Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A company has implemented Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They want to ensure that if a local administrator accidentally deletes a large number of user accounts on-premises, these deletions do not immediately synchronize to Azure AD, potentially causing widespread data loss. What Azure AD Connect feature should be enabled to prevent this scenario?

  1. APrevent accidental deletions
  2. BPass-through Authentication (PTA)
  3. CSelective attribute synchronization
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: A. Prevent accidental deletions

The 'Prevent accidental deletions' feature in Azure AD Connect is specifically designed to stop bulk deletion synchronizations to Azure AD if the number of deletions exceeds a configured threshold, protecting against accidental data loss.

Why the other options are wrong

  • B. PTA authenticates users against on-premises AD, not a deletion protection feature.
  • C. Selective attribute synchronization controls which attributes are synced, not the deletion of entire user accounts.
  • D. PHS synchronizes password hashes, not a protection against accidental deletions.

Azure AD Connect: Prevent Accidental Deletions

An Azure AD Connect feature that protects against large-scale, unintended deletions from the on-premises Active Directory being synchronized to Azure AD.

  • Configurable deletion threshold.
  • Blocks sync if threshold is exceeded.
  • Requires administrator review and approval for large deletions.

Memory trick: Accidental deletion prevention is like a safety net for your synced users.

More Manage identity and access questions