Enable Single Sign-On for Azure AD and AD DS | AZ-301 Exam Answer

Enable Single Sign-On for Azure AD and AD DS

Question

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an on-premises Active Directory Domain Services (AD DS) domain and an established Azure Active Directory (Azure AD) environment.

Your company would like users to be automatically signed in to cloud apps when they are on their corporate desktops that are connected to the corporate network.

You need to enable single sign-on (SSO) for company users.

Solution: Install and configure an Azure AD Connect server to use password hash synchronization and select the Enable single sign-on option.

Does the solution meet the goal?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B.

A

The proposed solution meets the goal of enabling single sign-on (SSO) for company users.

Single sign-on (SSO) allows users to access multiple applications with a single set of login credentials. This can improve security and user experience by reducing the need for users to remember and enter multiple usernames and passwords.

The solution involves installing and configuring an Azure AD Connect server. Azure AD Connect is a tool that synchronizes identity data between on-premises AD DS and Azure AD. By using password hash synchronization, passwords are securely synchronized from on-premises AD to Azure AD, which enables users to sign in to cloud apps using their on-premises AD credentials.

Enabling the "Enable single sign-on" option in Azure AD Connect ensures that users are automatically signed in to cloud apps when they are on their corporate desktops that are connected to the corporate network. This is achieved by using the Kerberos protocol to authenticate users against their on-premises AD domain controller.

Therefore, the proposed solution of installing and configuring an Azure AD Connect server to use password hash synchronization and selecting the "Enable single sign-on" option meets the goal of enabling SSO for company users. Hence, the answer is A. Yes.