Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is implementing Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They want to ensure that user passwords synchronized to Azure AD are not stored in a readable format in the cloud and that a user's password change on-premises is immediately reflected in Azure AD. Which authentication method should they choose during the Azure AD Connect configuration to meet these requirements?
- APassword Hash Synchronization (PHS)
- BCloud-only user accounts
- CFederation with AD FS
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: A. Password Hash Synchronization (PHS)
Password Hash Synchronization (PHS) is the method that synchronizes a hash of the user's on-premises password to Azure AD, ensuring it's not stored in readable format. It also provides immediate reflection of password changes.
Why the other options are wrong
- B. Cloud-only accounts are managed entirely in Azure AD and don't synchronize from on-premises AD.
- C. Federation delegates authentication to on-premises AD FS, which doesn't store hashes in Azure AD but adds complexity.
- D. PTA validates passwords directly against on-premises AD, but doesn't store hashes in Azure AD; it requires agents.
Password Hash Synchronization (PHS)
A method of identity synchronization where a cryptographic hash of a user's on-premises Active Directory password is synchronized to Azure AD. This allows users to sign in to cloud services with the same credentials.
- Simplest to implement for hybrid identity.
- Provides a resilient backup authentication method.
- Passes password hashes, not actual passwords.
Memory trick: Connect, Authenticate, Synchronize: Choose Your Path Wisely.