AZ-305 exam dumps

AZ-305 practice question 25 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 25

Single answer

Contoso currently manages user identities using on-premises Active Directory Domain Services (AD DS) across multiple global offices. They want to adopt Azure-based SaaS solutions and need a secure, cloud-ready identity management solution supporting single sign-on and minimizing on-premises infrastructure dependencies. Which approach best meets these requirements?

  1. A

    Implement Azure AD Connect with Password Hash Synchronization

  2. B

    Implement Azure AD Connect with Pass-through Authentication

  3. C

    Implement a full AD FS federation infrastructure

  4. D

    Decommission on-premises AD DS and rely solely on Azure AD

Show answer and explanation

Correct answer: A

Explanation

For most hybrid identity scenarios, Microsoft recommends using Azure AD Connect with Password Hash Synchronization to achieve reliable cloud authentication, single sign-on, and reduced on-premises infrastructure requirements. This aligns with Microsoft’s best practices in Azure identity and access management documentation. If complex federation scenarios are not strictly needed, Password Hash Synchronization is typically more cost-effective and simpler to maintain.

  • A. Correct.

    Correct: Azure AD Connect with Password Hash Synchronization provides a straightforward, low-maintenance hybrid identity setup. Users can authenticate to Azure AD using their on-premises credentials, and it doesn’t require deploying the additional servers or infrastructure needed for AD FS. This approach is often recommended when the goal is to reduce on-premises overhead while maintaining a familiar sign-on experience.

  • B. Incorrect.

    Incorrect: Pass-through Authentication allows on-premises authentication directly against domain controllers, but it requires additional infrastructure and continuous availability of those domain controllers. This approach is beneficial in certain scenarios needing real-time password validation, but it’s more complex than Password Hash Synchronization and doesn’t reduce on-premises dependencies as effectively.

  • C. Incorrect.

    Incorrect: AD FS provides advanced federation capabilities and control over sign-on policies but introduces significant infrastructure overhead, including the need for AD FS servers, proxy servers, and load balancing. This is more suitable for complex SSO scenarios requiring detailed access policies, not minimal on-premises infrastructure.

  • D. Incorrect.

    Incorrect: Completely decommissioning on-premises AD DS is risky if Contoso still relies on on-premises applications and directory-aware services. Transitioning everything to cloud-only identity would disrupt on-premises operations and isn't a minimal-dependency project step unless all on-premises services have already been migrated or refactored.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam