Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company is implementing Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They want to ensure that user passwords synchronized to Azure AD are not stored in a readable format in the cloud and that a user's password change on-premises is immediately reflected in Azure AD. Which authentication method should they choose during the Azure AD Connect configuration to meet these requirements?

  1. APassword Hash Synchronization (PHS)
  2. BCloud-only user accounts
  3. CFederation with AD FS
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: A. Password Hash Synchronization (PHS)

Password Hash Synchronization (PHS) is the method that synchronizes a hash of the user's on-premises password to Azure AD, ensuring it's not stored in readable format. It also provides immediate reflection of password changes.

Why the other options are wrong

  • B. Cloud-only accounts are managed entirely in Azure AD and don't synchronize from on-premises AD.
  • C. Federation delegates authentication to on-premises AD FS, which doesn't store hashes in Azure AD but adds complexity.
  • D. PTA validates passwords directly against on-premises AD, but doesn't store hashes in Azure AD; it requires agents.

Password Hash Synchronization (PHS)

A method of identity synchronization where a cryptographic hash of a user's on-premises Active Directory password is synchronized to Azure AD. This allows users to sign in to cloud services with the same credentials.

  • Simplest to implement for hybrid identity.
  • Provides a resilient backup authentication method.
  • Passes password hashes, not actual passwords.

Memory trick: Connect, Authenticate, Synchronize: Choose Your Path Wisely.

More Implement an identity management solution questions