Novasphere Solutions has an on-premises Active Directory Domain Services (AD DS) forest named novasphere.local with 3,200 user accounts. You are designing a hybrid identity solution to integrate the on-premises directory with a new Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to Azure resources using their on-premises credentials.
- In the event of an on-premises datacenter or internet connectivity outage, users must still be able to authenticate to cloud services.
- Users must have the ability to reset their own passwords in the cloud, and these changes must immediately reflect in the on-premises directory.
- The administrative overhead of the identity infrastructure must be minimized.
Which hybrid identity synchronization and configuration strategy should you recommend?
- Password Hash Synchronization (PHS) with Microsoft Entra Connect and password writeback enabledAnswer
- BPass-through Authentication (PTA) with Microsoft Entra Connect and password writeback enabled
- CActive Directory Federation Services (AD FS) federation with Microsoft Entra Connect
- DPassword Hash Synchronization (PHS) with Microsoft Entra Connect and password writeback disabled