Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Kestrel Dynamics has an on-premises Active Directory Domain Services (AD DS) forest. You are designing a hybrid identity solution that integrates the AD DS forest with a new Microsoft Entra ID tenant. The solution must meet the following requirements:

* Users must be able to sign in to cloud services using their on-premises credentials.
* Users must be able to authenticate to Microsoft Entra ID even if the on-premises network or AD DS domain controllers are completely offline.
* Users must be able to reset their passwords in the cloud, and the changes must immediately write back to the on-premises AD DS.
* Administrative overhead and infrastructure costs must be minimized.

Which two components should you include in the hybrid identity design? (Select two).

  1. Password Hash Synchronization (PHS)Cevap
  2. Password writeback enabled in Microsoft Entra ConnectCevap
  3. C
    Active Directory Federation Services (AD FS)
  4. D
    Pass-through Authentication (PTA)

Cevap

The correct design components are Password Hash Synchronization (PHS) and Password writeback enabled in Microsoft Entra Connect.
Password Hash Synchronization (PHS) allows users to log in with their on-premises credentials by validating hashes locally in Microsoft Entra ID. Because the hashes reside in the cloud, sign-in works even if the on-premises network or AD DS domain controllers go offline. Additionally, PHS requires no extra on-premises servers, aligning with the low overhead constraint. Enabling password writeback in Microsoft Entra Connect is the specific configuration needed to write SSPR changes immediately back to the on-premises AD DS.

Adım Adım Çözüm

1
Identify the cloud-based authentication method that handles on-premises outages.
Password Hash Synchronization (PHS) is selected because it enables independent cloud-based sign-in from synchronized password hashes, unlike Pass-through Authentication or Active Directory Federation Services which depend on active on-premises availability.
The system must support user sign-ins during on-premises offline events.
2
Evaluate the design against complexity and cost constraints.
Confirming PHS meets the low overhead constraint, whereas AD FS would require dedicated federation servers and complex setup.
The scenario mandates that administrative overhead and infrastructure costs be minimized.
3
Determine the requirement for SSPR changes to reflect on-premises.
Enable password writeback in the Microsoft Entra Connect configuration.
Cloud-initiated self-service password resets must update the on-premises AD DS immediately.

Anahtar Kavram

Selecting the appropriate hybrid identity authentication protocol and directory synchronization settings under cost, complexity, and availability constraints.
Bu soruyu puanla