Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is using Azure AD Connect to synchronize user accounts from their on-premises Active Directory. They want to ensure that if a user's password is changed on-premises, it is immediately reflected in Azure AD, allowing cloud applications to use the new password without delay. Which synchronization feature should be enabled and configured?

  1. APass-through Authentication (PTA)
  2. BFederation with AD FS
  3. CPassword Hash Synchronization (PHS)
  4. DSeamless Single Sign-On (SSO)
Show answer & explanation

Correct answer: C. Password Hash Synchronization (PHS)

Password Hash Synchronization (PHS) is the most common method for synchronizing passwords from on-premises Active Directory to Azure AD. It immediately hashes and synchronizes password changes, ensuring consistency and enabling cloud applications to use the new password.

Why the other options are wrong

  • A. Pass-through Authentication (PTA) validates passwords directly against on-premises AD, but it doesn't store the password hash in Azure AD for cloud-only authentication.
  • B. Federation with AD FS delegates authentication to AD FS, meaning Azure AD doesn't store or validate the password itself.
  • D. Seamless Single Sign-On (SSO) provides a seamless sign-in experience but is not a password synchronization method itself; it works with PHS or PTA.

Password Hash Synchronization (PHS)

A method of hybrid identity that synchronizes a hash of the user's password hash from on-premises Active Directory to Azure AD, enabling users to authenticate directly against Azure AD.

  • Simplest to implement, provides cloud authentication.
  • Password changes are synchronized quickly.
  • Offers redundancy if on-premises AD is unavailable (for cloud apps).

Memory trick: PHS: Passwords Hashed, Swiftly Synced.

More Implement an identity management solution questions