Vespera Financial Services has an on-premises Active Directory Domain Services (AD DS) forest named corp.vesperafin.com containing 14,200 user accounts. The company is designing a hybrid identity solution to integrate with a new Microsoft Entra ID tenant.
The solution must meet the following requirements:
- Users must sign in to cloud services using their on-premises passwords.
- Remote users must be able to authenticate to cloud services even during an extended internet outage at the corporate offices.
- Users on domain-joined devices within the corporate network must experience automatic sign-in without credential prompts or redirections to on-premises login pages.
- Users must be able to reset their passwords using Microsoft Entra Self-Service Password Reset (SSPR), with the changes synchronized on-premises in near real-time.
- On-premises infrastructure footprint and management overhead must be minimized.
Which hybrid identity and authentication configuration should you recommend?
- AConfigure Pass-through Authentication (PTA) as the authentication method, enable Seamless Single Sign-On (Seamless SSO), and enable password writeback in Microsoft Entra Connect.
- Configure Password Hash Synchronization (PHS) as the authentication method, enable Seamless Single Sign-On (Seamless SSO), and enable password writeback in Microsoft Entra Connect.Cevap
- CDeploy Active Directory Federation Services (AD FS) and Web Application Proxy (WAP) servers, configure federation in Microsoft Entra Connect, and enable password writeback.
- DConfigure Password Hash Synchronization (PHS) as the authentication method, enable Seamless Single Sign-On (Seamless SSO), and configure Microsoft Entra self-service password reset (SSPR) without enabling password writeback.