← SC-300: identity, access, and operations
02 / 11 · 35 MIN

Hybrid identity and partners

Design authentication and collaboration with explicit dependencies and recovery.

Concept and mechanism

Synchronization and authentication are related but different decisions. Synchronization creates or updates identity representations; authentication validates sign-in. Password hash synchronization enables Entra ID validation using synchronized material without storing plaintext passwords. A local change must reach cloud before the new value can be used on that path. Pass-through authentication uses agents validating against on-premises AD and depends on that path. Federation hands validation to a trusted system. Compare availability, required policy, and operational capability. Preparing PHS as a PTA alternative does not enable automatic failover: the runbook needs a controlled method switch and validation.

Guided application

In a fictional acquisition, disconnected forests can motivate Cloud Sync evaluation. Documentation includes this scenario with agents and cloud orchestration; compare features and limitations before replacing the existing design. Do not infer full Connect Sync equivalence simply because both synchronize identities. For partners, separate the account-managing tenant, resource-hosting tenant, and applicable inbound and outbound rules. Cross-tenant access controls collaboration and permits trust in selected claims such as MFA. That trust does not automatically assign application roles. At handover, provide a map of tenants, owners, dependencies, trust configuration, and recovery actions. Exercise local failure and partner authorization failure as separate situations so the team does not try fixing connectivity by adding privileges.

IN PRACTICE

PHS prepared, PTA unavailable, and method unchanged: the team still needs to perform the authorized switch.

Common pitfalls

Synchronization as authentication; prepared backup as activated backup; partner MFA as authorization; agents as complete parity.

Related topics: Tenant, scope, and objects · Methods and emergency access · Conditional Access and risk

Take this idea with you

Document who validates, dependencies, and recovery for each access path.

Create account

Reference: Hybrid authentication choices · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately