Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A company is migrating its email services to Exchange Online. They have an existing on-premises Active Directory and want to synchronize user accounts to Azure AD, allowing users to use their existing on-premises credentials to access Microsoft 365 services. The company does NOT want to deploy additional servers for identity federation. Which authentication method should the administrator implement?

  1. AActive Directory Federation Services (AD FS)
  2. BCloud-only authentication
  3. CPassword Hash Synchronization (PHS)
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: D. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) meets the requirements by allowing users to sign in to Microsoft 365 services using their on-premises Active Directory credentials, without deploying additional servers like AD FS. It achieves this by installing a lightweight agent on-premises that validates passwords directly against the on-premises AD.

Why the other options are wrong

  • A. AD FS requires deploying additional servers for identity federation, which the company explicitly wants to avoid.
  • B. Cloud-only authentication requires users to have separate credentials managed purely in Azure AD, which contradicts the requirement to use existing on-premises credentials.
  • C. PHS synchronizes a hash of the password to Azure AD, meaning the password itself is not validated against on-prem AD in real-time, which might not fully align with 'using their existing on-premises credentials' in the strictest sense of real-time validation.

Azure AD Pass-through Authentication (PTA)

Azure AD Pass-through Authentication (PTA) is a free feature that allows users to sign in to both on-premises and cloud-based applications using the same password. It achieves this by validating users' passwords directly against their on-premises Active Directory without storing hashes in Azure AD or requiring federation servers.

  • Uses lightweight agents installed on-premises for password validation.
  • No federation servers (like AD FS) are required.
  • Provides a seamless single sign-on experience.
  • User passwords are never stored in the cloud in any form.

Memory trick: On-prem credentials, no new servers? Pass-through is the answer, no more queries!

More Deploy and manage a Microsoft 365 tenant questions