Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDHard

A company is planning to deploy Microsoft Entra Connect to synchronize identities from its on-premises Active Directory Domain Services (AD DS) to Microsoft Entra ID. The on-premises environment consists of two separate, non-trusted Active Directory forests, ForestA.local and ForestB.local. Users in both forests need to be synchronized to a single Microsoft Entra tenant. Each forest has its own DNS infrastructure and network segments. You need to design the Microsoft Entra Connect deployment. Which deployment topology is most suitable for this scenario?

  1. AMultiple forests, multiple Microsoft Entra tenants
  2. BSingle forest, multiple Microsoft Entra tenants
  3. CMultiple forests, single Microsoft Entra tenant
  4. DSingle forest, single Microsoft Entra tenant
Show answer & explanation

Correct answer: C. Multiple forests, single Microsoft Entra tenant

The scenario describes two separate, non-trusted Active Directory forests needing to synchronize to a single Microsoft Entra tenant. The 'Multiple forests, single Microsoft Entra tenant' topology is designed precisely for this situation, where one or more Microsoft Entra Connect sync servers connect to multiple on-premises AD forests and provision objects to a single Microsoft Entra tenant.

Why the other options are wrong

  • A. This topology involves multiple AD forests synchronizing to multiple Microsoft Entra tenants, which is more complex than needed for a single target tenant.
  • B. This topology is for a single AD forest synchronizing to multiple Microsoft Entra tenants, which is the opposite of the requirement.
  • D. This topology is for a single AD forest, not two separate ones.

Microsoft Entra Connect Topology: Multiple Forests, Single Microsoft Entra Tenant

A Microsoft Entra Connect deployment topology where identities from multiple on-premises Active Directory forests (trusted or untrusted) are synchronized to a single Microsoft Entra ID tenant.

  • Supports multiple AD forests, even if they are not trusted.
  • Requires a single Microsoft Entra Connect sync server or multiple servers in staging mode.
  • Common in mergers, acquisitions, or complex enterprise environments.
  • Ensures a unified identity platform in Microsoft Entra ID.

Memory trick: Multiple Forests, Single Cloud: United in Entra.

More Implement and manage Microsoft Entra ID questions