exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 8 discussion

Actual exam question from Microsoft's AZ-304
Question #: 8
Topic #: 2
[All AZ-304 Questions]

HOTSPOT -
You manage a network that includes an on-premises Active Directory domain and an Azure Active Directory (Azure AD).
Employees are required to use different accounts when using on-premises or cloud resources. You must recommend a solution that lets employees sign in to all company resources by using a single account. The solution must implement an identity provider.
You need to provide guidance on the different identity providers.
How should you describe each identity provider? To answer, select the appropriate description from each list in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box1: User management occurs on-premises. Azure AD authenticates employees by using on-premises passwords.
Azure AD Domain Services for hybrid organizations
Organizations with a hybrid IT infrastructure consume a mix of cloud resources and on-premises resources. Such organizations synchronize identity information from their on-premises directory to their Azure AD tenant. As hybrid organizations look to migrate more of their on-premises applications to the cloud, especially legacy directory-aware applications, Azure AD Domain Services can be useful to them.
Example: Litware Corporation has deployed Azure AD Connect, to synchronize identity information from their on-premises directory to their Azure AD tenant. The identity information that is synchronized includes user accounts, their credential hashes for authentication (password hash sync) and group memberships.

User accounts, group memberships, and credentials from Litware's on-premises directory are synchronized to Azure AD via Azure AD Connect. These user accounts, group memberships, and credentials are automatically available within the managed domain.
Box 2: User management occurs on-premises. The on-promises domain controller authenticates employee credentials.
You can federate your on-premises environment with Azure AD and use this federation for authentication and authorization. This sign-in method ensures that all user authentication occurs on-premises.

Reference:
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/active-directory-ds-overview https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-fed

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mmmore
Highly Voted 4 years, 5 months ago
Correct
upvoted 49 times
...
milind8451
Highly Voted 4 years, 3 months ago
Right ans. Sync identity denotes Pass thru authentication or Pass hash sync. Federated idemtity denotes ADFS and in ADFS, authentication happens at on-prem DCs.
upvoted 14 times
...
pingpongset
Most Recent 2 years, 8 months ago
Does anyone understand this part? It said "Employees are required to use different accounts. ", But "you must recommend a solution that lets employees sign in to all company resources by using a single account." This is confusing. "Employees are required to use different accounts when using on-premises or cloud resources. You must recommend a solution that lets employees sign in to all company resources by using a single account. "
upvoted 1 times
...
OCHT
2 years, 11 months ago
We can figure out given that following 4 points are hiccups of AZ AD domain service :- 1.This is a stand-alone managed domain. It is not an extension of Litware's on-premises domain. 2.Litware's IT administrator does not need to manage, patch or monitor this domain or any domain controllers for this managed domain. 3.There is no need to manage AD replication to this domain. User accounts, group memberships and credentials from Litware's on-premises directory are synchronized to Azure AD via Azure AD Connect. These are automatically available within this managed domain. 4. Since the domain is managed by Azure AD Domain Services, Litware's IT administrator does not have Domain Administrator or Enterprise Administrator privileges on this domain. Aware what kind of on-premise tasks there. Thence , answers are correct.
upvoted 1 times
...
plmmsg
3 years, 1 month ago
answer is correct
upvoted 1 times
...
syu31svc
3 years, 7 months ago
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-hybrid-identity-design-considerations-identity-adoption-strategy#:~:text=Synchronized%3A%20these%20are%20identities%20that,is%20called%20a%20password%20hash. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/media/plan-hybrid-identity-design-considerations/integration-scenarios.png Synchronized: these are identities that exist on-premises and in the cloud. Using Azure AD Connect, these users are either created or joined with existing Azure AD accounts. The user’s password hash is synchronized from the on-premises environment to the cloud in what is called a password hash. When using synchronized the one caveat is that if a user is disabled in the on-premises environment, it can take up to three hours for that account status to show up in Azure AD. This is due to the synchronization time interval. Federated: these identities exist both on-premises and in the cloud. Using Azure AD Connect, these users are either created or joined with existing Azure AD accounts. Answer is correct
upvoted 4 times
...
Gautam1985
3 years, 8 months ago
correct as provided
upvoted 1 times
...
glam
4 years, 3 months ago
Box1: User management occurs on-premises. Azure AD authenticates employees by using on-premises passwords. Box 2: User management occurs on-premises. The on-promises domain controller authenticates employee credentials.
upvoted 4 times
...
[Removed]
4 years, 3 months ago
for Sych , Pass through authentication as well the authentication will be done in on premises AD...hence the authentication is done via on premises domain controller? bit confised about the answer here
upvoted 1 times
teehex
3 years, 8 months ago
The solution is to use Password hash Auth.
upvoted 1 times
...
...
sanketshah
4 years, 4 months ago
given answer is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago