Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy

A company is implementing a new internal web application that needs to authenticate users from its Azure Active Directory (Azure AD). The application development team requires a solution that minimizes credential management overhead for both users and administrators, and allows users to access the application seamlessly after logging into their Windows devices joined to Azure AD. Which authentication method should be recommended?

  1. APass-through Authentication (PTA)
  2. BAzure AD Seamless Single Sign-On (SSO)
  3. CPassword Hash Synchronization (PHS)
  4. DFederation with Active Directory Federation Services (AD FS)
Show answer & explanation

Correct answer: B. Azure AD Seamless Single Sign-On (SSO)

Azure AD Seamless SSO provides a seamless sign-in experience for users when their devices are joined to Azure AD, eliminating the need to re-enter passwords. This directly addresses the requirement for minimizing credential management overhead and seamless access.

Why the other options are wrong

  • A. PTA validates credentials against on-premises AD, but doesn't inherently provide seamless SSO for web applications without additional configuration.
  • C. PHS synchronizes password hashes to Azure AD, but users still need to enter credentials for web applications initially.
  • D. AD FS federation provides SSO but adds complexity and requires on-premises infrastructure, which is not the simplest solution for seamless access in an Azure AD-joined environment.

Azure AD Seamless SSO

Azure AD Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on their corporate network and their devices are joined to Azure AD, without requiring them to type their passwords.

  • Provides a true single sign-on experience for Azure AD-joined devices.
  • Works with both Password Hash Synchronization and Pass-through Authentication.
  • Requires client-side configuration (e.g., Internet Explorer zone settings via GPO) for full functionality.

Memory trick: Simple Sign-On, Smooth Experience, Securely.

More Implement an authentication and access management solution questions