Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDEasy

A company is planning to implement Microsoft Entra ID for identity management. They have an existing on-premises Active Directory Domain Services (AD DS) environment. The security team insists that user passwords must *never* leave the on-premises network and that users should authenticate directly against the on-premises AD DS. Which Microsoft Entra Connect authentication method should you recommend?

  1. ACloud Kerberos Trust
  2. BPass-through Authentication (PTA)
  3. CFederation with AD FS
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: B. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory directly, ensuring that passwords never leave the on-premises network. This fulfills the security team's requirement.

Why the other options are wrong

  • A. Cloud Kerberos Trust is a feature for hybrid identity, but not an authentication method for initial Microsoft Entra Connect setup directly addressing the 'never leave on-premises' password requirement in this manner.
  • C. Federation with AD FS involves additional infrastructure and redirects authentication, but passwords are still processed by AD FS, which is on-premises.
  • D. PHS synchronizes password hashes to Microsoft Entra ID, meaning a representation of the password leaves the on-premises network.

Pass-through Authentication (PTA)

A Microsoft Entra Connect authentication method where user sign-in requests are redirected to an agent running on an on-premises server, which validates the password directly against Active Directory.

  • Passwords never leave the on-premises network.
  • Requires one or more lightweight agents on-premises.
  • Provides a seamless sign-in experience for users.

Memory trick: Pass-Through: Passwords Stay Safe On-Premises.

More Implement and manage Microsoft Entra ID questions