Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium

A Microsoft 365 administrator is managing a tenant where users are currently authenticating directly to Azure AD. The company has a large on-premises Active Directory infrastructure and wants to implement single sign-on (SSO) for all Microsoft 365 services without synchronizing password hashes to Azure AD. The solution must also support advanced authentication policies from the on-premises environment. Which authentication method should the administrator choose?

  1. AFederation with Active Directory Federation Services (AD FS)
  2. BPassword Hash Synchronization (PHS)
  3. CPass-through Authentication (PTA)
  4. DAzure AD Join
Show answer & explanation

Correct answer: A. Federation with Active Directory Federation Services (AD FS)

Federation with AD FS allows for SSO using on-premises Active Directory credentials without synchronizing password hashes to Azure AD. It also enables the use of advanced on-premises authentication policies, directly satisfying all requirements.

Why the other options are wrong

  • B. PHS synchronizes a hash of the user's password to Azure AD, which violates the 'without synchronizing password hashes' requirement.
  • C. PTA validates passwords against on-premises AD but does not inherently support advanced on-premises authentication policies like AD FS does.
  • D. Azure AD Join is for device management and joining devices to Azure AD, not an authentication method for user identities in this context.

Federated Identity (AD FS)

An authentication method for Microsoft 365 that uses Active Directory Federation Services (AD FS) to enable single sign-on (SSO) by redirecting authentication requests to an on-premises AD FS server.

  • Passwords/hashes never leave the on-premises environment.
  • Supports advanced on-premises authentication policies (e.g., smart card, MFA from AD FS).
  • Requires on-premises infrastructure (AD FS servers, WAP).

Memory trick: AD FS is the on-prem bouncer, letting you into the cloud without giving up your secret handshake.

More Deploy and manage a Microsoft 365 tenant questions