certslothcertsloth
SC-300/Topic 02

Microsoft / Associate

Hybrid Identity and Authentication Paths

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Synchronization moves identity data; authentication proves the sign-in.

Must remember

Microsoft Entra Connect Sync and Cloud Sync provide supported directory synchronization with different architectures and feature support. Choose from topology, objects/features, agent deployment and operational requirements. Synchronization success does not prove every sign-in path is healthy.

Password hash synchronization sends a derived representation for cloud authentication; it does not send the user’s plaintext password. Pass-through authentication validates through on-premises agents and depends on that path’s availability. Federation delegates authentication to a trusted identity provider such as AD FS, adding certificate, endpoint and operational dependencies.

Seamless SSO improves the experience for supported domain-connected scenarios; it does not replace MFA or authorization. Migrating from federation to managed authentication requires staged testing of identities, applications, claims, policies and recovery. Keep a documented rollback and emergency-access strategy.

Entra Connect Health helps observe supported hybrid identity components. Investigate synchronization scope, duplicate/conflicting attributes, source authority and provisioning errors when objects diverge. For authentication issues, trace the method actually selected, agent/provider reachability and relevant sign-in logs instead of re-running sync blindly.

Choose under exam pressure

Requirement Choice and reason
Reduce dependency on on-premises sign-in infrastructure Evaluate password hash synchronization for supported requirements.
Validate passwords through on-premises agents Pass-through authentication.
External IdP must issue authentication claims Federation with its operational dependencies.

Traps

  • Directory synchronization and authentication are separate processes.
  • Federation is not automatically more secure than managed authentication.

Active recall

1. Does hash synchronization send plaintext passwords?

No; it synchronizes a derived password representation for supported cloud authentication.

2. What dependency does pass-through authentication introduce?

Reachable healthy on-premises authentication agents and their directory path.

3. What does federation delegate?

Authentication to a trusted external identity provider.

4. Why stage a federation migration?

Claims, apps and policy assumptions may differ in the new path.

5. Why inspect source authority?

Editing a synchronized attribute in the wrong place may be overwritten or unsupported.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.