AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company plans to migrate on-premises applications to Azure. They require users to authenticate using their existing on-premises Active Directory credentials without syncing password hashes to the cloud. Which Microsoft Entra ID authentication method should they use?
⚠ Common exam trap
Many exam-takers confuse Seamless SSO (which is a convenience feature, not an authentication method) with a primary authentication method, or they assume AD FS is required when the real constraint is avoiding password hash sync.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Pass-through Authentication
Pass-through Authentication (PTA) validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud. A lightweight agent on-premises forwards authentication requests to the local domain controller, meeting the requirement to avoid password hash synchronization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID Pass-through Authentication
Why this is correct
Pass-through Authentication (PTA) uses a lightweight agent on a domain-joined server to validate user passwords directly against on-premises Active Directory. Because authentication occurs on-premises, no password hashes are ever transferred to or stored in Microsoft Entra ID, which precisely satisfies the stated requirement to avoid hash sync. PTA is also simpler to deploy than AD FS while still supporting interactive sign-in.
- ✗
Microsoft Entra ID Password Hash Sync
Why it's wrong here
Password Hash Sync (PHS) generates a cryptographic hash of each on-premises password and synchronizes it to Microsoft Entra ID. This means a representation of the password hash is stored in the cloud, directly contradicting the requirement that password hashes not be synchronized to the cloud. Even though PHS enables features like leaked credential detection, the cloud-side presence of hash data makes it unsuitable here.
- ✗
Microsoft Entra ID Federation Services (AD FS)
Why it's wrong here
Active Directory Federation Services (AD FS) can indeed avoid password hash synchronization because authentication is redirected to on-premises AD FS servers. However, AD FS requires deploying and maintaining federation server farms, certificates, and proxy infrastructure, adding significant complexity and cost. For a simple migration that only needs to avoid hash sync, AD FS is an over-engineered solution compared to Pass-through Authentication, which is why it is not the best answer.
- ✗
Microsoft Entra ID Connect with Seamless SSO
Why it's wrong here
Seamless SSO is not an authentication method; it is a feature that can be enabled alongside either Password Hash Sync or Pass-through Authentication to provide silent sign-on on domain-joined devices. By itself, Seamless SSO does not perform password validation, store hashes, or make a decision about where authentication occurs. Therefore, it cannot satisfy the requirement of avoiding password hash sync on its own.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.