Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A global manufacturing company with subsidiaries in multiple countries wants to implement a hybrid identity solution using Azure AD Connect. Each subsidiary has its own on-premises Active Directory forest, and these forests are not mutually trusted. The company needs to synchronize user identities from all these forests into a single Azure AD tenant. What is the minimum number of Azure AD Connect servers required to achieve this configuration?

  1. AOne Azure AD Connect server per forest
  2. BTwo Azure AD Connect servers
  3. CThree Azure AD Connect servers
  4. DOne Azure AD Connect server
Show answer & explanation

Correct answer: D. One Azure AD Connect server

Azure AD Connect can connect to multiple on-premises Active Directory forests, even if they are not mutually trusted, and synchronize identities to a single Azure AD tenant. Therefore, only one Azure AD Connect server is required.

Why the other options are wrong

  • A. While possible, it's not the minimum requirement; a single server can connect to multiple forests.
  • B. Two servers are not strictly necessary for this scenario; one can handle multiple forests.
  • C. Three servers are excessive for this scenario.

Azure AD Connect Multi-Forest Sync

Azure AD Connect's capability to synchronize identities from multiple on-premises Active Directory forests into a single Azure AD tenant.

  • Forests can be trusted or untrusted.
  • Requires only one Azure AD Connect server for multiple forests.
  • Supports various topologies, including multiple forests to a single Azure AD tenant.

Memory trick: Topologies: Single forest, multiple forests, or staging for sync.

More Implement an identity management solution questions