Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company is implementing Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password hashes are securely synchronized to Azure AD while also allowing users to sign in with their existing on-premises credentials. Which authentication method should be configured in Azure AD Connect to meet these requirements?

  1. AFederation with AD FS
  2. BPass-through Authentication (PTA)
  3. CCloud-only authentication
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: D. Password Hash Synchronization (PHS)

Password Hash Synchronization (PHS) is the recommended method for synchronizing password hashes to Azure AD, allowing users to sign in with their on-premises credentials while providing cloud authentication capabilities.

Why the other options are wrong

  • A. Federation with AD FS offloads authentication to AD FS servers, which requires more complex infrastructure and management.
  • B. PTA validates passwords directly against on-premises AD, which can introduce dependency on on-premises infrastructure.
  • C. Cloud-only authentication is for users created directly in Azure AD and not synchronized from on-premises AD.

Password Hash Synchronization (PHS)

A method used by Azure AD Connect to synchronize a hash of the user's password hash from on-premises Active Directory to Azure AD.

  • Enables users to sign in to Azure AD services with their on-premises credentials.
  • Provides redundancy and resilience as authentication can occur even if on-premises AD is unavailable.
  • Simplest to implement for hybrid identity.

Memory trick: Connect choices: Password Hashes, Pass-through, or Federation's embrace.

More Implement an identity management solution questions