Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company plans to migrate on-premises applications to Azure. They require users to authenticate using their existing on-premises Active Directory credentials without syncing password hashes to the cloud. Which Microsoft Entra ID authentication method should they use?

⚠ Common exam trap

Many exam-takers confuse Seamless SSO (which is a convenience feature, not an authentication method) with a primary authentication method, or they assume AD FS is required when the real constraint is avoiding password hash sync.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Pass-through Authentication

Pass-through Authentication (PTA) validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud. A lightweight agent on-premises forwards authentication requests to the local domain controller, meeting the requirement to avoid password hash synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID Pass-through Authentication

    Why this is correct

    Pass-through Authentication (PTA) uses a lightweight agent on a domain-joined server to validate user passwords directly against on-premises Active Directory. Because authentication occurs on-premises, no password hashes are ever transferred to or stored in Microsoft Entra ID, which precisely satisfies the stated requirement to avoid hash sync. PTA is also simpler to deploy than AD FS while still supporting interactive sign-in.

  • ✗

    Microsoft Entra ID Password Hash Sync

    Why it's wrong here

    Password Hash Sync (PHS) generates a cryptographic hash of each on-premises password and synchronizes it to Microsoft Entra ID. This means a representation of the password hash is stored in the cloud, directly contradicting the requirement that password hashes not be synchronized to the cloud. Even though PHS enables features like leaked credential detection, the cloud-side presence of hash data makes it unsuitable here.

  • ✗

    Microsoft Entra ID Federation Services (AD FS)

    Why it's wrong here

    Active Directory Federation Services (AD FS) can indeed avoid password hash synchronization because authentication is redirected to on-premises AD FS servers. However, AD FS requires deploying and maintaining federation server farms, certificates, and proxy infrastructure, adding significant complexity and cost. For a simple migration that only needs to avoid hash sync, AD FS is an over-engineered solution compared to Pass-through Authentication, which is why it is not the best answer.

  • ✗

    Microsoft Entra ID Connect with Seamless SSO

    Why it's wrong here

    Seamless SSO is not an authentication method; it is a feature that can be enabled alongside either Password Hash Sync or Pass-through Authentication to provide silent sign-on on domain-joined devices. By itself, Seamless SSO does not perform password validation, store hashes, or make a decision about where authentication occurs. Therefore, it cannot satisfy the requirement of avoiding password hash sync on its own.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.