Hybrid identity authentication methods
Hybrid identity requires an authentication method that supports the integration of AD and Azure AD. Using AD Connect, the following sign-on methods can be configured for users to enable hybrid identity in an organization:
- Azure AD Password Hash Synchronization (PHS)
- Azure AD Pass-Through Authentication (PTA)
- AD Federation Services
The following screenshot shows the sign-on methods and options that are available:
Figure 4.3 – Cloud sign-on methods
The authentication method chosen will depend on the needs of the scenario.
These hybrid identity authentication methods are categorized as cloud authentication and federated authentication.
In the following sections, we’ll discuss each of these authentication methods.
Cloud authentication
With the cloud authentication model, the user’s sign-on credentials are processed by Azure AD as the IDP.
Two sign-on methods are provided...