Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is implementing Azure AD Connect for the first time to synchronize identities from their on-premises Active Directory to Azure AD. They have a strict security policy requiring that no user passwords ever leave the on-premises environment in any form. Which authentication method should they choose during the Azure AD Connect configuration to meet this requirement?
- APassword Hash Synchronization (PHS)
- BCloud-only user accounts
- CFederation with AD FS
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: D. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) is designed to validate user passwords directly against the on-premises Active Directory. This ensures that passwords never leave the on-premises environment, fulfilling the company's security requirement.
Why the other options are wrong
- A. PHS synchronizes a hash of the password, which, while not the plain-text password, still transmits a derivative to Azure AD.
- B. Cloud-only user accounts would mean users are managed solely in Azure AD, which doesn't use the on-premises Active Directory for authentication.
- C. Federation with AD FS involves setting up a separate identity provider, which is more complex and not strictly necessary for the password requirement.
Pass-through Authentication (PTA)
An Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory without storing them in Azure AD.
- Passwords never leave the on-premises network.
- Requires lightweight agents to be installed on-premises.
- Provides a seamless sign-in experience (SSO).
Memory trick: PHS is 'hash it and stash it', PTA is 'pass it through, no view', AD FS is 'federate and delegate'.