Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity model using Azure AD Connect. They have a strict security requirement that user password hashes must NEVER be synchronized to Azure AD. However, users must still be able to sign in to both on-premises and cloud applications using the same credentials. Which authentication method should the client configure in Azure AD Connect?
- APassword Hash Synchronization (PHS)
- BFederation with AD FS
- CCloud-only authentication
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: B. Federation with AD FS
Federation with AD FS keeps all authentication requests on-premises, meaning no password hashes (or even the passwords themselves) ever leave the on-premises environment. Azure AD redirects authentication requests to AD FS, which validates against the local AD DS.
Why the other options are wrong
- A. PHS synchronizes password hashes to Azure AD, which violates the requirement.
- C. Cloud-only authentication requires users to have separate credentials or be managed solely in Azure AD, which doesn't meet the 'same credentials' and 'on-premises AD DS' requirements.
- D. PTA agents validate passwords directly against on-premises AD DS, but it still involves the password being validated by an Azure AD component (PTA agent) that receives it from Azure AD, even if not stored. The 'never synchronized' implies no hashes leaving the on-prem AD DS boundary.
Federation with AD FS (Hybrid Identity)
Federation with Active Directory Federation Services (AD FS) in a hybrid identity model means that Azure AD delegates authentication to an on-premises AD FS server. This allows users to sign in using their on-premises credentials without their passwords or hashes ever leaving the on-premises environment.
- Azure AD redirects authentication requests to AD FS.
- AD FS validates credentials against on-premises AD DS.
- Azure AD receives a security token, not credentials.
- Requires more infrastructure (AD FS servers) than PHS or PTA.
Memory trick: Hybrid authentication: Where is the password validated?