Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company recently acquired another business. Both companies use separate on-premises Active Directory forests. The acquired company's users need to access resources in the acquiring company's Azure Active Directory (Azure AD) tenant. The acquiring company wants to consolidate identity management into a single Azure AD tenant while keeping both on-premises Active Directory forests operational for their respective domains. Which Azure AD Connect configuration supports this scenario?

  1. ASingle forest, single Azure AD tenant
  2. BMultiple forests, multiple Azure AD tenants
  3. CSingle forest, multiple Azure AD tenants
  4. DMultiple forests, single Azure AD tenant
Show answer & explanation

Correct answer: D. Multiple forests, single Azure AD tenant

Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests to a single Azure AD tenant. This is a common scenario during mergers and acquisitions, allowing users from different on-premises domains to authenticate against a unified Azure AD tenant.

Why the other options are wrong

  • A. This describes a typical setup for a single company, not for merging two companies with separate on-premises forests.
  • B. This would maintain separate identity management systems, contrary to the goal of consolidating into a single Azure AD tenant.
  • C. This scenario is generally not supported for synchronization from a single forest to multiple tenants for user objects. It's more complex and usually involves specific filtering.

Azure AD Connect: Multiple Forests

Azure AD Connect can synchronize user identities from multiple disparate on-premises Active Directory forests into a single Azure Active Directory tenant.

  • Supports various topologies for mergers/acquisitions.
  • Consolidates identities into one Azure AD.
  • Requires careful planning for identity matching.

Memory trick: Many forests, one cloud, all connected.

More Manage Azure identities and governance questions