Your organization has an on-premises Active Directory domain weylandindustries.com and an Azure AD tenant with the same name. You will use Azure AD Connect. Requirements: password policies and account logon restrictions must apply to synced accounts, and the number of required servers should be minimized. Solution: use pass-through authentication and seamless single sign-on together with password hash synchronization. Does this solution meet the requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Yes.
Why this is the answer
Yes, this solution meets the requirements. Pass-through authentication (PTA) allows on-premises Active Directory to authenticate users, ensuring that existing password policies and account logon restrictions (like lockout policies) are enforced for synced accounts. Seamless single sign-on (SSO) provides a smooth user experience. Including password hash synchronization (PHS) as a backup mechanism is a best practice for business continuity, as it allows users to authenticate to Azure AD even if on-premises domain controllers are unavailable. This combination also minimizes server count as it doesn't require additional servers like Active Directory Federation Services (AD FS).
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed