Zephyr Energy Services has an on-premises Active Directory Domain Services (AD DS) domain. The company is designing a hybrid identity solution to integrate AD DS with a Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to authenticate to cloud services using their on-premises credentials.
- User password hashes must not be synchronized or stored in the cloud under any circumstances due to regulatory compliance policies.
- Authentication requests must be validated directly against on-premises Active Directory domain controllers.
- The deployment must avoid the infrastructure overhead and complexity of Active Directory Federation Services (AD FS).
Which authentication sync method should you include in the design to meet these requirements?
- Pass-through Authentication (PTA) with Seamless Single Sign-On (SSO)Cevap
- BPassword Hash Synchronization (PHS) with Seamless Single Sign-On (SSO)
- CActive Directory Federation Services (AD FS) federated sign-in
- DMicrosoft Entra Domain Services with cloud-only user accounts