Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A company wants to synchronize user accounts from their on-premises Active Directory to Azure Active Directory. They have multiple distinct forests in their on-premises environment, and all users from these forests need to exist in a single Azure AD tenant. Which Azure AD Connect topology supports this requirement?
- ASingle forest, single Azure AD tenant
- BMultiple forests, single Azure AD tenant
- CMultiple forests, multiple Azure AD tenants
- DSingle forest, multiple Azure AD tenants
Show answer & explanationAnswer & explanation
Correct answer: B. Multiple forests, single Azure AD tenant
The 'Multiple forests, single Azure AD tenant' topology for Azure AD Connect is specifically designed to synchronize user accounts from several independent on-premises Active Directory forests into a single Azure Active Directory tenant, allowing for a unified identity management in the cloud.
Why the other options are wrong
- A. This topology is for a single on-premises forest, not multiple.
- C. This topology synchronizes multiple on-premises forests to multiple Azure AD tenants, also not the requirement.
- D. This topology synchronizes one on-premises forest to multiple Azure AD tenants, which is not the requirement.
Azure AD Connect: Multiple Forests, Single Azure AD Tenant
An Azure AD Connect deployment topology where identities from two or more separate on-premises Active Directory forests are synchronized into a single Azure Active Directory tenant.
- Consolidates identities from multiple forests into one cloud directory
- Requires unique user identities across all forests
- Supports various authentication methods (password hash sync, pass-through auth, federation)
Memory trick: Many on-prem trees, one cloud garden.