Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?
Pass-through Authentication with Seamless SSO is not the best option because it uses lightweight agents on-premises to validate passwords directly against Active Directory in real time, rather than synchronizing any password hash to Entra ID. While PTA avoids storing password hashes in the cloud, it introduces a dependency on on-premises agent availability, requires agent high availability planning, and Seamless SSO only provides silent sign-in on domain-joined devices. For a simple migration to cloud authentication, PTA is operationally more complex than PHS and does not allow cloud-based sign-in if the on-premises directory becomes unreachable.
Why this answer
Pass-through Authentication (PTA) validates passwords directly against on-premises Active Directory, ensuring that on-premises password policies (complexity, expiration, lockout) are enforced for cloud sign-ins. PHS merely synchronizes password hashes to Entra ID and cannot enforce on-premises lockout or account state at authentication time.
Exam trap
The trap is that candidates may think PHS is sufficient because it uses the same password, but the requirement to maintain on-premises policy enforcement during logon points to PTA, not PHS. Seamless SSO is optional and not the deciding factor.
How to eliminate wrong answers
Option B is wrong because Pass-through Authentication with Seamless SSO validates passwords directly against on-premises Active Directory without storing password hashes in the cloud, but it does not maintain password policy enforcement on-premises in a way that differs from PHS—it still relies on on-premises policy, but the question specifically asks for a feature that ensures users can use existing passwords while maintaining on-premises policy enforcement, and PHS is the simplest and most direct solution. Option C is wrong because Active Directory Federation Services (AD FS) is a federation service that redirects authentication to on-premises servers, which adds complexity and requires high-availability infrastructure; it is not the simplest or most appropriate choice when the goal is to use existing passwords without additional federation overhead. Option D is wrong because installing Azure AD Connect with default settings does not automatically enable password synchronization; the default settings only synchronize directory objects, and you must explicitly select the Password Hash Synchronization option to achieve the described goal.