Your environment has an Active Directory forest contoso.com and an Azure AD tenant contoso.com. You will deploy Azure AD Connect and need an integration approach that enforces on-premises password policies and sign-on restrictions for synced accounts while minimizing the number of required servers. Which authentication method should you recommend?
Choose an answer
Tap an option to check your answer.
Correct answer: pass-through authentication with seamless single sign-on (SSO).
Why this is the answer
Pass-through authentication (PTA) with seamless SSO is the correct choice because it directly validates user passwords against your on-premises Active Directory, thereby enforcing all your existing password policies and sign-on restrictions. It minimizes server count as it only requires lightweight agents on existing servers, unlike AD FS which demands dedicated federation servers and proxies. Password hash synchronization (PHS) does not enforce on-premises password policies or sign-on restrictions in real-time, as it stores a hash of the password in Azure AD. Federated identity with AD FS, while enforcing policies, requires a significantly larger server infrastructure, contradicting the requirement to minimize server count.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed