Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A company is implementing Azure AD Connect to synchronize user identities from its on-premises Active Directory to Azure AD. They need to ensure that password hash synchronization (PHS) is enabled and configured correctly for all synchronized users. Which of the following components is primarily responsible for transmitting the password hashes securely to Azure AD?
- AAzure AD Connect Sync Service
- BAzure AD Application Proxy Connector
- CAzure AD Pass-through Authentication Agent
- DAzure AD Domain Services
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Connect Sync Service
The Azure AD Connect Sync Service, specifically the synchronization engine within Azure AD Connect, is responsible for collecting the password hashes from the on-premises Active Directory and securely transmitting them to Azure AD when Password Hash Synchronization is enabled.
Why the other options are wrong
- B. Azure AD Application Proxy Connector is used for providing secure remote access to on-premises web applications.
- C. Azure AD Pass-through Authentication Agent handles sign-in requests by validating passwords directly against on-premises AD, not by transmitting hashes.
- D. Azure AD Domain Services provides managed domain services for Azure VMs and is not directly involved in synchronizing password hashes from on-premises AD.
Password Hash Synchronization (PHS)
A method of identity synchronization where a hash of the user's password from on-premises Active Directory is synchronized to Azure AD.
- Provides a simple way to enable cloud authentication for hybrid identities.
- Offers high availability and disaster recovery for authentication.
- Requires Azure AD Connect to be installed and configured.
Memory trick: Syncing hashes securely ensures cloud access.