Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard
A Microsoft 365 administrator is configuring a new tenant. They need to ensure that all user identities are managed by their on-premises Active Directory and synchronized to Azure AD. Users should authenticate against the on-premises directory when accessing Microsoft 365 services. Which identity model should the administrator implement?
- ACloud-only identity
- BFederated identity with Active Directory Federation Services (AD FS)
- CSynchronized identity with Pass-through Authentication (PTA)
- DSynchronized identity with Password Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: B. Federated identity with Active Directory Federation Services (AD FS)
Federated identity with AD FS allows users to authenticate directly against their on-premises Active Directory when accessing Microsoft 365 services. This model ensures that identity management remains entirely on-premises while synchronizing user objects to Azure AD.
Why the other options are wrong
- A. Cloud-only identity means users are managed directly in Azure AD, not on-premises.
- C. PTA agents forward authentication requests to on-premises AD, but AD FS is the dedicated federation service for direct on-premises authentication.
- D. PHS synchronizes password hashes to Azure AD, allowing users to authenticate against Azure AD, not directly on-premises.
Federated Identity (AD FS)
An identity model where user authentication requests for cloud services are redirected to an on-premises identity provider (like AD FS), which then authenticates the user against the on-premises Active Directory.
- Authentication occurs on-premises.
- Requires AD FS infrastructure.
- Provides single sign-on (SSO) experience.
- Supports advanced authentication policies defined on-premises.
Memory trick: Federated identity is like a border checkpoint: your on-premises AD is the authority stamping your passport for cloud access.