MS-900 · Question #32
Drag and Drop Question An organization plans to deploy Microsoft 365 in a hybrid scenario. You need to provide a recommendation based on some common identity and access management scenarios. The solut
The correct answer is Active Directory Federation Services (AD FS); Password hash synchronization with single sign-on; Pass-through authentication and single sign-on. The three correct solutions address hybrid identity scenarios while minimizing costs. AD FS is used when organizations require advanced federation capabilities or compliance requirements that necessitate on-premises token issuance. Password hash synchronization with SSO is the si
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Active Directory Federation Services (AD FS)
- Password hash synchronization with single sign-on
- Pass-through authentication and single sign-on
Explanation
The three correct solutions address hybrid identity scenarios while minimizing costs. AD FS is used when organizations require advanced federation capabilities or compliance requirements that necessitate on-premises token issuance. Password hash synchronization with SSO is the simplest and lowest-cost option, syncing password hashes to Azure AD for cloud-based authentication without requiring on-premises infrastructure for authentication. Pass-through authentication with SSO validates passwords directly against on-premises AD in real-time without storing hashes in the cloud, ideal for organizations with security policies that prohibit cloud-stored password hashes but want to avoid the complexity of AD FS.
Topics
Community Discussion
No community discussion yet for this question.
