AZ-305 Design infrastructure solutions Practice Question
Your company has a hybrid identity environment with Microsoft Entra ID and an on-premises Active Directory. You need to enable single sign-on (SSO) for users accessing Microsoft 365 applications from domain-joined devices. Which authentication method should you configure?
⚠ Common exam trap
Test-takers frequently confuse authentication methods that validate credentials (like Pass-through Authentication or password hash sync) with methods that provide single sign-on, forgetting that SSO requires a separate mechanism like Seamless SSO or federation to eliminate credential prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Seamless SSO
Microsoft Entra Seamless SSO (C) is the correct choice because it automatically signs users in when they are on domain-joined devices connected to the corporate network, without requiring any additional prompts. It integrates with password hash synchronization or pass-through authentication to provide a true single sign-on experience for Microsoft 365 applications, leveraging Kerberos delegation to validate the user's identity against on-premises Active Directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Pass-through Authentication
Why it's wrong here
Microsoft Entra Pass-through Authentication is an authentication method that validates a user's password directly against on-premises Active Directory, but it does not, by itself, provide single sign-on. When PTA is enabled alone, users are still prompted for their credentials when accessing Microsoft Entra ID resources, because no SSO token or Kerberos-based sign-on is issued. Seamless SSO is a separate feature that can be enabled alongside PTA to deliver automatic sign-on for domain-joined devices; PTA alone cannot satisfy the SSO requirement.
- ✗
Microsoft Entra password hash synchronization
Why it's wrong here
Microsoft Entra password hash synchronization synchronizes a hash of the on-premises password hash to Microsoft Entra ID, allowing cloud authentication to verify the password against that synced hash. However, PHS is purely an authentication synchronization mechanism and does not perform single sign-on; users must still enter their credentials when accessing Microsoft Entra ID applications. While Seamless SSO can be enabled on top of PHS to create a silent sign-in experience, PHS by itself does not provide SSO and is therefore not the correct answer for a scenario requiring automatic sign-on.
- ✓
Microsoft Entra Seamless SSO
Why this is correct
Microsoft Entra Seamless SSO is the correct feature because it automatically signs in domain-joined devices when users access Microsoft Entra ID resources while they are connected to the corporate network. It uses the on-premises Active Directory computer account of the user's device to obtain a Kerberos ticket, which is then presented to Microsoft Entra ID through a non-interactive flow, eliminating the need for password prompts. Seamless SSO can be combined with either PHS or PTA and specifically addresses the hybrid identity need for frictionless access without deploying additional federation infrastructure.
- ✗
Active Directory Federation Services (AD FS)
Why it's wrong here
Active Directory Federation Services (AD FS) is a claims-based identity federation service that can deliver single sign-on by issuing security tokens after authenticating the user. While AD FS technically satisfies an SSO requirement, deploying and managing AD FS involves significant infrastructure: federation servers, proxies, certificates, and WS-Fed/SAML protocol configuration. In a modern hybrid identity setup, Microsoft Entra Seamless SSO provides the same user-visible SSO outcome with far less operational overhead, making AD FS an over-engineered and unnecessary choice for this scenario.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.