Memory hook: Synchronization moves identity data; authentication proves the sign-in.
Must remember
Microsoft Entra Connect Sync and Cloud Sync provide supported directory synchronization with different architectures and feature support. Choose from topology, objects/features, agent deployment and operational requirements. Synchronization success does not prove every sign-in path is healthy.
Password hash synchronization sends a derived representation for cloud authentication; it does not send the user’s plaintext password. Pass-through authentication validates through on-premises agents and depends on that path’s availability. Federation delegates authentication to a trusted identity provider such as AD FS, adding certificate, endpoint and operational dependencies.
Seamless SSO improves the experience for supported domain-connected scenarios; it does not replace MFA or authorization. Migrating from federation to managed authentication requires staged testing of identities, applications, claims, policies and recovery. Keep a documented rollback and emergency-access strategy.
Entra Connect Health helps observe supported hybrid identity components. Investigate synchronization scope, duplicate/conflicting attributes, source authority and provisioning errors when objects diverge. For authentication issues, trace the method actually selected, agent/provider reachability and relevant sign-in logs instead of re-running sync blindly.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reduce dependency on on-premises sign-in infrastructure | Evaluate password hash synchronization for supported requirements. |
| Validate passwords through on-premises agents | Pass-through authentication. |
| External IdP must issue authentication claims | Federation with its operational dependencies. |
Traps
- Directory synchronization and authentication are separate processes.
- Federation is not automatically more secure than managed authentication.
Active recall
1. Does hash synchronization send plaintext passwords?
No; it synchronizes a derived password representation for supported cloud authentication.
2. What dependency does pass-through authentication introduce?
Reachable healthy on-premises authentication agents and their directory path.
3. What does federation delegate?
Authentication to a trusted external identity provider.
4. Why stage a federation migration?
Claims, apps and policy assumptions may differ in the new path.
5. Why inspect source authority?
Editing a synchronized attribute in the wrong place may be overwritten or unsupported.