Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium
A Microsoft 365 administrator is setting up a new tenant for an organization. They need to ensure that all user identities are synchronized from their on-premises Active Directory to Azure Active Directory, enabling single sign-on for Microsoft 365 services. Which tool is primarily used for this synchronization?
- AAzure AD Connect
- BMicrosoft Graph
- CMicrosoft Intune
- DMicrosoft 365 admin center
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect
Azure AD Connect is the dedicated Microsoft tool for synchronizing user, group, and contact information from an on-premises Active Directory to Azure Active Directory, which is essential for enabling single sign-on to Microsoft 365 services.
Why the other options are wrong
- B. Microsoft Graph is a developer API for programmatic access to Microsoft 365 data, not a tool for identity synchronization.
- C. Microsoft Intune is for mobile device and application management, not for synchronizing on-premises identities to Azure AD.
- D. The Microsoft 365 admin center is for managing the Microsoft 365 tenant, but it doesn't perform the actual synchronization of on-premises AD objects; it relies on Azure AD Connect for that function.
Azure AD Connect
A Microsoft tool designed to connect an on-premises identity infrastructure to Azure Active Directory.
- Synchronizes users, groups, and contact objects from on-premises AD to Azure AD
- Enables single sign-on (SSO) for Microsoft 365 services
- Supports various authentication methods like password hash synchronization and pass-through authentication
Memory trick: Connect on-prem to Azure, keep identities true.