Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy

A company is implementing Azure AD Connect for the first time to synchronize identities from their on-premises Active Directory to Azure AD. They have a strict security policy requiring that no user passwords ever leave the on-premises environment in any form. Which authentication method should they choose during the Azure AD Connect configuration to meet this requirement?

  1. APassword Hash Synchronization (PHS)
  2. BCloud-only user accounts
  3. CFederation with AD FS
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: D. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) is designed to validate user passwords directly against the on-premises Active Directory. This ensures that passwords never leave the on-premises environment, fulfilling the company's security requirement.

Why the other options are wrong

  • A. PHS synchronizes a hash of the password, which, while not the plain-text password, still transmits a derivative to Azure AD.
  • B. Cloud-only user accounts would mean users are managed solely in Azure AD, which doesn't use the on-premises Active Directory for authentication.
  • C. Federation with AD FS involves setting up a separate identity provider, which is more complex and not strictly necessary for the password requirement.

Pass-through Authentication (PTA)

An Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory without storing them in Azure AD.

  • Passwords never leave the on-premises network.
  • Requires lightweight agents to be installed on-premises.
  • Provides a seamless sign-in experience (SSO).

Memory trick: PHS is 'hash it and stash it', PTA is 'pass it through, no view', AD FS is 'federate and delegate'.

More Implement an identity management solution questions