AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Microsoft Entra ID and has a hybrid identity deployment with Active Directory Domain Services (AD DS) on-premises. You need to synchronize user identities to Microsoft Entra ID, but you must ensure that password hashes are never stored in the cloud. Which synchronization method should you use?
⚠ Common exam trap
Candidates often confuse Pass-through Authentication with Password Hash Sync, assuming that any synchronization method must store password hashes in the cloud, but PTA avoids this by performing real-time validation without hash storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-through Authentication (PTA)
Pass-through Authentication (PTA) is the correct choice because it validates user passwords directly against on-premises Active Directory without ever storing password hashes in Microsoft Entra ID. This meets the requirement that password hashes are never stored in the cloud, as PTA uses an agent on-premises to authenticate users, and only the validation result is sent to Microsoft Entra ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password Hash Sync
Why it's wrong here
Password Hash Sync (PHS) computes a cryptographic hash of each user's on-premises AD password and writes that hash (actually a hash of the hash) into Entra ID. This means the cloud directory permanently holds password-derived material, which directly violates the requirement that no password hashes be stored in the cloud. Even though PHS is simple and enables features like leaked-credential detection, it is fundamentally incompatible with a no-hash-in-cloud security policy.
- ✗
Federation with AD FS
Why it's wrong here
AD FS federation redirects authentication to an on-premises federation server, so passwords are validated locally and not in the cloud. However, Microsoft Entra Connect still synchronizes user objects, and Password Hash Sync is often enabled by default as a backup authentication method. Even if PHS is explicitly disabled, AD FS adds significant infrastructure and configuration overhead, and it doesn't inherently guarantee that no password hash ever lands in the cloud—making it a less direct and less clean answer than choosing a true no-hash method.
- ✓
Pass-through Authentication (PTA)
Why this is correct
Pass-through Authentication (PTA) is the correct method because it validates users' passwords directly against on-premises Active Directory through a lightweight authentication agent. The password is never written to or stored in Entra ID; it is transmitted to the on-prem agent and only a success/failure response is returned. This satisfies the 'no password hashes in the cloud' requirement exactly and also works with Seamless SSO to provide a user-friendly sign-in experience.
- ✗
Microsoft Entra Connect Cloud Sync
Why it's wrong here
Microsoft Entra Connect Cloud Sync is a synchronization engine, not an authentication method, and by default it uses Password Hash Sync—which stores password hashes in the cloud, violating the policy. While Cloud Sync can be configured to use Pass-through Authentication, the option itself does not specify the authentication method, and merely choosing Cloud Sync does not guarantee hash-free operation. Additionally, Cloud Sync lacks full federation support, so it is not a direct or reliable answer for this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.