An organization uses Azure AD Connect to synchronize on-premises identities. A security auditor discovers that password hash synchronization is enabled. What is the primary security implication of this feature in a hybrid environment?
Trap 1: It stores plaintext passwords in the Microsoft Entra ID cloud…
PHS does not transmit or store passwords in plaintext. It uses an iterative hashing algorithm to process the on-premises password, creating a hash that is then synchronized to Microsoft Entra ID. This ensures that cleartext credentials are never exposed during the transit or storage process in the cloud.
Trap 2: It requires the on-premises domain controller to be directly…
Microsoft Entra Connect handles the synchronization process via outbound-only connections to Azure. The on-premises domain controllers do not need to be exposed to the internet. The sync service initiates the connection over HTTPS, maintaining the security boundary of the internal network against direct external inbound attacks.
Trap 3: It forces all cloud users to reset their passwords every 90 days.
Password hash synchronization does not dictate or enforce password rotation policies. Password policies are governed by the source of authority, which remains the on-premises Active Directory. Microsoft Entra ID will honor the password policy settings defined within the local domain controllers during the synchronization process.
- A
It stores plaintext passwords in the Microsoft Entra ID cloud repository.
Why it fails: PHS does not transmit or store passwords in plaintext. It uses an iterative hashing algorithm to process the on-premises password, creating a hash that is then synchronized to Microsoft Entra ID. This ensures that cleartext credentials are never exposed during the transit or storage process in the cloud.
- B
It requires the on-premises domain controller to be directly accessible from the internet.
Why it fails: Microsoft Entra Connect handles the synchronization process via outbound-only connections to Azure. The on-premises domain controllers do not need to be exposed to the internet. The sync service initiates the connection over HTTPS, maintaining the security boundary of the internal network against direct external inbound attacks.
- C
It provides a mechanism for cloud-based authentication if the on-premises environment is offline.
PHS allows Microsoft Entra ID to perform authentication locally without requiring a round-trip to the on-premises environment. This provides high availability and disaster recovery for identity services. From a security perspective, this shifts the target from on-premises domain controllers to the Microsoft Entra ID tenant for authentication-based attacks.
- D
It forces all cloud users to reset their passwords every 90 days.
Why it fails: Password hash synchronization does not dictate or enforce password rotation policies. Password policies are governed by the source of authority, which remains the on-premises Active Directory. Microsoft Entra ID will honor the password policy settings defined within the local domain controllers during the synchronization process.