Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesMedium
A company wants to extend its on-premises Active Directory to Azure to provide single sign-on (SSO) capabilities for cloud-based applications and manage user identities in a hybrid environment. They need a service that synchronizes user identities from their on-premises directory to Azure. Which Azure service enables this functionality?
- AAzure AD Connect
- BAzure Active Directory Domain Services (Azure AD DS)
- CAzure Active Directory (Azure AD)
- DAzure MFA
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect
Azure AD Connect is a Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes users, groups, and contacts from on-premises Active Directory to Azure Active Directory, enabling SSO and consistent identity management across hybrid environments.
Why the other options are wrong
- B. Azure Active Directory Domain Services (Azure AD DS) provides managed domain services for VMs, not synchronization from on-premises AD.
- C. Azure Active Directory (Azure AD) is the cloud-based identity service itself, but not the tool for synchronization.
- D. Azure MFA provides multi-factor authentication, which is a security feature, not an identity synchronization tool.
Azure AD Connect
Azure AD Connect is a Microsoft tool designed to synchronize on-premises Active Directory identities with Azure Active Directory.
- Enables hybrid identity scenarios.
- Synchronizes users, groups, and contacts.
- Supports password hash synchronization, pass-through authentication, and federation.
Memory trick: Azure AD Connect is the 'identity bridge' that links your on-premises world to the cloud.