Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium
A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that, for disaster recovery purposes, user authentication must remain functional even if the on-premises Active Directory Domain Services (AD DS) becomes temporarily unavailable. Which authentication method should you choose for Microsoft Entra Connect to meet this requirement?
- APass-through Authentication (PTA)
- BCloud Kerberos Trust
- CPassword Hash Synchronization (PHS)
- DFederation with AD FS
Show answer & explanationAnswer & explanation
Correct answer: C. Password Hash Synchronization (PHS)
Password Hash Synchronization (PHS) is the only authentication method that allows users to authenticate directly against Microsoft Entra ID even if on-premises AD DS is unavailable. This is because a hash of their password is synchronized and stored in Microsoft Entra ID.
Why the other options are wrong
- A. PTA requires on-premises AD DS availability for authentication.
- B. Cloud Kerberos Trust is for hybrid-joined devices to access on-premises resources, not an authentication method for cloud sign-in when on-premises AD is down.
- D. Federation with AD FS relies entirely on the availability of the on-premises AD FS infrastructure and AD DS.
Password Hash Synchronization (PHS)
A Microsoft Entra Connect authentication method where a cryptographic hash of a user's password hash is synchronized from on-premises Active Directory to Microsoft Entra ID.
- Provides a cloud-only authentication experience.
- Allows users to sign in even if on-premises AD DS is unavailable.
- Simplest to deploy and manage among hybrid authentication methods.
- Offers built-in high availability and disaster recovery for authentication.
Memory trick: PHS: Passwords Hashed, Safe in the Cloud.