Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A global company has multiple on-premises Active Directory forests (Forest A, Forest B, Forest C) with non-routable UPN suffixes. They want to consolidate identity management by synchronizing all user accounts from these forests into a single Azure AD tenant. Users must be able to sign in to Azure AD with their on-premises credentials. What is the minimum number of Azure AD Connect servers required to achieve this, assuming high availability is not a primary concern for the initial setup?

  1. AOne Azure AD Connect server.
  2. BThree Azure AD Connect servers.
  3. CTwo Azure AD Connect servers.
  4. DA dedicated Azure AD Connect server for each forest.
Show answer & explanation

Correct answer: A. One Azure AD Connect server.

A single Azure AD Connect server can connect to multiple on-premises Active Directory forests simultaneously and synchronize them to a single Azure AD tenant. This is a common multi-forest scenario.

Why the other options are wrong

  • B. Three servers are unnecessary for basic multi-forest synchronization without high availability.
  • C. Two servers might be used for redundancy (staging mode) but aren't strictly required for multi-forest sync.
  • D. One server can handle multiple forests; a dedicated server per forest is not a requirement unless there are specific network or security isolations.

Azure AD Connect Multi-Forest Sync

Azure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests to a single Azure AD tenant, enabling a unified identity experience.

  • Single Azure AD Connect server can connect to multiple forests.
  • Allows different topologies (e.g., full mesh, account-resource).
  • Requires network connectivity between Connect server and all forests.

Memory trick: One Connect server can wrangle all your forest identities into the cloud.

More Implement an identity management solution questions