A company is migrating its email services to Exchange Online. They have an existing on-premises Active Directory and want to synchronize user accounts to Azure AD, allowing users to use their existing on-premises credentials to access Microsoft 365 services. The company does NOT want to deploy additional servers for identity federation. Which authentication method should the administrator implement?
- AActive Directory Federation Services (AD FS)
- BCloud-only authentication
- CPassword Hash Synchronization (PHS)
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: D. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) meets the requirements by allowing users to sign in to Microsoft 365 services using their on-premises Active Directory credentials, without deploying additional servers like AD FS. It achieves this by installing a lightweight agent on-premises that validates passwords directly against the on-premises AD.
Why the other options are wrong
- A. AD FS requires deploying additional servers for identity federation, which the company explicitly wants to avoid.
- B. Cloud-only authentication requires users to have separate credentials managed purely in Azure AD, which contradicts the requirement to use existing on-premises credentials.
- C. PHS synchronizes a hash of the password to Azure AD, meaning the password itself is not validated against on-prem AD in real-time, which might not fully align with 'using their existing on-premises credentials' in the strictest sense of real-time validation.
Azure AD Pass-through Authentication (PTA)
Azure AD Pass-through Authentication (PTA) is a free feature that allows users to sign in to both on-premises and cloud-based applications using the same password. It achieves this by validating users' passwords directly against their on-premises Active Directory without storing hashes in Azure AD or requiring federation servers.
- Uses lightweight agents installed on-premises for password validation.
- No federation servers (like AD FS) are required.
- Provides a seamless single sign-on experience.
- User passwords are never stored in the cloud in any form.
Memory trick: On-prem credentials, no new servers? Pass-through is the answer, no more queries!