Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A global organization uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company uses an on-premises Active Directory Domain Services (AD DS) environment. The organization wants to integrate the acquired company's users into its existing Azure AD tenant for single sign-on (SSO) to Microsoft 365 and other cloud applications, while ensuring that password hashes are synchronized to Azure AD. Which Azure AD Connect synchronization option should be implemented?
- ACloud Sync (Azure AD Connect cloud provisioning)
- BPassword Hash Synchronization (PHS)
- CFederation with Active Directory Federation Services (AD FS)
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: B. Password Hash Synchronization (PHS)
Password Hash Synchronization (PHS) is the simplest method to enable hybrid identity with Azure AD. It synchronizes a hash of the user's on-premises password hash to Azure AD, allowing users to sign in with the same credentials. This meets the requirement of synchronizing password hashes and enabling SSO to cloud applications without requiring on-premises infrastructure to be always available for authentication requests.
Why the other options are wrong
- A. Cloud Sync is an alternative to Azure AD Connect for provisioning users, but PHS is the specific synchronization option for password hashes within Azure AD Connect.
- C. Federation with AD FS keeps authentication entirely on-premises and does not synchronize password hashes to Azure AD.
- D. PTA keeps passwords on-premises and requires always-on agents, which is not what 'synchronizing password hashes' implies.
Password Hash Synchronization (PHS)
A hybrid identity method where a hash of the on-premises AD password hash is synchronized to Azure AD, allowing users to sign in with the same credentials.
- Simplest to implement and deploy.
- Provides high availability and resilience as authentication can occur even if on-premises AD is down.
- Enables SSO to cloud applications.
- Does not store actual passwords in Azure AD, only cryptographically strong hashes of hashes.
Memory trick: PHS: 'Password Hashes Synchronized' to cloud for easy access.