Soru

Zorluk: KolayHybrid and Multi-Tenant Identity Solutions

Aetherius Logistics has an on-premises Active Directory Domain Services (AD DS) domain. The company is designing a hybrid identity solution using a single Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to cloud resources using their on-premises credentials.
- If the network connection between the on-premises datacenter and Azure is temporarily lost, users must still be able to authenticate to cloud resources.
- Users must be able to reset their passwords using Microsoft Entra Self-Service Password Reset (SSPR), and the changes must immediately update on-premises AD DS.
- On-premises infrastructure footprint and management overhead must be minimized.

Which hybrid identity synchronization and authentication solution should you recommend?

  1. Microsoft Entra Connect sync using Password Hash Synchronization (PHS) with Password Writeback enabledCevap
  2. B
    Microsoft Entra Connect sync using Pass-through Authentication (PTA) with Password Writeback enabled
  3. C
    Active Directory Federation Services (AD FS) federated sign-in with Password Writeback enabled
  4. D
    Microsoft Entra Connect Cloud Sync with Pass-through Authentication (PTA)

Cevap

Microsoft Entra Connect sync using Password Hash Synchronization (PHS) with Password Writeback enabled
The correct option is Password Hash Synchronization (PHS) with Password Writeback enabled because PHS copies the password hashes to Microsoft Entra ID, allowing authentication to occur entirely in the cloud, which ensures business continuity during on-premises network outages. Password Writeback ensures that SSPR updates are written back to on-premises Active Directory, and PHS has the lowest infrastructure overhead among hybrid identity options.

Adım Adım Çözüm

1
Analyze the business continuity requirement.
Since users must authenticate even during an on-premises network outage, authentication must occur directly in the cloud. This rules out Pass-through Authentication (PTA) and Active Directory Federation Services (AD FS) without complex, highly available configurations.
PTA and AD FS rely on on-premises resources to validate credentials in real time.
2
Analyze the self-service capability requirement.
Users must reset passwords in Microsoft Entra ID and have them update on-premises AD DS. This requires enabling Password Writeback, which is a feature of Microsoft Entra Connect sync.
Password Writeback synchronizes password changes from cloud to on-premises in real-time.
3
Select the correct combination that minimizes on-premises infrastructure.
Password Hash Synchronization (PHS) with Password Writeback meets all constraints with minimal local footprint compared to AD FS.
PHS utilizes the Microsoft Entra Connect sync agent without requiring additional dedicated authentication servers.

Anahtar Kavram

Selecting the appropriate hybrid identity authentication method to ensure business continuity and minimize infrastructure overhead
Bu soruyu puanla