AZ-305 Design business continuity solutions Practice Question
Your company has a hybrid identity solution with Microsoft Entra ID Connect syncing on-premises Active Directory to Microsoft Entra ID. You need to design a business continuity solution for the identity service in case of an on-premises outage. The solution must allow users to authenticate and access cloud applications even if the on-premises domain controllers are unavailable. Which feature should you enable?
⚠ Common exam trap
Test-takers frequently confuse Seamless SSO or Pass-through authentication as providing offline authentication, but neither works without on-premises infrastructure, whereas password hash synchronization is the only option that enables cloud authentication independently of on-premises domain controllers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password hash synchronization
Password hash synchronization (PHS) is the correct choice because it synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, enabling cloud authentication even when on-premises domain controllers are unavailable. During an on-premises outage, users can still authenticate against Entra ID using their synced credentials, ensuring continued access to cloud applications without dependency on local infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Federation with AD FS in a secondary on-premises site
Why it's wrong here
Federation with AD FS, even when deployed in a secondary on-premises site, still requires you to run an Active Directory Federation Services (AD FS) farm and a Web Application Proxy (WAP) on Windows Servers inside your own network. AD FS must actively validate the user's password against the on-premises Active Directory, and it relies on federation trust configuration, certificate management, and network availability to Microsoft Entra ID. Because the authentication authority itself resides on-premises, this fails the requirement to enable cloud authentication with no on-premises authentication infrastructure.
- ✓
Password hash synchronization
Why this is correct
Password hash synchronization (PHS) is the only option that meets the requirement for pure cloud authentication without any on-premises runtime dependency. Microsoft Entra Connect synchronizes a SHA256 hash of the user's AD password (derived from the MD4 hash) to Microsoft Entra ID; at sign-in, Microsoft Entra ID validates the credentials locally in the cloud with no call back to on-premises domain controllers. This eliminates the need for on-premises servers during authentication, while still allowing Microsoft Entra ID to enforce conditional access and other cloud policies.
- ✗
Seamless Single Sign-On
Why it's wrong here
Seamless Single Sign-On (S-SSO) is not a standalone authentication method—it is an add-on feature that works with either Password Hash Synchronization or Pass-through Authentication. It enables silent sign-in only for domain-joined devices by having Microsoft Entra Connect's computer account in on-premises AD issue a Kerberos ticket to the user. Because that ticket must come from the on-premises domain controller, the process still requires on-premises AD availability and therefore does not satisfy the requirement for authentication with no on-premises dependency.
- ✗
Pass-through authentication with an agent in a secondary on-premises site
Why it's wrong here
Pass-through authentication (PTA) requires on-premises Authentication Agents that directly validate each user's password against on-premises Active Directory at the moment of sign-in. Even if you place an agent in a secondary on-premises site, the cloud authentication flow still depends on the agent's availability and its ability to reach on-premises domain controllers. If the on-premises site or network path is unavailable, authentication fails; thus PTA does not meet the requirement for fully cloud-based authentication.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.