Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A company is migrating an on-premises application that uses Windows integrated authentication to Azure. The application needs to authenticate users against their existing Active Directory Domain Services (AD DS) without synchronizing user hashes to Azure AD. Which Azure AD service should be configured for this purpose?

  1. AAzure AD Domain Services (Azure AD DS)
  2. BAzure AD Connect Pass-through Authentication
  3. CAzure AD Connect Password Hash Synchronization
  4. DAzure AD B2C
Show answer & explanation

Correct answer: B. Azure AD Connect Pass-through Authentication

Azure AD Connect Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating users' passwords directly against their on-premises Active Directory, without storing any password hashes in Azure AD.

Why the other options are wrong

  • A. Azure AD Domain Services provides managed domain services for Azure VMs, but doesn't handle the direct authentication against on-premises AD DS for cloud apps without hash sync or federation.
  • C. Password Hash Synchronization synchronizes a hash of the user's on-premises password hash to Azure AD, which the requirement explicitly avoids.
  • D. Azure AD B2C is for customer-facing applications and external identities, not for internal AD DS users.

Azure AD Connect Pass-through Authentication

An Azure AD Connect sign-in method that allows users to sign in to Azure AD with the same passwords as their on-premises Active Directory, without synchronizing password hashes to Azure AD.

  • Agents on-premises validate passwords directly
  • No password hashes stored in Azure AD
  • Provides single sign-on (SSO) capabilities

Memory trick: Pass-through: Your password 'passes through' to on-prem AD, not stored in the cloud.

More Implement Azure security questions