Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

An enterprise is designing a hybrid and multi-tenant identity solution to integrate their on-premises Active Directory Domain Services (AD DS) forest with Microsoft Entra ID. The solution must support various user populations, access control policies, and authentication methods. Match each business and security requirement on the left to the most appropriate Microsoft Entra identity technology or feature on the right that satisfies it.

  • Authenticate users in Microsoft Entra ID using synced credentials, ensuring sign-in capability even if the on-premises WAN link is offline, and allowing Microsoft Entra ID Protection to identify leaked credentials.Password Hash Synchronization (PHS)
  • Authenticate users in real-time against on-premises AD DS to enforce local policies and account states, without hosting federation servers in a perimeter network.Pass-Through Authentication (PTA)
  • Delegate user authentication to an on-premises identity provider to support third-party hardware security modules (HSMs) and smart cards for logging on.Active Directory Federation Services (AD FS)
  • Enable external partners to collaborate by logging in to corporate resources using their own organization's credentials, without managing their lifecycle in the local Active Directory.Microsoft Entra B2B collaboration

Cevap

The requirement for offline authentication and leaked credential detection matches Password Hash Synchronization (PHS). The requirement for real-time authentication against local AD DS to enforce policies without federation servers matches Pass-Through Authentication (PTA). The requirement for third-party HSM and smart card authentication matches Active Directory Federation Services (AD FS). The requirement for external partner collaboration using their own corporate credentials matches Microsoft Entra B2B collaboration.
The requirements are matched based on the native capabilities of Microsoft Entra ID hybrid identity models: Password Hash Synchronization (PHS) enables offline sign-in and leaked credential detection; Pass-Through Authentication (PTA) enables real-time local AD DS validation and policy enforcement without federation servers; Active Directory Federation Services (AD FS) supports advanced on-premises authentication requirements like HSMs and smart cards; Microsoft Entra B2B collaboration allows secure external collaboration without managing partner credentials.

Adım Adım Çözüm

1
Analyze the first requirement for offline sign-in capability and leaked credential detection.
Password Hash Sync (PHS) stores password hashes in the cloud, enabling offline authentication and letting Microsoft Entra ID Protection inspect hashes against leaked credentials database.
Only PHS stores a hash of the user's password hash in Microsoft Entra ID, which is a prerequisite for Azure AD Identity Protection's leaked credential detection.
2
Analyze the second requirement for real-time local AD DS validation and enforcing account states/logon hours without federation infrastructure.
Pass-Through Authentication (PTA) fulfills this by using a simple local agent to validate passwords directly against on-premises Domain Controllers, ensuring real-time policy evaluation.
PTA redirects the authentication request to local domain controllers in real-time, enforcing local restrictions without requiring a heavy AD FS infrastructure.
3
Analyze the third requirement for leveraging local HSMs and smart cards for federation-based sign-in.
Active Directory Federation Services (AD FS) redirects users to the on-premises federation endpoints where advanced local authentication methods (like smart cards and HSM integration) are executed.
Federated solutions like AD FS delegate the entire authentication process to the on-premises identity provider, which is required for custom on-premises authentication mechanisms.
4
Analyze the fourth requirement for external partner collaboration using their own credentials.
Microsoft Entra B2B collaboration enables sharing resources with external users who sign in with their own tenant credentials, removing the need for local lifecycle management.
B2B collaboration allows guest users to sign in with their external identity provider (such as another Entra ID tenant, Google, or SAML/WS-Fed IdP).

Anahtar Kavram

Selecting the correct hybrid identity authentication sync method and tenant collaboration mechanism based on business continuity, authentication policies, and multi-tenant requirements.
Tahmini Süre:2m 0s
Bu soruyu puanla