Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy
A client is migrating their on-premises Active Directory Domain Services (AD DS) to a hybrid identity solution with Azure Active Directory (Azure AD). They want to ensure that users continue to authenticate using their existing on-premises credentials for applications integrated with Azure AD, without storing password hashes in Azure AD. Which authentication method should be implemented?
- AFederation with Active Directory Federation Services (AD FS)
- BAzure AD Kerberos authentication
- CPass-through Authentication (PTA)
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: C. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud applications using the same passwords. It achieves this by validating users' passwords directly against their on-premises Active Directory, without storing password hashes in Azure AD.
Why the other options are wrong
- A. Federation with AD FS also uses on-premises authentication but involves a more complex infrastructure with AD FS servers, which is not the simplest method for this specific requirement.
- B. Azure AD Kerberos authentication is not a standard authentication method for hybrid identity solutions as described; Kerberos is primarily for on-premises AD.
- D. PHS synchronizes a hash of the user's password to Azure AD, which violates the requirement of not storing password hashes in Azure AD.
Azure AD Pass-through Authentication (PTA)
An Azure AD Connect authentication method that signs users in by validating their passwords directly against on-premises Active Directory.
- No password hashes stored in Azure AD.
- Requires lightweight agents on-premises.
- Provides a simple way to achieve hybrid identity.
Memory trick: PHS hashes, PTA passes, AD FS federates, Kerberos stays home.