Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium

A Microsoft 365 administrator is setting up a new tenant for an organization. They need to ensure that all user identities are synchronized from their on-premises Active Directory to Azure Active Directory, enabling single sign-on for Microsoft 365 services. Which tool is primarily used for this synchronization?

  1. AAzure AD Connect
  2. BMicrosoft Graph
  3. CMicrosoft Intune
  4. DMicrosoft 365 admin center
Show answer & explanation

Correct answer: A. Azure AD Connect

Azure AD Connect is the dedicated Microsoft tool for synchronizing user, group, and contact information from an on-premises Active Directory to Azure Active Directory, which is essential for enabling single sign-on to Microsoft 365 services.

Why the other options are wrong

  • B. Microsoft Graph is a developer API for programmatic access to Microsoft 365 data, not a tool for identity synchronization.
  • C. Microsoft Intune is for mobile device and application management, not for synchronizing on-premises identities to Azure AD.
  • D. The Microsoft 365 admin center is for managing the Microsoft 365 tenant, but it doesn't perform the actual synchronization of on-premises AD objects; it relies on Azure AD Connect for that function.

Azure AD Connect

A Microsoft tool designed to connect an on-premises identity infrastructure to Azure Active Directory.

  • Synchronizes users, groups, and contact objects from on-premises AD to Azure AD
  • Enables single sign-on (SSO) for Microsoft 365 services
  • Supports various authentication methods like password hash synchronization and pass-through authentication

Memory trick: Connect on-prem to Azure, keep identities true.

More Describe core Microsoft 365 services and concepts questions