exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 32 discussion

Actual exam question from Microsoft's AZ-304
Question #: 32
Topic #: 2
[All AZ-304 Questions]

Your company wants to use an Azure Active Directory (Azure AD) hybrid identity solution.
You need to ensure that users can authenticate if the internet connection to the on-premises Active Directory is unavailable. The solution must minimize authentication prompts for the users.
What should you include in the solution?

  • A. password hash synchronization and Azure AD Seamless Single Sign-On (Azure AD Seamless SSO)
  • B. pass-through authentication and Azure AD Seamless Single Sign-On (Azure AD Seamless SSO)
  • C. an Active Directory Federation Services (AD FS) server
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Debleenac
Highly Voted 4 years, 1 month ago
Correct answer
upvoted 34 times
...
Santosh43
Highly Voted 4 years, 1 month ago
With password hash sync and seamless single sign on it will first try to use kerberos against your on prem infrastructure. If that is offline or you are outside the office, you will be able to enter your password to access the services. With adfs or pass through auth, you are offline if the on prem service is offline.
upvoted 31 times
...
One111
Most Recent 2 years, 8 months ago
PHS will allow to authenticate to cloud resources with or without onprem internet connectivity. PtA always require onprem (AADC server or other member server with PtA agent to be up, running and communicating with Azure). Correct answer is PtA.
upvoted 1 times
...
teyol51117
3 years, 1 month ago
On exam 31.03.2022
upvoted 3 times
...
iwuehfkjj3
3 years, 4 months ago
Selected Answer: A
correct
upvoted 2 times
...
bluewaves
3 years, 4 months ago
Selected Answer: A
Answer is correct
upvoted 3 times
...
syu31svc
3 years, 7 months ago
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn#comparing-methods What are the requirements for on-premises Internet and networking beyond the provisioning system? -> shows "None" for Password hash synchronization + Seamless SSO Answer is correct
upvoted 3 times
...
tita_tovenaar
3 years, 9 months ago
It's A or B depending on how you read the question. If you read it as "users must still be able to authenticate IN AZURE if internet ..." then it's A. If you rather read it as "on-prem users must be able to authenticate if internet ..." then it's B. This question is like the picture of the old woman/young girl, if you see one version it's difficult to see the other. Since the company doesn't have AAD yet, I assume we're in scenario B: users are still mainly on-prem, and a connection between AAD and on-prem AD must not complicate authentication if internet is down.
upvoted 2 times
pentium75
3 years, 8 months ago
The whole exam is about Azure. So if it says "users must be able to authenticate", then this is about authenticating to Azure.
upvoted 5 times
...
...
tvs2021
3 years, 9 months ago
on Exam (7-19-2021). passed 304 exam
upvoted 3 times
...
BenWat
3 years, 9 months ago
This shows the importance of reading the question "if the internet connection to the on-premises Active Directory is unavailable". I originally read it as if users were on prem with the AD and the risk was the internet connection to AAD might be lost. Doh.
upvoted 4 times
examineezer
3 years, 6 months ago
Me too
upvoted 2 times
...
...
GetulioJr
3 years, 10 months ago
Answer is correct.: You need to ensure that users can authenticate if the internet connection TO THE on-premises Active Directory is unavailable If there is no internet in On-Premises the other two methods will not work, but he can still sign-in through Azure with first method.
upvoted 4 times
...
AMMANANA
3 years, 11 months ago
Ans: B Pass through Explanation Since here users should still be able to authenticate even if the internet connection is not available, you must use Pass-through authentication. This would ensure users are authenticated via the on-premises Active Directory setup.
upvoted 1 times
modiallo
3 years, 9 months ago
Ans is A: Azure AD Pass-through Authentication. Provides a simple password validation for Azure AD authentication services by using a software agent that **runs on one or more on-premises servers**. The servers validate the users directly with your on-premises Active Directory, which ensures that the password validation doesn't happen in the cloud.
upvoted 1 times
...
...
Rume
3 years, 11 months ago
Correct Answer is Password Hash Sync... Refer: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn scroll down to "Comparing Methods"
upvoted 1 times
...
ashishg2105
3 years, 11 months ago
Incorrect Answer. Answer is B. Since here users should still be able to authenticate even if the internet connection is not available, you must use Pass-through authentication. This would ensure users are authenticated via the on-premises Active Directory setup.
upvoted 2 times
modiallo
3 years, 9 months ago
Ans is A: Azure AD Pass-through Authentication. Provides a simple password validation for Azure AD authentication services by using a software agent that **runs on one or more on-premises servers**. The servers validate the users directly with your on-premises Active Directory, which ensures that the password validation doesn't happen in the cloud.
upvoted 1 times
...
...
bbcz
4 years ago
On Exam 05/01/2021
upvoted 3 times
...
Stan007
4 years, 1 month ago
it should be B. pass-through authentication and Azure AD Seamless Single Sign-On (Azure AD Seamless SSO) Explanation Since here users should still be able to authenticate even if the internet connection is not available, you must use Pass-through authentication. This would ensure users are authenticated via the on-premises Active Directory setup.
upvoted 6 times
Montrealcupid
4 years, 1 month ago
disagree, if the internet connection to the on-premises Active Directory is unavailable, user still need to be able to authenticate with AAD, they have no means to connect to on-prem, pass-through won't work
upvoted 20 times
...
AustinY
4 years, 1 month ago
PT uses on-premises components.
upvoted 3 times
...
modiallo
3 years, 9 months ago
Ans is A: Azure AD Pass-through Authentication. Provides a simple password validation for Azure AD authentication services by using a software agent that **runs on one or more on-premises servers**. The servers validate the users directly with your on-premises Active Directory, which ensures that the password validation doesn't happen in the cloud.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago