provides single sign-on (SSO) experience.
  • Ideal for complex multi-forest or security-sensitive environments.

Memory trick: Credentials stay home, but everyone gets a key to the cloud castle.

More Design identity, governance, and monitoring solutions questions