Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A company is migrating an existing on-premises web application to Azure App Service. The application uses Windows Integrated Authentication (WIA) and requires users to authenticate against their on-premises Active Directory. The company wants to maintain the single sign-on experience for users without synchronizing password hashes to Azure AD or deploying AD FS. Which Azure AD authentication method is appropriate for this scenario?

  1. APassword Hash Synchronization (PHS)
  2. BFederated Authentication (AD FS)
  3. CAzure AD Domain Services (AAD DS)
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: D. Pass-through Authentication (PTA)

Azure AD Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud applications using the same passwords. It achieves this by validating users' passwords directly against the on-premises Active Directory, without storing password hashes in Azure AD or requiring a complex federation infrastructure like AD FS. This ensures a consistent single sign-on experience with on-premises password validation.

Why the other options are wrong

  • A. Password Hash Synchronization (PHS) synchronizes a hash of the on-premises AD password hash to Azure AD. While it provides SSO, it involves syncing hashes, which the company wants to avoid.
  • B. Federated Authentication (AD FS) provides SSO but requires deploying and managing ADFS infrastructure, which the company explicitly wants to avoid.
  • C. Azure AD Domain Services (AAD DS) provides managed domain services for legacy applications that require LDAP or Kerberos, but it is not an authentication method for Azure AD users to access cloud applications directly against on-premises AD without syncing password hashes or AD FS.

Azure AD Pass-through Authentication (PTA)

An Azure AD Connect feature that provides single sign-on by validating user sign-in attempts directly against the on-premises Active Directory.

  • Authentication agents run on-premises, securely forwarding sign-in requests to on-premises AD.
  • No password hashes are stored in Azure AD.
  • Simplifies authentication for hybrid environments without requiring AD FS.

Memory trick: PTA: The on-premises bouncer for cloud access.

More Implement Azure security questions