Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A company is planning to migrate its on-premises data center to Azure. They need to ensure that user identities and authentication processes remain consistent across both environments. The solution must allow users to use their existing on-premises Active Directory credentials to access Azure resources. Which Azure identity service should they implement?
- AAzure Information Protection
- BAzure Active Directory (Azure AD) Connect
- CAzure Active Directory Domain Services (Azure AD DS)
- DAzure Active Directory B2C
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Active Directory (Azure AD) Connect
Azure AD Connect synchronizes user identities between an on-premises Active Directory and Azure Active Directory, enabling users to use their existing credentials for accessing both on-premises and Azure resources.
Why the other options are wrong
- A. Azure Information Protection helps classify and protect sensitive documents and emails.
- C. Azure AD Domain Services provides managed domain services for Azure VMs, but Azure AD Connect is for syncing existing on-premises AD.
- D. Azure AD B2C is for managing consumer identities for customer-facing applications.
Azure AD Connect
Azure AD Connect is a Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes user identities between on-premises Active Directory and Azure Active Directory.
- Enables hybrid identity scenarios
- Supports password hash synchronization, pass-through authentication, and federation
- Provides single sign-on experience
- Required for syncing users, groups, and contacts
Memory trick: AD Connect is the bridge that lets your on-premises users walk right into Azure.