Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A client organization uses Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password changes made on-premises are immediately effective for cloud applications without requiring additional synchronization cycles or agents. Which authentication method should be configured in Azure AD Connect to achieve this requirement?
- AFederation with AD FS
- BPassword Hash Synchronization (PHS)
- CPass-through Authentication (PTA)
- DAzure AD Kerberos
Show answer & explanationAnswer & explanation
Correct answer: C. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to use the same password on-premises and in the cloud. When a user attempts to sign in to Azure AD, PTA agents validate their credentials directly against the on-premises Active Directory, ensuring immediate reflection of password changes without synchronization delays.
Why the other options are wrong
- A. Federation with AD FS offloads authentication to AD FS, which involves a more complex setup and might not immediately reflect password changes without proper configuration.
- B. PHS synchronizes password hashes, meaning password changes are not immediately effective and require a synchronization cycle.
- D. Azure AD Kerberos is used for hybrid identity scenarios with Azure AD Domain Services, not for direct authentication of on-premises users to Azure AD for cloud apps.
Azure AD Pass-through Authentication (PTA)
An Azure AD Connect authentication method that validates user passwords directly against an on-premises Active Directory.
- Uses lightweight agents on-premises.
- Provides immediate password validation.
- Does not store passwords in Azure AD.
Memory trick: PTA: Pass Through Always to On-Prem.