Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard
A company wants to extend its on-premises Active Directory to Azure to provide single sign-on (SSO) for cloud-based applications while maintaining a synchronized user identity experience. They need a tool that synchronizes user accounts, passwords, and groups from their on-premises Active Directory to Azure Active Directory. Which Azure service is designed for this hybrid identity scenario?
- AAzure MFA
- BAzure AD Connect
- CAzure Active Directory Domain Services
- DAzure Active Directory B2C
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Connect
Azure AD Connect is a tool for connecting on-premises identity infrastructure to Azure Active Directory, enabling synchronization of users, groups, and passwords for a hybrid identity solution and SSO.
Why the other options are wrong
- A. Azure MFA (Multi-Factor Authentication) adds a layer of security to sign-ins, but it's not the tool for synchronizing identities.
- C. Azure Active Directory Domain Services provides managed domain services in Azure, but it doesn't synchronize with an existing on-premises AD; Azure AD Connect handles that synchronization.
- D. Azure Active Directory B2C is for customer-facing identity management, not for synchronizing corporate on-premises AD to Azure AD.
Azure AD Connect
A Microsoft tool designed to meet and accomplish your hybrid identity goals by synchronizing users, groups, and passwords between on-premises Active Directory and Azure Active Directory.
- Synchronizes on-premises AD to Azure AD.
- Enables hybrid identity.
- Supports password hash synchronization, pass-through authentication, federation.
- Provides single sign-on (SSO) experience.
Memory trick: AD Connect is the seamless bridge between your old on-prem AD and new Azure AD.