Soru

Zorluk: ZorHybrid and Multi-Tenant Identity Solutions

Luminary Financials is designing a hybrid identity solution to integrate their on-premises Active Directory Domain Services (AD DS) forest, corp.luminaryfinancials.com, with a new Microsoft Entra ID tenant. The forest contains approximately 35,000 user accounts.

The solution must meet the following requirements:
- On-premises users must be able to authenticate to cloud resources.
- If the connection between the on-premises network and Azure is lost, users must still be able to authenticate to cloud resources.
- Users must be able to change their passwords in the cloud using self-service password reset (SSPR), and these changes must immediately synchronize back to the on-premises AD DS forest.
- Emergency access accounts must be protected against accidental lockout during tenant-wide Multi-Factor Authentication (MFA) enforcement.

Which two configuration actions should you include in the hybrid identity design? (Select two.)

  1. Configure Microsoft Entra Connect to use Password Hash Synchronization (PHS).Cevap
  2. B
    Configure Microsoft Entra Connect to use Pass-Through Authentication (PTA).
  3. Enable password writeback in the Microsoft Entra Connect configuration.Cevap
  4. D
    Deploy Active Directory Federation Services (AD FS) on-premises to handle authentication requests.
  5. E
    Create a Conditional Access policy that requires Multi-Factor Authentication (MFA) for all administrator accounts without exclusions.

Cevap

Configure Microsoft Entra Connect to use Password Hash Synchronization (PHS) and enable password writeback in the Microsoft Entra Connect configuration.
The correct configuration combines Password Hash Synchronization (PHS) with enabling password writeback in Microsoft Entra Connect. Password Hash Synchronization ensures that users can authenticate to cloud services using their AD DS credentials even if the on-premises network link is down, as Microsoft Entra ID performs the authentication natively in the cloud. Enabling password writeback is required to allow self-service password reset (SSPR) operations performed in Microsoft Entra ID to propagate back to the on-premises AD DS forest.

Adım Adım Çözüm

1
Determine the synchronization and authentication method that satisfies the business continuity requirements during an on-premises network outage.
Password Hash Synchronization (PHS) is selected as the primary sync authentication method.
Unlike PTA or AD FS, PHS enables Microsoft Entra ID to handle user authentication entirely in the cloud, ensuring users can log in even if the on-premises network or domain controllers are unreachable.
2
Enable password writeback within the Microsoft Entra Connect synchronization configuration.
Password writeback is successfully activated.
This allows self-service password reset (SSPR) updates triggered in the cloud to be written back to the on-premises AD DS environment in real time, satisfying the bi-directional password synchronization requirement.

Anahtar Kavram

Designing a highly available hybrid identity synchronization and self-service password reset solution.
Tahmini Süre:2m 0s
Bu soruyu puanla