Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator is configuring a new tenant. They need to ensure that all user identities are managed by their on-premises Active Directory and synchronized to Azure AD. Users should authenticate against the on-premises directory when accessing Microsoft 365 services. Which identity model should the administrator implement?

  1. ACloud-only identity
  2. BFederated identity with Active Directory Federation Services (AD FS)
  3. CSynchronized identity with Pass-through Authentication (PTA)
  4. DSynchronized identity with Password Hash Synchronization (PHS)
Show answer & explanation

Correct answer: B. Federated identity with Active Directory Federation Services (AD FS)

Federated identity with AD FS allows users to authenticate directly against their on-premises Active Directory when accessing Microsoft 365 services. This model ensures that identity management remains entirely on-premises while synchronizing user objects to Azure AD.

Why the other options are wrong

  • A. Cloud-only identity means users are managed directly in Azure AD, not on-premises.
  • C. PTA agents forward authentication requests to on-premises AD, but AD FS is the dedicated federation service for direct on-premises authentication.
  • D. PHS synchronizes password hashes to Azure AD, allowing users to authenticate against Azure AD, not directly on-premises.

Federated Identity (AD FS)

An identity model where user authentication requests for cloud services are redirected to an on-premises identity provider (like AD FS), which then authenticates the user against the on-premises Active Directory.

  • Authentication occurs on-premises.
  • Requires AD FS infrastructure.
  • Provides single sign-on (SSO) experience.
  • Supports advanced authentication policies defined on-premises.

Memory trick: Federated identity is like a border checkpoint: your on-premises AD is the authority stamping your passport for cloud access.

More Deploy and manage a Microsoft 365 tenant questions