Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A company is migrating its on-premises Active Directory to Azure Active Directory (Azure AD). They need to ensure that all user accounts and their associated attributes are synchronized securely and efficiently to Azure AD. The solution must support password hash synchronization and single sign-on for cloud applications. Which Azure AD tool should be used for this synchronization?
- AAzure AD Connect
- BAzure AD Application Proxy
- CAzure AD Domain Services
- DAzure AD Connect Health
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect
Azure AD Connect is the primary tool for synchronizing on-premises Active Directory identities to Azure Active Directory, supporting password hash synchronization and single sign-on capabilities.
Why the other options are wrong
- B. Azure AD Application Proxy provides secure remote access to on-premises web applications, not directory synchronization.
- C. Azure AD Domain Services provides managed domain services for Azure VMs, but is not used for initial synchronization from on-premises AD.
- D. Azure AD Connect Health monitors the health of your on-premises identity infrastructure, but does not perform synchronization.
Azure AD Connect
A Microsoft tool designed to synchronize on-premises Active Directory identities with Azure Active Directory.
- Enables hybrid identity scenarios.
- Supports password hash synchronization (PHS), pass-through authentication (PTA), and federation integration.
- Synchronizes users, groups, and contacts.
Memory trick: Connect on-premises to the cloud with the right tool.