Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

A company uses Azure Active Directory (Azure AD) to manage its user accounts. They recently acquired another business, and both companies use separate on-premises Active Directory forests. The goal is to synchronize user accounts from both on-premises forests into a single Azure AD tenant. What is the recommended Azure AD Connect deployment topology for this scenario?

  1. AMultiple forests, single Azure AD tenant
  2. BSingle forest, multiple Azure AD tenants
  3. CSingle forest, single Azure AD tenant
  4. DMultiple forests, multiple Azure AD tenants
Show answer & explanation

Correct answer: A. Multiple forests, single Azure AD tenant

The scenario describes two separate on-premises Active Directory forests needing to synchronize into one Azure AD tenant. The 'Multiple forests, single Azure AD tenant' topology is designed precisely for this situation.

Why the other options are wrong

  • B. This topology is not supported for a single Azure AD Connect server and is generally not recommended.
  • C. This topology is for a single on-premises forest, not two separate ones.
  • D. This topology involves multiple Azure AD tenants, but the requirement is for a single Azure AD tenant.

Azure AD Connect: Multiple Forests, Single Azure AD Tenant

An Azure AD Connect deployment topology where user identities from multiple separate on-premises Active Directory forests are synchronized to a single Azure Active Directory tenant.

  • Common in mergers and acquisitions.
  • Requires careful planning for identity matching.
  • Can use a single Azure AD Connect sync server.

Memory trick: Many trees, one cloud: Multiple forests, single Azure AD.

More Manage Azure identities and governance questions