Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

An enterprise named Vertex Holdings has an on-premises Active Directory Domain Services (AD DS) forest with 8,500 users. You are designing a hybrid identity solution to integrate the on-premises environment with a new Microsoft Entra ID tenant.

The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises credentials.
- Users must be able to sign in even if the on-premises network connection or on-premises domain controllers are temporarily unavailable.
- Users must be allowed to reset their own passwords in the cloud, and these changes must immediately synchronize back to the on-premises AD DS.
- You must minimize on-premises infrastructure requirements and administrative overhead.

Which two actions should you include in the design to meet these requirements? (Select two.)

  1. Install Microsoft Entra Connect on-premises and configure Password Hash Synchronization (PHS).Cevap
  2. Enable Password Writeback in Microsoft Entra Connect and configure Self-Service Password Reset (SSPR) in the Microsoft Entra tenant.Cevap
  3. C
    Install Microsoft Entra Connect on-premises and configure Pass-through Authentication (PTA).
  4. D
    Deploy Active Directory Federation Services (AD FS) and Web Application Proxy servers on-premises.
  5. E
    Create a Microsoft Entra Conditional Access policy requiring multi-factor authentication (MFA) for all users, and ensure that emergency access administrator accounts are included in the policy.

Cevap

To meet the requirements, you must deploy Microsoft Entra Connect with Password Hash Synchronization (PHS) to ensure authentication during on-premises outages, and enable Password Writeback with Self-Service Password Reset (SSPR) to allow password resets to synchronize back to the on-premises Active Directory.
Implementing Password Hash Synchronization (PHS) copies password hashes to Microsoft Entra ID, allowing authentication requests to be handled entirely in the cloud, which satisfies the business continuity requirement during on-premises outages. Enabling Password Writeback in Microsoft Entra Connect coupled with Self-Service Password Reset (SSPR) allows users to reset their passwords in the cloud and writes those changes back to the on-premises Active Directory Domain Services (AD DS) immediately.

Adım Adım Çözüm

1
Evaluate hybrid identity authentication synchronization options for business continuity.
Select Password Hash Synchronization (PHS).
PHS stores password hashes in the cloud, allowing authentication to succeed even if the on-premises connection is lost, unlike Pass-through Authentication or Active Directory Federation Services.
2
Evaluate self-service password reset and synchronization requirements.
Configure SSPR in Entra ID and enable Password Writeback in Microsoft Entra Connect.
SSPR allows cloud-based password resets, and Password Writeback ensures those updates are immediately synchronized back to the on-premises Active Directory.
3
Assess operational simplicity and minimize local footprint.
Avoid deploying AD FS or on-premises federation servers.
PHS requires only the Entra Connect sync engine, minimizing infrastructure and operational overhead.

Anahtar Kavram

Selecting the optimal hybrid identity authentication method (PHS vs. PTA vs. AD FS) based on business continuity, on-premises infrastructure constraints, and self-service password writeback capabilities.
Bu soruyu puanla