Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Contoso Ltd. has an on-premises Active Directory forest with 10,000 users. The company will adopt several Azure and SaaS applications that support SAML 2.0 or OAuth 2.0. Security requirements: users must sign in with their on-premises domain credentials; multi-factor authentication (MFA) must be enforced for all cloud logons; no user password hashes may be stored in Azure AD. You must recommend an authentication solution that meets the requirements while keeping additional on-premises infrastructure to a minimum. Which solution should you recommend?
Create an Azure AD B2C tenant and integrate the on-premises Active Directory as an identity provider by using custom policies.
Implement Azure AD Pass-through Authentication with Seamless Single Sign-On and enable Azure AD Multi-Factor Authentication.
Configure Azure AD Password Hash Synchronization with Seamless Single Sign-On and Conditional Access to enforce Multi-Factor Authentication.
Deploy an Active Directory Federation Services (AD FS) farm and configure federated authentication with Azure AD Multi-Factor Authentication Server.
Azure AD Pass-through Authentication (PTA) uses lightweight agents to validate a user's password directly against the on-premises domain controller during sign-in, so no password hashes are ever stored in Azure AD. PTA supports Seamless Single Sign-On, allowing users to authenticate with their existing corporate credentials, and Azure AD Conditional Access can require MFA for all cloud sign-ins. This approach needs only a few agent installations and avoids the extra servers, proxy configuration, and certificate management overhead required by an AD FS farm. Password Hash Synchronization does not meet the requirement to avoid storing hashes in Azure AD, while Azure AD B2C is intended for external identities rather than corporate users. Therefore, implementing PTA with Seamless SSO and Azure AD MFA is the best fit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Pass-through Authentication (PTA)?
Open an interactive chat with Bash
How does Seamless Single Sign-On (SSO) work in Azure AD?
Open an interactive chat with Bash
Why is Azure AD Pass-through Authentication preferred over AD FS in this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .