Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsMedium

A Microsoft 365 administrator is implementing a new identity management strategy. They need to synchronize user accounts and passwords from their on-premises Active Directory to Azure Active Directory (Azure AD) to enable single sign-on for Microsoft 365 services. Which tool is specifically used for this purpose?

  1. AAzure AD Identity Protection
  2. BAzure AD Connect
  3. CAzure AD B2B collaboration
  4. DMicrosoft Intune
Show answer & explanation

Correct answer: B. Azure AD Connect

Azure AD Connect is the primary tool used to synchronize on-premises Active Directory identities (users, groups, contacts) and their password hashes or perform pass-through authentication to Azure Active Directory, enabling a hybrid identity environment and single sign-on for Microsoft 365.

Why the other options are wrong

  • A. Azure AD Identity Protection detects and remediates identity-based risks, it does not synchronize user accounts.
  • C. Azure AD B2B collaboration allows external users to access your resources, it's not for synchronizing internal on-premises users.
  • D. Microsoft Intune is for mobile device and application management, not identity synchronization.

Azure AD Connect

A Microsoft tool designed to synchronize identities between on-premises Active Directory and Azure Active Directory.

  • Enables hybrid identity for Microsoft 365 and other Azure services
  • Supports password hash synchronization, pass-through authentication, and federation
  • Synchronizes users, groups, and contacts
  • Crucial for single sign-on (SSO) experience

Memory trick: To 'connect' on-premises to Azure AD, use Azure AD 'Connect'.

More Describe core Microsoft 365 services and concepts questions