Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A large enterprise has a hybrid identity environment with Azure AD Connect synchronizing identities from on-premises Active Directory. They observe that some users are experiencing slow sign-in times when accessing cloud applications, and they want to improve the authentication experience by allowing users to sign in using the same password they use on-premises, without storing password hashes in Azure AD or deploying ADFS. Which authentication method should be configured?
- ACloud-only authentication
- BFederation with ADFS
- CPassword Hash Synchronization (PHS)
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: D. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to cloud applications using their on-premises passwords, which are validated directly against the on-premises Active Directory. It does not store password hashes in Azure AD and avoids the complexity of ADFS.
Why the other options are wrong
- A. Cloud-only authentication means users are managed directly in Azure AD and do not use on-premises passwords.
- B. Federation with ADFS involves deploying and managing ADFS servers, which the scenario explicitly wants to avoid.
- C. PHS synchronizes a hash of the user's password to Azure AD, meaning passwords are not validated directly against on-premises AD.
Pass-through Authentication (PTA)
An Azure AD Connect authentication method that signs users in by validating their passwords directly against on-premises Active Directory.
- Uses lightweight agents on-premises to validate passwords.
- Does not store password hashes in Azure AD.
- Provides a simple way to achieve single sign-on without ADFS.
Memory trick: Choose how your on-prem password travels to the cloud.