Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A company is migrating its on-premises user accounts to Microsoft 365. The security team mandates that all user identities must be managed centrally from the on-premises Active Directory and that users should experience a single sign-on experience when accessing Microsoft 365 services. Which synchronization method should be implemented to meet these requirements?

  1. APass-through Authentication (PTA)
  2. BCloud-only identities
  3. CFederation with Active Directory Federation Services (AD FS)
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: C. Federation with Active Directory Federation Services (AD FS)

Federation with AD FS allows for centralized identity management on-premises and provides a true single sign-on experience where authentication requests are redirected to the on-premises AD FS server. This meets the security team's mandate for central management and single sign-on.

Why the other options are wrong

  • A. PTA agents authenticate against on-premises AD, but it's not a full federation solution and can have different SSO characteristics than AD FS in some scenarios.
  • B. Cloud-only identities would mean managing identities directly in Azure AD, which contradicts the requirement for centralized on-premises management.
  • D. PHS synchronizes password hashes to Azure AD, but authentication still occurs in Azure AD, not strictly centrally from on-premises AD for every login.

Federated Identity

A system where a user's identity and authentication are managed by one system (identity provider) but trusted by another system (service provider) to grant access.

  • Enables single sign-on across multiple services.
  • Requires an identity provider (e.g., AD FS) to handle authentication.
  • Provides centralized control over authentication policies.

Memory trick: Think of different bridges connecting your on-premises castle to the Microsoft 365 cloud kingdom.

More Deploy and manage a Microsoft 365 tenant questions