Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Zephyr Logistics is designing a hybrid identity and multi-tenant collaboration solution. The company has an on-premises Active Directory Domain Services (AD DS) forest with 82008{}200 users. You are tasked with selecting the appropriate identity integration and collaboration technologies to satisfy the company's security, compliance, and availability requirements.

Match each business requirement on the left to the correct Microsoft Entra ID or hybrid identity technology on the right.

  • Authenticate users in the cloud even during an on-premises network outage, minimizing on-premises infrastructure.Password Hash Synchronization (PHS)
  • Authenticate users against on-premises Active Directory in real-time without storing credential hashes in the cloud.Pass-through Authentication (PTA)
  • Authenticate users using existing on-premises smart cards, keeping all authentication policies within the corporate network perimeter.Active Directory Federation Services (AD FS)
  • Allow external partner users to securely access corporate applications using their own organizational identity providers.Microsoft Entra B2B Collaboration

Cevap

Authenticate users in the cloud during outages matches Password Hash Synchronization (PHS). Authenticate users in real-time without cloud hashes matches Pass-through Authentication (PTA). Authenticate users using smart cards within the perimeter matches Active Directory Federation Services (AD FS). Allow partner users to access resources using their own identity provider matches Microsoft Entra B2B Collaboration.
The correct matches align each scenario with its primary architectural capability. Password Hash Synchronization (PHS) offers high availability by allowing Entra ID to authenticate users independently of on-premises connectivity. Pass-through Authentication (PTA) provides real-time local validation without storing hashes in the cloud. Active Directory Federation Services (AD FS) handles specialized on-premises authentication requirements like smart card/certificate validation and local perimeter policy enforcement. Microsoft Entra B2B Collaboration facilitates secure, external partner access by trusting their home identity provider.

Adım Adım Çözüm

1
Analyze the requirement for outage resilience and minimal on-premises footprint.
Password Hash Synchronization (PHS) is selected as it offloads authentication to Entra ID and has zero runtime dependency on the on-premises environment once synced.
This guarantees sign-in availability during network or on-premises server outages.
2
Analyze the requirement for real-time authentication without storing credential hashes in the cloud.
Pass-through Authentication (PTA) is selected because authentication requests are forwarded to local agents on-premises, and no credential hashes are stored in Microsoft Entra ID.
This satisfies strict organizational compliance rules that forbid cloud credential storage.
3
Analyze the requirement for on-premises smart card authentication and local policy management.
Active Directory Federation Services (AD FS) is selected because federation hands over the authentication handshake to the on-premises directory, permitting the use of smart cards and certificate-based auth.
This keeps authentication traffic and security policy enforcement within the corporate perimeter.
4
Analyze the requirement for partner collaboration using their own identity providers.
Microsoft Entra B2B Collaboration is selected as it allows guest users to use their existing external credentials to sign in, reducing administrative overhead.
This meets the multi-tenant collaboration requirements securely and efficiently.

Anahtar Kavram

Designing hybrid identity authentication methods (PHS, PTA, AD FS) and multi-tenant collaboration strategies (Entra B2B) based on availability, security, and administrative requirements.
Bu soruyu puanla