Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDEasy
A company is planning to implement Microsoft Entra ID for identity management. They have an existing on-premises Active Directory Domain Services (AD DS) environment. The security team insists that user passwords must *never* leave the on-premises network and that users should authenticate directly against the on-premises AD DS. Which Microsoft Entra Connect authentication method should you recommend?
- ACloud Kerberos Trust
- BPass-through Authentication (PTA)
- CFederation with AD FS
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: B. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory directly, ensuring that passwords never leave the on-premises network. This fulfills the security team's requirement.
Why the other options are wrong
- A. Cloud Kerberos Trust is a feature for hybrid identity, but not an authentication method for initial Microsoft Entra Connect setup directly addressing the 'never leave on-premises' password requirement in this manner.
- C. Federation with AD FS involves additional infrastructure and redirects authentication, but passwords are still processed by AD FS, which is on-premises.
- D. PHS synchronizes password hashes to Microsoft Entra ID, meaning a representation of the password leaves the on-premises network.
Pass-through Authentication (PTA)
A Microsoft Entra Connect authentication method where user sign-in requests are redirected to an agent running on an on-premises server, which validates the password directly against Active Directory.
- Passwords never leave the on-premises network.
- Requires one or more lightweight agents on-premises.
- Provides a seamless sign-in experience for users.
Memory trick: Pass-Through: Passwords Stay Safe On-Premises.