Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard

A company is deploying Microsoft Entra Connect to synchronize identities from its on-premises Active Directory Domain Services (AD DS). The security team has mandated that user passwords should not be stored in Microsoft Entra ID, but users should still be able to sign in using their on-premises credentials. Additionally, the company already has an existing Active Directory Federation Services (AD FS) farm deployed and wants to leverage it for single sign-on (SSO) to Microsoft 365 and other Microsoft Entra ID-connected applications. Which Microsoft Entra Connect authentication method should you configure?

  1. ASeamless Single Sign-On (SSO)
  2. BPass-through Authentication (PTA)
  3. CFederation with AD FS
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: C. Federation with AD FS

The requirement to not store passwords in Microsoft Entra ID, use on-premises credentials, and leverage an *existing AD FS farm* points directly to Federation with AD FS. This method redirects authentication requests to the on-premises AD FS, which then authenticates against AD DS.

Why the other options are wrong

  • A. Seamless SSO is a feature that can be enabled with PHS or PTA for a better user experience, but it's not an authentication method itself for this scenario, especially with an existing AD FS farm.
  • B. PTA agents validate passwords against on-premises AD DS, but the scenario explicitly mentions leveraging an *existing AD FS farm* for SSO, which PTA does not use.
  • D. PHS stores password hashes in Microsoft Entra ID, violating the 'not stored in Microsoft Entra ID' requirement.

Microsoft Entra Connect Federation (AD FS)

An authentication method where Microsoft Entra ID redirects authentication requests to an on-premises Active Directory Federation Services (AD FS) farm, which then authenticates users against Active Directory.

  • Leverages existing AD FS infrastructure.
  • Passwords never leave the on-premises network.
  • Provides advanced authentication features (e.g., smart card authentication, third-party MFA).
  • Requires more infrastructure and management overhead than PHS or PTA.

Memory trick: Federation: Focus on Existing AD FS.

More Implement and manage Microsoft Entra ID questions