Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A company is planning to implement Azure AD Connect to synchronize identities from its on-premises Active Directory to Azure AD. Due to strict security policies, the company requires that no password hashes are synchronized to Azure AD. However, users must still be able to use their on-premises credentials for single sign-on to cloud applications. Which authentication method should the company choose for Azure AD Connect to satisfy these requirements?
- ASeamless Single Sign-On (SSO)
- BPass-through Authentication (PTA)
- CFederation with AD FS
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: C. Federation with AD FS
Federation with AD FS (Active Directory Federation Services) allows users to authenticate directly against their on-premises Active Directory. Azure AD acts as a relying party, trusting AD FS to authenticate users. This means no password hashes are synchronized to Azure AD, and users authenticate using their existing on-premises credentials, fulfilling both requirements.
Why the other options are wrong
- A. Seamless SSO is a feature that works *with* PHS or PTA to provide a seamless sign-in experience, but it is not an authentication method itself that dictates where passwords reside.
- B. PTA validates user passwords directly against on-premises AD, but it still involves Azure AD receiving the password for validation, which might not meet the strictest interpretation of 'no password hashes' in Azure AD's storage.
- D. PHS synchronizes a hash of the user's password to Azure AD, which violates the 'no password hashes' requirement.
Federation with AD FS
An Azure AD Connect authentication method where users authenticate directly against an on-premises AD FS farm, and Azure AD trusts AD FS for identity verification.
- Authentication occurs entirely on-premises.
- No password hashes or passwords stored/synchronized to Azure AD.
- Requires deployment and management of AD FS infrastructure.
Memory trick: Hash, Pass, Federate for Identities.