Tech Talk 7 – AD FS oder PTA

Thomas‘ Tech Talk 7: Microsoft 365 und Azure AD unterstützen unterschiedliche Modelle für Benutzeridentitäten. Bei der Synchronisation von Konten aus einem lokalen Active Directory wird standardmäßig die Kennwort-Synchronisierung (PHS) verwendet. Wenn Sie keine Kennwort-Hashes synchronisieren möchten, haben Sie zwei Möglichkeiten, Entweder nutzen Sie föderierte Authentifizierung mit AD FS oder Pass-Through-Authentifizierung (PTA).

Register Azure AD PTA agent manually

Azure AD Pass-through authentication (PTA) recommends that you run at least three authentication agents to provide high availability for authentication.

When you download and install the PTA agent, registering the PTA agent to Azure AD might fail. This happens most of the time when the network connectivity to Azure AD requires the use of a proxy server.