Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company with a hybrid identity environment uses Azure AD Connect for synchronizing user accounts. They recently acquired another company that also has an on-premises Active Directory forest. Both forests need to synchronize users to the same Azure AD tenant. The acquired company's forest uses a different UPN suffix, and there's no trust between the forests. How should the company configure Azure AD Connect to support this scenario?

  1. AMigrate all users from the new forest to the existing forest before synchronization.
  2. BEstablish a two-way trust between the two Active Directory forests.
  3. CDeploy a second Azure AD Connect server in staging mode for the new forest.
  4. DInstall a single Azure AD Connect server and configure it to connect to both forests.
Show answer & explanation

Correct answer: D. Install a single Azure AD Connect server and configure it to connect to both forests.

Azure AD Connect can manage synchronization from multiple on-premises Active Directory forests to a single Azure AD tenant. It supports scenarios with no trust between forests and different UPN suffixes, making a single Azure AD Connect server capable of handling multiple forest connections.

Why the other options are wrong

  • A. Migrating users is a major undertaking that is often unnecessary and complex, especially when Azure AD Connect natively supports multi-forest synchronization without migration.
  • B. Establishing a trust is a complex task and not a prerequisite for Azure AD Connect to synchronize from multiple, untrusted forests to Azure AD.
  • C. Deploying a second Azure AD Connect server for the same tenant is generally not recommended unless for high availability (staging mode) or specific complex topologies, but a single server can handle multiple forests.

Azure AD Connect Multi-Forest Synchronization

The capability of Azure AD Connect to synchronize user and group identities from multiple on-premises Active Directory forests into a single Azure Active Directory tenant.

  • Supports forests with and without trust relationships.
  • Can handle different UPN suffixes.
  • Typically uses a single Azure AD Connect server (with optional staging server for HA/DR).

Memory trick: Connect all your forests to one cloud.

More Implement an identity management solution questions