Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard
A company with a hybrid identity environment uses Azure AD Connect for synchronizing user accounts. They recently acquired another company that also has an on-premises Active Directory forest. Both forests need to synchronize users to the same Azure AD tenant. The acquired company's forest uses a different UPN suffix, and there's no trust between the forests. How should the company configure Azure AD Connect to support this scenario?
- AMigrate all users from the new forest to the existing forest before synchronization.
- BEstablish a two-way trust between the two Active Directory forests.
- CDeploy a second Azure AD Connect server in staging mode for the new forest.
- DInstall a single Azure AD Connect server and configure it to connect to both forests.
Show answer & explanationAnswer & explanation
Correct answer: D. Install a single Azure AD Connect server and configure it to connect to both forests.
Azure AD Connect can manage synchronization from multiple on-premises Active Directory forests to a single Azure AD tenant. It supports scenarios with no trust between forests and different UPN suffixes, making a single Azure AD Connect server capable of handling multiple forest connections.
Why the other options are wrong
- A. Migrating users is a major undertaking that is often unnecessary and complex, especially when Azure AD Connect natively supports multi-forest synchronization without migration.
- B. Establishing a trust is a complex task and not a prerequisite for Azure AD Connect to synchronize from multiple, untrusted forests to Azure AD.
- C. Deploying a second Azure AD Connect server for the same tenant is generally not recommended unless for high availability (staging mode) or specific complex topologies, but a single server can handle multiple forests.
Azure AD Connect Multi-Forest Synchronization
The capability of Azure AD Connect to synchronize user and group identities from multiple on-premises Active Directory forests into a single Azure Active Directory tenant.
- Supports forests with and without trust relationships.
- Can handle different UPN suffixes.
- Typically uses a single Azure AD Connect server (with optional staging server for HA/DR).
Memory trick: Connect all your forests to one cloud.