Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A company is migrating its on-premises user accounts to Microsoft 365. The security team mandates that all user identities must be managed centrally from the on-premises Active Directory and that users should experience a single sign-on experience when accessing Microsoft 365 services. Which synchronization method should be implemented to meet these requirements?
- APass-through Authentication (PTA)
- BCloud-only identities
- CFederation with Active Directory Federation Services (AD FS)
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: C. Federation with Active Directory Federation Services (AD FS)
Federation with AD FS allows for centralized identity management on-premises and provides a true single sign-on experience where authentication requests are redirected to the on-premises AD FS server. This meets the security team's mandate for central management and single sign-on.
Why the other options are wrong
- A. PTA agents authenticate against on-premises AD, but it's not a full federation solution and can have different SSO characteristics than AD FS in some scenarios.
- B. Cloud-only identities would mean managing identities directly in Azure AD, which contradicts the requirement for centralized on-premises management.
- D. PHS synchronizes password hashes to Azure AD, but authentication still occurs in Azure AD, not strictly centrally from on-premises AD for every login.
Federated Identity
A system where a user's identity and authentication are managed by one system (identity provider) but trusted by another system (service provider) to grant access.
- Enables single sign-on across multiple services.
- Requires an identity provider (e.g., AD FS) to handle authentication.
- Provides centralized control over authentication policies.
Memory trick: Think of different bridges connecting your on-premises castle to the Microsoft 365 cloud kingdom.