Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A global manufacturing company with subsidiaries in multiple countries wants to implement Azure AD Connect. Each subsidiary has its own on-premises Active Directory forest, and all forests are independent (no trust relationships). The company needs to synchronize all user accounts from these disparate forests into a single Azure AD tenant. Which Azure AD Connect topology should they use?

  1. ASingle forest, multiple Azure AD tenants
  2. BSingle forest, single Azure AD tenant
  3. CMultiple forests, single Azure AD tenant
  4. DMultiple forests, multiple Azure AD tenants
Show answer & explanation

Correct answer: C. Multiple forests, single Azure AD tenant

The 'Multiple forests, single Azure AD tenant' topology is designed for scenarios where an organization has several independent Active Directory forests and wants to synchronize all users and objects from these forests into one unified Azure AD tenant.

Why the other options are wrong

  • A. This is for synchronizing one forest to multiple Azure AD tenants, which is not the requirement.
  • B. This is for a single on-premises AD forest.
  • D. This involves multiple forests and multiple tenants, which is more complex and not the core requirement here.

Azure AD Connect Multi-Forest Sync

An Azure AD Connect deployment topology that allows synchronization of identities from multiple independent on-premises Active Directory forests into a single Azure Active Directory tenant.

  • Supports various forest topologies (e.g., disjoint, trusted).
  • Requires unique source anchors across all forests.
  • Can use a single Azure AD Connect server or multiple staged servers.

Memory trick: Forests unite in the cloud, one tenant for all.

More Implement an identity management solution questions