Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Zephyr Aerospace has an on-premises Active Directory Domain Services (AD DS) forest named corp.zephyraero.com. The company is designing a hybrid identity solution using Microsoft Entra Connect to integrate with a new Microsoft Entra ID tenant.

You need to select the identity synchronization and authentication design that meets the following requirements:
- Users must use their existing on-premises credentials to sign in to cloud resources.
- Users must be able to reset their passwords using the Microsoft Entra self-service password reset (SSPR) portal, and the updated passwords must immediately update on-premises AD DS.
- Users must be able to authenticate to cloud services even during an extended on-premises network outage.

Which identity solution should you recommend?

  1. Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabledCevap
  2. B
    Microsoft Entra Connect with Pass-through Authentication (PTA) and Password Writeback enabled
  3. C
    Active Directory Federation Services (AD FS) federated with Microsoft Entra ID and Password Writeback enabled
  4. D
    Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback disabled

Cevap

Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabled
The correct option is the one proposing Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabled. PHS copies password hashes to Microsoft Entra ID, allowing authentication to continue in the cloud even if the on-premises network is offline. Enabling Password Writeback allows SSPR events to sync back to the on-premises Active Directory.

Adım Adım Çözüm

1
Analyze the business continuity requirement: 'authenticate to cloud services even during an extended on-premises network outage'.
Identify that authentication must be handled directly by the cloud provider (Microsoft Entra ID) without relying on live on-premises connectivity.
This rules out Pass-through Authentication (PTA) and Active Directory Federation Services (AD FS), which require active on-premises communication for authentication.
2
Analyze the self-service requirement: 'reset their passwords using the Microsoft Entra SSPR portal, and the updated passwords must immediately update on-premises AD DS'.
Identify that Password Writeback must be enabled in Microsoft Entra Connect.
Without Password Writeback, cloud-initiated password resets cannot be synchronized back to the on-premises Active Directory.
3
Combine the requirements to select the matching architecture.
Select Password Hash Synchronization (PHS) with Password Writeback enabled.
This combination ensures authentication availability during on-premises outages and supports writing password changes back to the on-premises environment.

Anahtar Kavram

Selecting the appropriate hybrid identity sync and authentication method based on business continuity and password writeback requirements.
Bu soruyu puanla