Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsEasy
A multinational corporation is migrating its on-premises applications to Azure. They require a centralized identity solution that allows users to sign in once with their existing on-premises Active Directory credentials and access both on-premises and Azure-based applications seamlessly. The solution must minimize infrastructure overhead in Azure and avoid synchronizing password hashes to the cloud. Which authentication method should be implemented?
- AAzure Active Directory Domain Services (AAD DS)
- BPass-through Authentication (PTA)
- CPassword Hash Synchronization (PHS)
- DFederation with Active Directory Federation Services (AD FS)
Show answer & explanationAnswer & explanation
Correct answer: B. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to Azure AD using their on-premises Active Directory passwords without synchronizing password hashes to Azure AD. It uses lightweight agents on-premises to validate credentials.
Why the other options are wrong
- A. AAD DS provides managed domain services in Azure but is not primarily an authentication method for syncing on-premises AD to Azure AD for user sign-in.
- C. PHS synchronizes password hashes to Azure AD, which the company wants to avoid.
- D. AD FS provides federation but typically involves significantly more infrastructure overhead than PTA and is more complex to manage.
Azure AD Pass-through Authentication (PTA)
Azure AD Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating users' passwords directly against their on-premises Active Directory.
- No password hashes stored in Azure AD
- Lightweight agents on-premises
- Seamless single sign-on experience
- Supports legacy authentication protocols
Memory trick: PTA Passes Through to AD.