CertKeen

Azure Solutions Architect Expert (AZ-305) · Free practice question 1 of 12

Pass-through authentication for on-premises policy

Ambleside Credit syncs its AD DS accounts into its Entra tenant. Its security policy forbids storing any form of password hash in the cloud, and on-premises sign-in hour restrictions and account disablement must take effect immediately for cloud sign-ins. Federation servers are not wanted. What should you recommend?

  1. A.Federation with an AD FS farm and Web Application Proxy servers
  2. B.Pass-through authentication with agents installed on several on-premises servers
  3. C.Microsoft Entra Cloud Sync with password hash synchronization
  4. D.Password hash synchronization with Seamless SSO
Show answer and explanation

Correct answer: B. Pass-through authentication with agents installed on several on-premises servers

Why: Pass-through authentication validates each password against on-premises Active Directory through lightweight agents, so no hash is stored in the cloud and on-premises policies such as logon hours apply at sign-in. Password hash synchronization, whether through Connect Sync or Cloud Sync, stores a hash of the password hash in Microsoft Entra ID. AD FS would meet the policy but adds the federation servers the company does not want.

More free Azure Solutions Architect Expert (AZ-305) questions