NovaSpace Solutions has an on-premises Active Directory Domain Services (AD DS) forest named corp.novaspacesolutions.com containing 18,500 user accounts. The company is designing a hybrid identity solution to integrate their on-premises directory with a new Microsoft Entra ID tenant.
The solution must satisfy the following constraints:
- Passwords must be validated directly against on-premises Domain Controllers in real-time to comply with local financial regulatory policies that require local audit logging of all authentication requests.
- The authentication solution must be highly available and tolerate the failure of an individual on-premises authentication server.
- The design must minimize administrative overhead and avoid the deployment of complex federation infrastructure like Active Directory Federation Services (AD FS).
- Users must be able to use Microsoft Entra Self-Service Password Reset (SSPR) to reset their passwords, and these changes must update the on-premises AD DS.
Which hybrid identity solution should you recommend?
- AActive Directory Federation Services (AD FS) federated with Microsoft Entra ID, using a Web Application Proxy (WAP) farm for high availability
- BMicrosoft Entra Connect Password Hash Synchronization (PHS) combined with Password Writeback, configuring high availability via staging mode servers
- Microsoft Entra Connect Pass-through Authentication (PTA) combined with Password Writeback, using multiple PTA agents installed on separate on-premises serversCevap
- DMicrosoft Entra Connect Cloud Sync with Pass-through Authentication (PTA) agents installed across multiple on-premises domain controllers