Courseiva

AZ-305 Design business continuity solutions Practice Question

Your company has a hybrid identity solution with Microsoft Entra ID Connect syncing on-premises Active Directory to Microsoft Entra ID. You need to design a business continuity solution for the identity service in case of an on-premises outage. The solution must allow users to authenticate and access cloud applications even if the on-premises domain controllers are unavailable. Which feature should you enable?

⚠ Common exam trap

Test-takers frequently confuse Seamless SSO or Pass-through authentication as providing offline authentication, but neither works without on-premises infrastructure, whereas password hash synchronization is the only option that enables cloud authentication independently of on-premises domain controllers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password hash synchronization

Password hash synchronization (PHS) is the correct choice because it synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, enabling cloud authentication even when on-premises domain controllers are unavailable. During an on-premises outage, users can still authenticate against Entra ID using their synced credentials, ensuring continued access to cloud applications without dependency on local infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Federation with AD FS in a secondary on-premises site

    Why it's wrong here

    Federation with AD FS, even when deployed in a secondary on-premises site, still requires you to run an Active Directory Federation Services (AD FS) farm and a Web Application Proxy (WAP) on Windows Servers inside your own network. AD FS must actively validate the user's password against the on-premises Active Directory, and it relies on federation trust configuration, certificate management, and network availability to Microsoft Entra ID. Because the authentication authority itself resides on-premises, this fails the requirement to enable cloud authentication with no on-premises authentication infrastructure.

  • ✓

    Password hash synchronization

    Why this is correct

    Password hash synchronization (PHS) is the only option that meets the requirement for pure cloud authentication without any on-premises runtime dependency. Microsoft Entra Connect synchronizes a SHA256 hash of the user's AD password (derived from the MD4 hash) to Microsoft Entra ID; at sign-in, Microsoft Entra ID validates the credentials locally in the cloud with no call back to on-premises domain controllers. This eliminates the need for on-premises servers during authentication, while still allowing Microsoft Entra ID to enforce conditional access and other cloud policies.

  • ✗

    Seamless Single Sign-On

    Why it's wrong here

    Seamless Single Sign-On (S-SSO) is not a standalone authentication method—it is an add-on feature that works with either Password Hash Synchronization or Pass-through Authentication. It enables silent sign-in only for domain-joined devices by having Microsoft Entra Connect's computer account in on-premises AD issue a Kerberos ticket to the user. Because that ticket must come from the on-premises domain controller, the process still requires on-premises AD availability and therefore does not satisfy the requirement for authentication with no on-premises dependency.

  • ✗

    Pass-through authentication with an agent in a secondary on-premises site

    Why it's wrong here

    Pass-through authentication (PTA) requires on-premises Authentication Agents that directly validate each user's password against on-premises Active Directory at the moment of sign-in. Even if you place an agent in a secondary on-premises site, the cloud authentication flow still depends on the agent's availability and its ability to reach on-premises domain controllers. If the on-premises site or network path is unavailable, authentication fails; thus PTA does not meet the requirement for fully cloud-based authentication.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.