Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Medium
A company has a hybrid Azure AD environment. All user accounts are synchronized from on-premises Active Directory. You need to ensure that when a user's account is deleted from the on-premises Active Directory, their corresponding Azure AD account is also automatically deleted, and their enrolled devices are deprovisioned from Intune. Which component is responsible for synchronizing these deletions from on-premises to Azure AD?
- AAzure AD Connect
- BMicrosoft Defender for Identity
- CAzure AD Connect Health
- DAzure AD Domain Services
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect
Azure AD Connect is the tool responsible for synchronizing identities between on-premises Active Directory and Azure Active Directory. This includes user accounts, groups, and the synchronization of changes like deletions.
Why the other options are wrong
- B. Microsoft Defender for Identity is a security solution that identifies advanced threats and compromised identities, not a synchronization tool.
- C. Azure AD Connect Health monitors the health and activity of identity components, but does not perform synchronization itself.
- D. Azure AD Domain Services provides managed domain services in Azure, primarily for lift-and-shift applications, not for synchronizing on-premises AD to Azure AD.
Azure AD Connect
A Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes user identities, groups, and device objects between on-premises Active Directory and Azure Active Directory.
- Handles synchronization of user accounts, groups, and device objects.
- Supports password hash synchronization, pass-through authentication, and federation.
- Essential for hybrid identity scenarios, including object lifecycle management (creation, updates, deletions).
Memory trick: Connect the halves, keep identities in sync, no user left behind.