Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Contoso Ltd. has a single Active Directory forest with 40,000 employees. Azure resources span multiple subscriptions. The company currently uses AD FS for sign-in to Microsoft 365 but wants to retire the AD FS servers to reduce on-premises complexity. Requirements: retain on-premises password validation, enable Azure AD Conditional Access and MFA, and automatically provision identities to several SaaS applications. Which identity management approach should you recommend?
Retain the existing AD FS farm and additionally enable Password Hash Synchronization in Azure AD Connect.
Create a dedicated Azure AD B2C tenant and migrate all employee accounts into it.
Replace AD FS with Azure AD Connect Pass-through Authentication and Seamless Single Sign-On, then configure Azure AD automatic provisioning for the required SaaS applications.
Deploy Azure AD Domain Services in Azure and join all cloud workloads to the managed domain.
Azure AD Connect Pass-through Authentication (PTA) with Seamless SSO validates user passwords against on-premises Active Directory without requiring AD FS. Because authentication is handled by Azure AD, Conditional Access policies and Azure AD MFA can be applied. Azure AD's built-in SCIM/graph-based provisioning engine can automatically create and manage user accounts in thousands of integrated SaaS applications.
Azure AD Domain Services is intended for legacy-auth workloads running in Azure VMs and does not satisfy the SaaS provisioning or Conditional Access requirements.
Keeping AD FS contradicts the requirement to decommission the federation farm and still leaves significant on-premises infrastructure.
Azure AD B2C is designed for external customer identities rather than an internal workforce and therefore does not meet the organization's needs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Connect Pass-through Authentication (PTA) and Seamless Single Sign-On (SSO)?
Open an interactive chat with Bash
What is the role of Azure AD automatic provisioning in managing SaaS applications?
Open an interactive chat with Bash
Why isn’t Azure AD Domain Services (Azure AD DS) suitable for this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .