Ignite Energy Partners has an on-premises Active Directory Domain Services (AD DS) forest. You are designing a hybrid identity solution to integrate the AD DS forest with a Microsoft Entra ID tenant. The design must meet the following requirements:
- Users must be able to sign in using their on-premises passwords.
- If the connection between the on-premises datacenter and Azure is lost, users must still be able to sign in to Azure resources.
- Users must be able to reset their passwords in Microsoft Entra ID using self-service password reset (SSPR), and the new passwords must write back to the on-premises AD DS.
- On-premises infrastructure requirements and administrative complexity must be minimized.
Which hybrid identity synchronization and authentication method should you recommend?
- Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabledAnswer
- BActive Directory Federation Services (AD FS) with Password Writeback enabled
- CMicrosoft Entra Connect with Pass-Through Authentication (PTA) and Password Writeback enabled
- DMicrosoft Entra Connect Cloud Sync with Password Hash Synchronization (PHS) and a separate Active Directory Lightweight Directory Services (AD LDS) instance