Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A global consulting firm uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company has its own on-premises Active Directory Domain Services (AD DS) and requires its users to authenticate against their existing AD DS for all applications, including those integrated with Azure AD. The acquired company's security policy prohibits synchronizing password hashes to the cloud. Which authentication method should be implemented to integrate the acquired company's users with Azure AD while respecting their security policy?

  1. APass-through Authentication (PTA)
  2. BFederation with Active Directory Federation Services (AD FS)
  3. CAzure AD Seamless Single Sign-On (SSO)
  4. DPassword Hash Synchronization (PHS)
Show answer & explanation

Correct answer: B. Federation with Active Directory Federation Services (AD FS)

The requirement to authenticate against existing on-premises AD DS and the prohibition of synchronizing password hashes to the cloud directly points to Federation with AD FS. AD FS keeps all authentication requests on-premises.

Why the other options are wrong

  • A. PTA validates passwords against on-premises AD, but it still involves the password leaving the on-premises network (albeit encrypted) to reach the PTA agent, and the prompt for authentication comes from Azure AD, not directly from on-premises AD DS. While better than PHS, AD FS offers full on-premises control.
  • C. Seamless SSO is a complementary feature for user experience, not an authentication method that dictates where the primary authentication occurs.
  • D. PHS synchronizes password hashes to Azure AD, which violates the security policy.

Federation with AD FS

Federation with Active Directory Federation Services (AD FS) allows organizations to authenticate users against their on-premises Active Directory without synchronizing passwords or hashes to Azure AD.

  • Authentication occurs entirely on-premises via AD FS servers.
  • Provides full control over the authentication process and policies.
  • Requires on-premises infrastructure (AD FS servers, WAP servers).
  • More complex to deploy and maintain compared to PHS or PTA.

Memory trick: AD FS: Always Done Fully On-Site.

More Implement an authentication and access management solution questions