Courseiva
Design infrastructure solutionshardMultiple ChoiceObjective-mapped

Hybrid Identity for MFA and Conditional Access

Your company has a hybrid identity environment using Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You need to design a solution that allows users to authenticate to Azure services using their on-premises credentials and enforce conditional access policies for sensitive applications. The solution must support multi-factor authentication (MFA) using the Microsoft Authenticator app. Which components should you include?

Quick Answer

The correct answer is Microsoft Entra Connect Sync, Microsoft Entra ID, and Conditional Access policies with MFA. This combination works because Entra Connect Sync bridges your on-premises Active Directory with the cloud, replicating user credentials so that authentication occurs against Entra ID while still honoring on-premises password policies. Conditional Access policies then evaluate the sign-in risk and enforce MFA via the Microsoft Authenticator app, which requires a cloud-based authentication method rather than a pass-through or federated flow. On the AZ-305 exam, this scenario tests your understanding of how hybrid identity components layer together for security and compliance; a common trap is choosing Pass-Through Authentication, which cannot natively support the Authenticator app’s push notifications, or adding AD FS unnecessarily. Remember the memory tip: “Sync, Sign, and Secure”—Entra Connect Sync for identity, Entra ID for sign-in, and Conditional Access for securing with MFA.

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing on-premises federation (AD FS) or pass-through authentication, not realizing that Microsoft Entra Connect Sync with Conditional Access is the simplest and most scalable approach for hybrid identity with MFA enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Connect Sync, Microsoft Entra ID, and Conditional Access policies with MFA.

Microsoft Entra Connect Sync synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to authenticate with their on-premises credentials. Conditional Access policies in Microsoft Entra ID can then enforce MFA using the Microsoft Authenticator app for sensitive applications, meeting all requirements without additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Connect Health, Microsoft Entra ID with cloud sync, and Azure AD Identity Protection.

    Why it's wrong here

    Connect Health is for monitoring; cloud sync is for synchronization but does not provide MFA enforcement.

  • Microsoft Entra Connect Sync, Microsoft Entra ID, and Conditional Access policies with MFA.

    Why this is correct

    Connect Sync syncs identities; Entra ID provides authentication and conditional access can require MFA via Authenticator.

  • Active Directory Federation Services (AD FS), Web Application Proxy, and Azure AD Conditional Access.

    Why it's wrong here

    AD FS is on-premises, not necessary; adds complexity.

  • Azure AD Pass-through Authentication, Azure AD Application Proxy, and Azure AD Identity Protection.

    Why it's wrong here

    Pass-through Authentication does not support MFA via Authenticator; Identity Protection is not for MFA enforcement.

About these practice questions

One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-305

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your company is designing a hybrid identity solution that will allow users to authenticate to Azure resources using their on-premises Active Directory credentials. The solution must support multi-factor authentication (MFA) and conditional access policies. Which TWO components should you include?

medium
  • A.Microsoft Entra Connect
  • B.Active Directory Federation Services (AD FS)
  • C.Microsoft Entra ID
  • D.Azure AD Application Proxy
  • E.Microsoft Intune

Why A: Microsoft Entra Connect synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to authenticate with their corporate credentials. Microsoft Entra ID is the cloud-based identity and access management service that processes authentication requests, enforces multi-factor authentication (MFA), and evaluates conditional access policies. Together, they form the core of a hybrid identity solution that supports MFA and conditional access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.