Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy

A company wants to synchronize user accounts from their on-premises Active Directory to Azure Active Directory. They have multiple distinct forests in their on-premises environment, and all users from these forests need to exist in a single Azure AD tenant. Which Azure AD Connect topology supports this requirement?

  1. ASingle forest, single Azure AD tenant
  2. BMultiple forests, single Azure AD tenant
  3. CMultiple forests, multiple Azure AD tenants
  4. DSingle forest, multiple Azure AD tenants
Show answer & explanation

Correct answer: B. Multiple forests, single Azure AD tenant

The 'Multiple forests, single Azure AD tenant' topology for Azure AD Connect is specifically designed to synchronize user accounts from several independent on-premises Active Directory forests into a single Azure Active Directory tenant, allowing for a unified identity management in the cloud.

Why the other options are wrong

  • A. This topology is for a single on-premises forest, not multiple.
  • C. This topology synchronizes multiple on-premises forests to multiple Azure AD tenants, also not the requirement.
  • D. This topology synchronizes one on-premises forest to multiple Azure AD tenants, which is not the requirement.

Azure AD Connect: Multiple Forests, Single Azure AD Tenant

An Azure AD Connect deployment topology where identities from two or more separate on-premises Active Directory forests are synchronized into a single Azure Active Directory tenant.

  • Consolidates identities from multiple forests into one cloud directory
  • Requires unique user identities across all forests
  • Supports various authentication methods (password hash sync, pass-through auth, federation)

Memory trick: Many on-prem trees, one cloud garden.

More Manage Azure identities and governance questions