Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard

A company wants to extend its on-premises Active Directory to Azure to provide single sign-on (SSO) for cloud-based applications while maintaining a synchronized user identity experience. They need a tool that synchronizes user accounts, passwords, and groups from their on-premises Active Directory to Azure Active Directory. Which Azure service is designed for this hybrid identity scenario?

  1. AAzure MFA
  2. BAzure AD Connect
  3. CAzure Active Directory Domain Services
  4. DAzure Active Directory B2C
Show answer & explanation

Correct answer: B. Azure AD Connect

Azure AD Connect is a tool for connecting on-premises identity infrastructure to Azure Active Directory, enabling synchronization of users, groups, and passwords for a hybrid identity solution and SSO.

Why the other options are wrong

  • A. Azure MFA (Multi-Factor Authentication) adds a layer of security to sign-ins, but it's not the tool for synchronizing identities.
  • C. Azure Active Directory Domain Services provides managed domain services in Azure, but it doesn't synchronize with an existing on-premises AD; Azure AD Connect handles that synchronization.
  • D. Azure Active Directory B2C is for customer-facing identity management, not for synchronizing corporate on-premises AD to Azure AD.

Azure AD Connect

A Microsoft tool designed to meet and accomplish your hybrid identity goals by synchronizing users, groups, and passwords between on-premises Active Directory and Azure Active Directory.

  • Synchronizes on-premises AD to Azure AD.
  • Enables hybrid identity.
  • Supports password hash synchronization, pass-through authentication, federation.
  • Provides single sign-on (SSO) experience.

Memory trick: AD Connect is the seamless bridge between your old on-prem AD and new Azure AD.

More Describe Azure architecture and services questions