Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company recently acquired another business. They need to integrate the acquired company's on-premises Active Directory users into their existing Azure AD tenant. The acquired company's Active Directory has a different domain name and uses a separate forest. Which Azure AD Connect topology should be implemented to synchronize users from both forests into a single Azure AD tenant?

  1. AMultiple forests, multiple Azure AD tenants
  2. BMultiple forests, single Azure AD tenant
  3. CSingle forest, multiple Azure AD tenants
  4. DSingle forest, single Azure AD tenant
Show answer & explanation

Correct answer: B. Multiple forests, single Azure AD tenant

The scenario describes two distinct Active Directory forests (acquired company's and existing company's) needing to synchronize users to a single, existing Azure AD tenant. This configuration is known as 'Multiple forests, single Azure AD tenant' in Azure AD Connect topologies.

Why the other options are wrong

  • A. This topology involves multiple forests synchronizing to multiple Azure AD tenants, which is not the requirement of consolidating into a single Azure AD.
  • C. This topology is for a single on-premises forest synchronizing to multiple Azure AD tenants, which is not the requirement.
  • D. This topology is for a single on-premises forest synchronizing to one Azure AD tenant.

Azure AD Connect Multiple Forests, Single Azure AD Tenant

An Azure AD Connect deployment topology where identities from two or more on-premises Active Directory forests are synchronized into one Azure Active Directory tenant.

  • Supports various forest topologies (resource forest, account-resource forest).
  • Requires careful planning for identity matching.
  • Consolidates identities into a single cloud directory.

Memory trick: Many on-prem trees feeding one cloud.

More Manage Azure identities and governance questions