You are designing a hybrid identity and multi-tenant solution for a company named ZenithLogix. The company has an on-premises Active Directory Domain Services (AD DS) forest and a Microsoft Entra ID tenant. You need to select the appropriate identity feature or sync method to meet each of the following business and security requirements:
- Ensure that users can authenticate to cloud services even during an on-premises network or power outage.
- Enforce on-premises account restrictions (such as logon hours) in real-time for cloud authentication without deploying Active Directory Federation Services (AD FS).
- Allow guest users from a trusted partner company to log in to corporate resources using their own corporate Microsoft Entra tenant credentials.
- Enable users who reset their passwords in Microsoft Entra ID to have the changes immediately reflected in the on-premises AD DS.
Match each requirement on the left to the correct identity solution on the right.
- Authentication must succeed during an on-premises network outage.Password Hash Synchronization (PHS)
- On-premises logon hours must be enforced in real-time without AD FS.Pass-through Authentication (PTA)
- External guest users must authenticate using their own Entra ID home tenant.Microsoft Entra B2B Collaboration
- Password changes made via Microsoft Entra self-service password reset (SSPR) must sync back to on-premises AD DS.Self-Service Password Reset (SSPR) with Password Writeback