Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium
A company recently acquired another business. They need to integrate the acquired company's on-premises Active Directory users into their existing Azure AD tenant. The acquired company's Active Directory has a different domain name and uses a separate forest. Which Azure AD Connect topology should be implemented to synchronize users from both forests into a single Azure AD tenant?
- AMultiple forests, multiple Azure AD tenants
- BMultiple forests, single Azure AD tenant
- CSingle forest, multiple Azure AD tenants
- DSingle forest, single Azure AD tenant
Show answer & explanationAnswer & explanation
Correct answer: B. Multiple forests, single Azure AD tenant
The scenario describes two distinct Active Directory forests (acquired company's and existing company's) needing to synchronize users to a single, existing Azure AD tenant. This configuration is known as 'Multiple forests, single Azure AD tenant' in Azure AD Connect topologies.
Why the other options are wrong
- A. This topology involves multiple forests synchronizing to multiple Azure AD tenants, which is not the requirement of consolidating into a single Azure AD.
- C. This topology is for a single on-premises forest synchronizing to multiple Azure AD tenants, which is not the requirement.
- D. This topology is for a single on-premises forest synchronizing to one Azure AD tenant.
Azure AD Connect Multiple Forests, Single Azure AD Tenant
An Azure AD Connect deployment topology where identities from two or more on-premises Active Directory forests are synchronized into one Azure Active Directory tenant.
- Supports various forest topologies (resource forest, account-resource forest).
- Requires careful planning for identity matching.
- Consolidates identities into a single cloud directory.
Memory trick: Many on-prem trees feeding one cloud.