Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your company has a hybrid identity environment with Microsoft Entra ID and an on-premises Active Directory. You need to enable single sign-on (SSO) for users accessing Microsoft 365 applications from domain-joined devices. Which authentication method should you configure?

⚠ Common exam trap

Test-takers frequently confuse authentication methods that validate credentials (like Pass-through Authentication or password hash sync) with methods that provide single sign-on, forgetting that SSO requires a separate mechanism like Seamless SSO or federation to eliminate credential prompts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Seamless SSO

Microsoft Entra Seamless SSO (C) is the correct choice because it automatically signs users in when they are on domain-joined devices connected to the corporate network, without requiring any additional prompts. It integrates with password hash synchronization or pass-through authentication to provide a true single sign-on experience for Microsoft 365 applications, leveraging Kerberos delegation to validate the user's identity against on-premises Active Directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Pass-through Authentication

    Why it's wrong here

    Microsoft Entra Pass-through Authentication is an authentication method that validates a user's password directly against on-premises Active Directory, but it does not, by itself, provide single sign-on. When PTA is enabled alone, users are still prompted for their credentials when accessing Microsoft Entra ID resources, because no SSO token or Kerberos-based sign-on is issued. Seamless SSO is a separate feature that can be enabled alongside PTA to deliver automatic sign-on for domain-joined devices; PTA alone cannot satisfy the SSO requirement.

  • ✗

    Microsoft Entra password hash synchronization

    Why it's wrong here

    Microsoft Entra password hash synchronization synchronizes a hash of the on-premises password hash to Microsoft Entra ID, allowing cloud authentication to verify the password against that synced hash. However, PHS is purely an authentication synchronization mechanism and does not perform single sign-on; users must still enter their credentials when accessing Microsoft Entra ID applications. While Seamless SSO can be enabled on top of PHS to create a silent sign-in experience, PHS by itself does not provide SSO and is therefore not the correct answer for a scenario requiring automatic sign-on.

  • ✓

    Microsoft Entra Seamless SSO

    Why this is correct

    Microsoft Entra Seamless SSO is the correct feature because it automatically signs in domain-joined devices when users access Microsoft Entra ID resources while they are connected to the corporate network. It uses the on-premises Active Directory computer account of the user's device to obtain a Kerberos ticket, which is then presented to Microsoft Entra ID through a non-interactive flow, eliminating the need for password prompts. Seamless SSO can be combined with either PHS or PTA and specifically addresses the hybrid identity need for frictionless access without deploying additional federation infrastructure.

  • ✗

    Active Directory Federation Services (AD FS)

    Why it's wrong here

    Active Directory Federation Services (AD FS) is a claims-based identity federation service that can deliver single sign-on by issuing security tokens after authenticating the user. While AD FS technically satisfies an SSO requirement, deploying and managing AD FS involves significant infrastructure: federation servers, proxies, certificates, and WS-Fed/SAML protocol configuration. In a modern hybrid identity setup, Microsoft Entra Seamless SSO provides the same user-visible SSO outcome with far less operational overhead, making AD FS an over-engineered and unnecessary choice for this scenario.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.