Courseiva

Hybrid Identity for MFA and Conditional Access

Your company is designing a hybrid identity solution that will allow users to authenticate to Azure resources using their on-premises Active Directory credentials. The solution must support multi-factor authentication (MFA) and conditional access policies. Which TWO components should you include?

⚠ Common exam trap

Candidates often assume AD FS is mandatory for hybrid identity with MFA and conditional access, but Microsoft Entra Connect combined with Microsoft Entra ID natively supports these features without federation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Connect

Microsoft Entra Connect synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to authenticate with their corporate credentials. Microsoft Entra ID is the cloud-based identity and access management service that processes authentication requests, enforces multi-factor authentication (MFA), and evaluates conditional access policies. Together, they form the core of a hybrid identity solution that supports MFA and conditional access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Connect

    Why this is correct

    Microsoft Entra Connect is the synchronization engine that replicates on-premises Active Directory Domain Services (AD DS) objects and hashed password or pass-through authentication information to Microsoft Entra ID. It enables users to sign in to Azure resources with their corporate AD credentials without needing a separate cloud account, and supports Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and Seamless SSO as managed authentication options. This makes it the correct component because it establishes the identity bridge between the on-premises directory and Entra ID, which is the tenant that authenticates Azure resource access.

  • ✗

    Active Directory Federation Services (AD FS)

    Why it's wrong here

    Active Directory Federation Services (AD FS) is not required for authenticating users to Microsoft Entra ID-backed Azure resources while supporting Microsoft Entra MFA and Conditional Access. Its primary role is as an on-premises identity provider, often used for federating authentication to third-party SaaS applications or complex on-premises scenarios requiring an on-premises authentication authority. For this question's requirements, leveraging Microsoft Entra ID's native authentication capabilities via Microsoft Entra Connect (e.g., Password Hash Synchronisation or Pass-through Authentication) provides a more direct and integrated solution for Azure resource access.

  • ✓

    Microsoft Entra ID

    Why this is correct

    Microsoft Entra ID is the cloud-based identity and access management service that actually authenticates users, issues tokens for Azure Resource Manager, and enforces security controls like MFA, Conditional Access, and sign-in risk policies. In a hybrid design, Entra ID is the control plane that determines whether a synchronized user can access Office 365 or Azure management portals, and it keeps the authentication authority in the cloud rather than on-premises. It is correct because no Azure access occurs without Entra ID, and Entra Connect exists solely to populate it with identities.

  • ✗

    Microsoft Entra application proxy

    Why it's wrong here

    Microsoft Entra application proxy is a reverse proxy service that securely publishes on-premises web applications to remote users by pre-authenticating them through Microsoft Entra ID and then forwarding traffic through an outbound connector. It does not sync directory objects, store credentials, or act as an identity provider, so it only solves remote access to legacy apps, not the core requirement of establishing a hybrid identity boundary. Selecting it would leave on-premises identities unrepresented in Entra ID and would not support MFA or Conditional Access for Azure resource authentication.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based Enterprise Mobility Management (EMM) and Mobile Device Management (MDM) service that enforces device compliance, configuration, and application management on enrolled devices. It can feed device compliance signals into Conditional Access policies and integrate with Entra ID for managed devices, but it performs no authentication, no password verification, and no directory synchronization. Intune is therefore incorrect because it complements identity security but does not provide any part of the identity foundation required by the scenario.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.