A security architect is designing an authentication solution for a new internal web application. The application will be accessed by employees only, and all employees are managed in Azure AD. The architect wants to implement a solution where users are automatically signed in when they access the application from a corporate-joined device within the corporate network, without explicitly entering credentials. If they access from outside the corporate network or from a non-corporate device, they should be prompted for MFA. Which combination of Azure AD features should the architect recommend?
- AFederation with AD FS + Conditional Access
- BPass-through Authentication (PTA) + Seamless SSO + Conditional Access
- CPassword Hash Synchronization (PHS) + Seamless SSO + Conditional Access
- DCloud-only identities + Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: B. Pass-through Authentication (PTA) + Seamless SSO + Conditional Access
Pass-through Authentication (PTA) allows users to sign in to Azure AD using their on-premises passwords, which are validated directly against on-premises Active Directory. When combined with Seamless SSO, it provides a truly seamless experience for corporate-joined devices within the corporate network. Conditional Access can then be used to enforce MFA for users accessing from outside the corporate network or non-corporate devices. PHS + Seamless SSO would also work, but PTA is often preferred for organizations that want to keep authentication entirely on-premises while avoiding AD FS complexity.
Why the other options are wrong
- A. Federation with AD FS can provide similar functionality but introduces the complexity of managing an AD FS infrastructure, which PTA aims to avoid while achieving similar security goals.
- C. PHS + Seamless SSO + Conditional Access is a viable option, but PTA + Seamless SSO is often chosen when organizations prefer direct on-premises password validation without syncing hashes.
- D. Cloud-only identities would mean users don't use their on-premises credentials, violating the implied desire to leverage existing on-premises identity infrastructure for a seamless experience.
PTA + Seamless SSO + Conditional Access
A common Azure AD authentication architecture that provides seamless sign-on for corporate users on trusted networks/devices and enforces adaptive access policies like MFA for others.
- PTA validates passwords against on-premises AD.
- Seamless SSO provides automatic sign-in on corporate networks/devices.
- Conditional Access enforces policies based on context (location, device, risk).
Memory trick: PTA Seamlessly Protects with CA.