Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A security architect is designing an authentication solution for a new internal web application. The application will be accessed by employees only, and all employees are managed in Azure AD. The architect wants to implement a solution where users are automatically signed in when they access the application from a corporate-joined device within the corporate network, without explicitly entering credentials. If they access from outside the corporate network or from a non-corporate device, they should be prompted for MFA. Which combination of Azure AD features should the architect recommend?

  1. AFederation with AD FS + Conditional Access
  2. BPass-through Authentication (PTA) + Seamless SSO + Conditional Access
  3. CPassword Hash Synchronization (PHS) + Seamless SSO + Conditional Access
  4. DCloud-only identities + Conditional Access
Show answer & explanation

Correct answer: B. Pass-through Authentication (PTA) + Seamless SSO + Conditional Access

Pass-through Authentication (PTA) allows users to sign in to Azure AD using their on-premises passwords, which are validated directly against on-premises Active Directory. When combined with Seamless SSO, it provides a truly seamless experience for corporate-joined devices within the corporate network. Conditional Access can then be used to enforce MFA for users accessing from outside the corporate network or non-corporate devices. PHS + Seamless SSO would also work, but PTA is often preferred for organizations that want to keep authentication entirely on-premises while avoiding AD FS complexity.

Why the other options are wrong

  • A. Federation with AD FS can provide similar functionality but introduces the complexity of managing an AD FS infrastructure, which PTA aims to avoid while achieving similar security goals.
  • C. PHS + Seamless SSO + Conditional Access is a viable option, but PTA + Seamless SSO is often chosen when organizations prefer direct on-premises password validation without syncing hashes.
  • D. Cloud-only identities would mean users don't use their on-premises credentials, violating the implied desire to leverage existing on-premises identity infrastructure for a seamless experience.

PTA + Seamless SSO + Conditional Access

A common Azure AD authentication architecture that provides seamless sign-on for corporate users on trusted networks/devices and enforces adaptive access policies like MFA for others.

  • PTA validates passwords against on-premises AD.
  • Seamless SSO provides automatic sign-in on corporate networks/devices.
  • Conditional Access enforces policies based on context (location, device, risk).

Memory trick: PTA Seamlessly Protects with CA.

More Implement an authentication and access management solution questions