Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesMedium

A company wants to extend its on-premises Active Directory to Azure to provide single sign-on (SSO) capabilities for cloud-based applications and manage user identities in a hybrid environment. They need a service that synchronizes user identities from their on-premises directory to Azure. Which Azure service enables this functionality?

  1. AAzure AD Connect
  2. BAzure Active Directory Domain Services (Azure AD DS)
  3. CAzure Active Directory (Azure AD)
  4. DAzure MFA
Show answer & explanation

Correct answer: A. Azure AD Connect

Azure AD Connect is a Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes users, groups, and contacts from on-premises Active Directory to Azure Active Directory, enabling SSO and consistent identity management across hybrid environments.

Why the other options are wrong

  • B. Azure Active Directory Domain Services (Azure AD DS) provides managed domain services for VMs, not synchronization from on-premises AD.
  • C. Azure Active Directory (Azure AD) is the cloud-based identity service itself, but not the tool for synchronization.
  • D. Azure MFA provides multi-factor authentication, which is a security feature, not an identity synchronization tool.

Azure AD Connect

Azure AD Connect is a Microsoft tool designed to synchronize on-premises Active Directory identities with Azure Active Directory.

  • Enables hybrid identity scenarios.
  • Synchronizes users, groups, and contacts.
  • Supports password hash synchronization, pass-through authentication, and federation.

Memory trick: Azure AD Connect is the 'identity bridge' that links your on-premises world to the cloud.

More Describe Azure architecture and services questions