Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A global consulting firm uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company uses its own on-premises Active Directory Domain Services (AD DS) and requires its users to continue authenticating against their existing infrastructure while accessing cloud resources in the consulting firm's Azure AD tenant. The consulting firm wants to minimize the operational overhead for both organizations and avoid synchronizing user passwords to Azure AD. Which authentication method should be implemented to meet these requirements?
- AFederation with AD FS
- BPassword Hash Synchronization (PHS)
- CCloud-only user accounts
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: A. Federation with AD FS
Federation with AD FS allows users to authenticate against their on-premises AD DS while accessing resources in Azure AD, without synchronizing passwords to the cloud. This method is ideal for scenarios where an existing on-premises identity provider needs to be leveraged for cloud access.
Why the other options are wrong
- B. PHS synchronizes password hashes to Azure AD, which violates the requirement to avoid synchronizing passwords.
- C. Cloud-only user accounts would require creating new user accounts in the consulting firm's Azure AD and managing separate credentials, which contradicts the goal of using existing infrastructure and minimizing overhead.
- D. PTA validates user passwords directly against on-premises AD DS but still requires agents to be installed and running, and while it doesn't sync passwords, federation offers more control over the authentication flow and is often preferred for existing AD FS deployments.
Federation with AD FS
A hybrid identity solution that allows users to authenticate against an on-premises Active Directory Federation Services (AD FS) instance to access resources in Azure Active Directory (Azure AD).
- Enables single sign-on (SSO) across on-premises and cloud resources.
- Does not synchronize user passwords to Azure AD.
- Requires an existing AD FS infrastructure or a new deployment.
Memory trick: FIDO: Federated Identities Don't Offload Passwords.