Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is migrating an existing web application to Azure App Service. The application uses a custom authentication system that validates user credentials against an on-premises Active Directory. The company wants to integrate this application with Azure Active Directory (AAD) to leverage AAD's security features, but users must continue to authenticate primarily against the on-premises Active Directory without syncing password hashes to the cloud. Which Azure AD authentication method should be used to meet these requirements?
- APass-through Authentication (PTA)
- BAzure AD Domain Services (AAD DS)
- CPassword Hash Synchronization (PHS)
- DFederation with Active Directory Federation Services (AD FS)
Show answer & explanationAnswer & explanation
Correct answer: A. Pass-through Authentication (PTA)
Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud applications using the same passwords. It achieves this by validating users' credentials directly against the on-premises Active Directory, without storing any hashes in Azure AD. This meets the requirement of not syncing password hashes to the cloud while leveraging AAD for authentication.
Why the other options are wrong
- B. AAD DS provides managed domain services in Azure, but it's not an authentication method for syncing identities from on-premises AD; it's a domain service itself.
- C. PHS syncs a hash of the user's on-premises password hash to Azure AD. The requirement is *without* syncing password hashes.
- D. Federation with AD FS also meets the requirement but involves more complex infrastructure (AD FS servers). PTA is a simpler, agent-based solution for the same goal.
Azure AD Pass-through Authentication (PTA)
An Azure AD authentication method that allows users to sign in to cloud applications using their on-premises Active Directory passwords, by validating credentials directly against the on-premises AD.
- No password hashes are stored in Azure AD.
- Uses lightweight agents installed on-premises.
- Provides a simple alternative to AD FS for hybrid identity.
- Offers seamless single sign-on experience.
Memory trick: Pass-through lets on-prem passwords just 'pass through' to Azure AD.