Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A large enterprise has a hybrid identity environment with Azure AD Connect synchronizing identities from on-premises Active Directory. They observe that some users are experiencing slow sign-in times when accessing cloud applications, and they want to improve the authentication experience by allowing users to sign in using the same password they use on-premises, without storing password hashes in Azure AD or deploying ADFS. Which authentication method should be configured?

  1. ACloud-only authentication
  2. BFederation with ADFS
  3. CPassword Hash Synchronization (PHS)
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: D. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) allows users to sign in to cloud applications using their on-premises passwords, which are validated directly against the on-premises Active Directory. It does not store password hashes in Azure AD and avoids the complexity of ADFS.

Why the other options are wrong

  • A. Cloud-only authentication means users are managed directly in Azure AD and do not use on-premises passwords.
  • B. Federation with ADFS involves deploying and managing ADFS servers, which the scenario explicitly wants to avoid.
  • C. PHS synchronizes a hash of the user's password to Azure AD, meaning passwords are not validated directly against on-premises AD.

Pass-through Authentication (PTA)

An Azure AD Connect authentication method that signs users in by validating their passwords directly against on-premises Active Directory.

  • Uses lightweight agents on-premises to validate passwords.
  • Does not store password hashes in Azure AD.
  • Provides a simple way to achieve single sign-on without ADFS.

Memory trick: Choose how your on-prem password travels to the cloud.

More Manage identity and access questions