AZ-305 Design infrastructure solutions Practice Question
A multinational corporation is designing a hybrid identity solution using Microsoft Entra ID. The company has multiple on-premises Active Directory forests with complex trust relationships. They require that users can authenticate to both cloud and on-premises resources using the same credentials, and they want to minimize changes to the existing infrastructure. Which THREE components should be part of the solution? (Choose three.)
⚠ Common exam trap
The trap here is that candidates often select Microsoft Entra Domain Services (option E) thinking it provides hybrid identity synchronization, but it actually creates a standalone managed domain in Azure that does not sync credentials from on-premises AD forests and cannot handle complex trust relationships.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Connect Sync
Microsoft Entra Connect Sync is correct because it synchronizes user identities from multiple on-premises Active Directory forests to Microsoft Entra ID, enabling single sign-on and unified credential usage across cloud and on-premises resources. It supports complex forest trust relationships by using the source anchor and UPN mapping to ensure each user has a unique identity in the cloud without requiring changes to the existing on-premises infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra Connect Sync
Why this is correct
Microsoft Entra Connect Sync is the foundational synchronization engine that replicates object metadata and credential hashes from on-premises Active Directory forests into Microsoft Entra ID, creating a unified identity for each user across both environments. It uses a rule-based sync engine to handle multiple on-premises forests, merging them into a single Entra tenant and resolving conflicts with a deterministic source anchor. Without this component, neither Password Hash Synchronization nor federation (AD FS) can function, because the user objects must first be provisioned in Entra ID. It is the core service that makes hybrid identity possible.
- ✓
Password hash synchronization
Why this is correct
Password Hash Synchronization (PHS) is a feature of Entra Connect Sync that computes an MD4 hash of the on-premises password, converts it to a form usable by Entra ID, and synchronizes that hash separately from the user object. It serves as a failover authentication mechanism when the federated AD FS service is unavailable, allowing users to sign in using the same credentials they use on-premises. However, PHS is not a standalone identity synchronization engine; it depends on Entra Connect Sync to first create and correlate the user objects. Its role is limited to authentication, not the provisioning or management of identity data itself.
- ✗
Microsoft Entra Connect Health
Why it's wrong here
Microsoft Entra Connect Health is an agent-based monitoring and reporting service that collects telemetry, alerts, and usage data from your on-premises identity infrastructure, including the sync engine, AD FS/WAP servers, and domain controllers. It provides insights into the health and performance of these components but does not participate in the actual synchronization of identities or the authentication flow. Because it is purely an observability tool, it cannot fulfill the role of the core hybrid identity synchronization service. Its presence is valuable for operations but is not a functional prerequisite for identity sync or federation.
- ✓
Active Directory Federation Services (AD FS)
Why this is correct
Active Directory Federation Services (AD FS) is a claims-based identity provider that establishes a federation trust between on-premises AD DS and Microsoft Entra ID, enabling users to authenticate via WS-Fed or SAML protocols and gain a single sign-on experience. It does not synchronize directory data; instead, it relies on Entra Connect Sync to provision the user objects in Entra ID, then handles only the authentication and issuance of security tokens. AD FS is an essential component when organizations require rich policy-based access control or support for non-AD identity providers, but it is not the tool that performs identity synchronization. Thus, it is correct as a component of the hybrid identity architecture, but the core sync role belongs to Entra Connect Sync.
- ✗
Microsoft Entra Domain Services
Why it's wrong here
Microsoft Entra Domain Services provides a managed domain in the cloud, offering services like domain join, group policy, LDAP, and Kerberos/NTLM authentication without deploying domain controllers. It can optionally synchronize users one-way from Microsoft Entra ID into the managed domain, but it does not sync on-premises AD identities into Entra ID; rather, it leverages identities already existing in Entra ID. This means it cannot serve as the hub for on-premises-to-cloud identity synchronization. It also does not support federation or password hash sync in the context of the hybrid identity stack, making it incorrect for this question.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.