Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company is planning to deploy Azure AD Connect to synchronize their on-premises Active Directory with Azure AD. They want to implement Pass-through Authentication (PTA) to ensure that users authenticate against their on-premises domain controllers, but they also need to maintain authentication availability even if the on-premises domain controllers or network connectivity to them is temporarily unavailable. What specific component or configuration is essential to meet the high availability requirement for PTA?

  1. AInstall multiple Pass-through Authentication agents on different servers.
  2. BImplement Azure AD Domain Services (Azure AD DS) for redundancy.
  3. CDeploy multiple Azure AD Connect servers in staging mode.
  4. DConfigure Password Hash Synchronization (PHS) as a fallback mechanism.
Show answer & explanation

Correct answer: A. Install multiple Pass-through Authentication agents on different servers.

For high availability with Pass-through Authentication, you must deploy multiple PTA agents on separate servers. If one agent or its connection to on-premises AD fails, other agents can continue to process authentication requests.

Why the other options are wrong

  • B. Azure AD DS is a managed domain service, not a component for providing high availability for on-premises PTA.
  • C. Staging mode is for Azure AD Connect server redundancy (sync engine), not PTA agent redundancy.
  • D. PHS is an alternative authentication method, not a high-availability component for PTA itself. While it can be a fallback, the question asks for HA for PTA.

PTA Agent High Availability

To ensure high availability for Azure AD Pass-through Authentication, multiple authentication agents must be installed on separate servers in the on-premises environment.

  • Each agent registers with Azure AD and becomes active.
  • Azure AD automatically load-balances authentication requests.
  • Provides resilience against agent or network failures.

Memory trick: PTA agents are like guards at multiple gates, always one open.

More Implement an identity management solution questions