Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium
A company is implementing Microsoft Entra Connect in a new hybrid environment. The security team has mandated that user password hashes must be synchronized to Microsoft Entra ID to enable cloud-only authentication scenarios, but also requires that users can sign in using their on-premises credentials. Which authentication method should be configured?
- APassword Hash Synchronization (PHS)
- BPass-through Authentication (PTA)
- CFederation with Active Directory Federation Services (AD FS)
- DSeamless single sign-on (SSO)
Show answer & explanationAnswer & explanation
Correct answer: A. Password Hash Synchronization (PHS)
Password Hash Synchronization (PHS) is the simplest method for enabling hybrid identity. It synchronizes a hash of the user's password hash from on-premises Active Directory to Microsoft Entra ID, allowing users to sign in with the same credentials. This fulfills the requirement for password hashes to be synchronized for cloud-only authentication while enabling sign-in with on-premises credentials.
Why the other options are wrong
- B. PTA does not synchronize password hashes; it validates passwords directly against on-premises AD.
- C. AD FS federation does not synchronize password hashes; it redirects authentication to on-premises AD FS.
- D. Seamless SSO is an enhancement for PHS/PTA, not an authentication method itself.
Password Hash Synchronization (PHS)
Password Hash Synchronization (PHS) is one of the sign-in methods for hybrid identity. It synchronizes a hash of a user's on-premises Active Directory password hash with Microsoft Entra ID.
- Simplest to implement for hybrid identity.
- Provides cloud authentication redundancy if on-premises AD is unavailable.
- Supports features like Microsoft Entra ID Protection and self-service password reset.
Memory trick: PHS is 'Password Hash Sync,' PTA 'Pass Through All,' AD FS 'Federates Directories Fully.'