Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium

A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that, for disaster recovery purposes, user authentication must remain functional even if the on-premises Active Directory Domain Services (AD DS) becomes temporarily unavailable. Which authentication method should you choose for Microsoft Entra Connect to meet this requirement?

  1. APass-through Authentication (PTA)
  2. BCloud Kerberos Trust
  3. CPassword Hash Synchronization (PHS)
  4. DFederation with AD FS
Show answer & explanation

Correct answer: C. Password Hash Synchronization (PHS)

Password Hash Synchronization (PHS) is the only authentication method that allows users to authenticate directly against Microsoft Entra ID even if on-premises AD DS is unavailable. This is because a hash of their password is synchronized and stored in Microsoft Entra ID.

Why the other options are wrong

  • A. PTA requires on-premises AD DS availability for authentication.
  • B. Cloud Kerberos Trust is for hybrid-joined devices to access on-premises resources, not an authentication method for cloud sign-in when on-premises AD is down.
  • D. Federation with AD FS relies entirely on the availability of the on-premises AD FS infrastructure and AD DS.

Password Hash Synchronization (PHS)

A Microsoft Entra Connect authentication method where a cryptographic hash of a user's password hash is synchronized from on-premises Active Directory to Microsoft Entra ID.

  • Provides a cloud-only authentication experience.
  • Allows users to sign in even if on-premises AD DS is unavailable.
  • Simplest to deploy and manage among hybrid authentication methods.
  • Offers built-in high availability and disaster recovery for authentication.

Memory trick: PHS: Passwords Hashed, Safe in the Cloud.

More Implement and manage Microsoft Entra ID questions