Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Aventis Logistics is designing a hybrid identity solution to integrate their on-premises Active Directory Domain Services (AD DS) forest of 6,200 users with a Microsoft Entra ID tenant. The design must satisfy the following requirements:
- Users must be able to sign in to Azure resources using their current on-premises passwords.
- Users must be able to perform self-service password resets from the cloud, and these updates must immediately synchronize back to the on-premises directory.
- The sign-in service must remain operational for users even if the network link between the on-premises datacenter and Azure is temporarily offline.
- On-premises server infrastructure and administrative overhead must be minimized.
Which two components should you include in the hybrid identity design? (Select two.)

  1. Password Hash Synchronization (PHS) as the hybrid identity authentication methodCevap
  2. Microsoft Entra self-service password reset (SSPR) with password writeback enabledCevap
  3. C
    Pass-Through Authentication (PTA) as the hybrid identity authentication method
  4. D
    Active Directory Federation Services (AD FS) as the hybrid identity authentication method

Cevap

Password Hash Synchronization (PHS) as the hybrid identity authentication method and Microsoft Entra self-service password reset (SSPR) with password writeback enabled
Password Hash Synchronization (PHS) is the correct authentication method because it processes authentication requests in the cloud, enabling users to log in even when the network connection to the on-premises environment is disconnected, while requiring the least administrative and server footprint. Enabling Microsoft Entra SSPR with password writeback satisfies the constraint to allow users to reset their passwords in Microsoft Entra ID and sync those modifications back to the local Active Directory Domain Services.

Adım Adım Çözüm

1
Analyze authentication business continuity requirements.
Identify that only Password Hash Synchronization (PHS) stores a representation of user passwords in the cloud, allowing authentication to proceed during a network outage between the on-premises datacenter and Azure. Pass-Through Authentication (PTA) and federation depend on live on-premises communication.
To satisfy the requirement that sign-in remains functional during network disconnects.
2
Analyze on-premises infrastructure footprint requirements.
Confirm that PHS requires only Microsoft Entra Connect agents and has the lowest infrastructure footprint compared to PTA and AD FS. AD FS requires complex on-premises federation and proxy deployments.
To ensure the solution minimizes on-premises infrastructure and administrative overhead.
3
Address the self-service password reset and writeback requirements.
Integrate Microsoft Entra self-service password reset (SSPR) with password writeback enabled to write cloud-based password resets back to the on-premises AD DS.
To meet the self-service password reset and bidirectional synchronization requirements.

Anahtar Kavram

Selecting and designing hybrid identity authentication and password management features based on availability, infrastructure footprint, and synchronization constraints.
Bu soruyu puanla