Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Ignite Energy Partners has an on-premises Active Directory Domain Services (AD DS) forest. You are designing a hybrid identity solution to integrate the AD DS forest with a Microsoft Entra ID tenant. The design must meet the following requirements:
- Users must be able to sign in using their on-premises passwords.
- If the connection between the on-premises datacenter and Azure is lost, users must still be able to sign in to Azure resources.
- Users must be able to reset their passwords in Microsoft Entra ID using self-service password reset (SSPR), and the new passwords must write back to the on-premises AD DS.
- On-premises infrastructure requirements and administrative complexity must be minimized.
Which hybrid identity synchronization and authentication method should you recommend?

  1. Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabledCevap
  2. B
    Active Directory Federation Services (AD FS) with Password Writeback enabled
  3. C
    Microsoft Entra Connect with Pass-Through Authentication (PTA) and Password Writeback enabled
  4. D
    Microsoft Entra Connect Cloud Sync with Password Hash Synchronization (PHS) and a separate Active Directory Lightweight Directory Services (AD LDS) instance

Cevap

Microsoft Entra Connect with Password Hash Synchronization (PHS) and Password Writeback enabled
Password Hash Synchronization (PHS) copies password hashes to Microsoft Entra ID, allowing authentication to occur directly in the cloud. This ensures that even during a complete WAN or datacenter outage, users can still authenticate to cloud resources. PHS has the lowest infrastructure footprint on-premises (requiring only Microsoft Entra Connect) and fully supports self-service password writeback.

Adım Adım Çözüm

1
Analyze the business continuity requirement during a connection outage.
Identify that authentication must occur directly in the cloud so that users can sign in even if the link to the on-premises datacenter is lost.
This rules out Pass-Through Authentication (PTA) and standard Active Directory Federation Services (AD FS), as both require active, real-time connectivity to on-premises infrastructure to authenticate users.
2
Evaluate the requirement to minimize on-premises infrastructure and administrative complexity.
Rule out AD FS, which requires dedicated servers, web application proxies, certificates, and load balancers on-premises.
Password Hash Synchronization (PHS) only requires the Microsoft Entra Connect sync server on-premises, representing the lowest infrastructure footprint and lowest complexity.
3
Verify support for Self-Service Password Reset (SSPR) and writeback.
Enable Password Writeback on the Microsoft Entra Connect synchronization server.
This allows passwords changed in Microsoft Entra ID via SSPR to be written back to the on-premises AD DS in near real-time, meeting all constraints.

Anahtar Kavram

Selecting the appropriate hybrid identity synchronization method to meet business continuity and infrastructure minimization requirements
Bu soruyu puanla