Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A client organization uses Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password changes made on-premises are immediately effective for cloud applications without requiring additional synchronization cycles or agents. Which authentication method should be configured in Azure AD Connect to achieve this requirement?

  1. AFederation with AD FS
  2. BPassword Hash Synchronization (PHS)
  3. CPass-through Authentication (PTA)
  4. DAzure AD Kerberos
Show answer & explanation

Correct answer: C. Pass-through Authentication (PTA)

Pass-through Authentication (PTA) allows users to use the same password on-premises and in the cloud. When a user attempts to sign in to Azure AD, PTA agents validate their credentials directly against the on-premises Active Directory, ensuring immediate reflection of password changes without synchronization delays.

Why the other options are wrong

  • A. Federation with AD FS offloads authentication to AD FS, which involves a more complex setup and might not immediately reflect password changes without proper configuration.
  • B. PHS synchronizes password hashes, meaning password changes are not immediately effective and require a synchronization cycle.
  • D. Azure AD Kerberos is used for hybrid identity scenarios with Azure AD Domain Services, not for direct authentication of on-premises users to Azure AD for cloud apps.

Azure AD Pass-through Authentication (PTA)

An Azure AD Connect authentication method that validates user passwords directly against an on-premises Active Directory.

  • Uses lightweight agents on-premises.
  • Provides immediate password validation.
  • Does not store passwords in Azure AD.

Memory trick: PTA: Pass Through Always to On-Prem.

More Manage identity and access questions