Azure-docs: Password Hash Sync for Pass-through Authentication

Created on 11 Jul 2019  Â·  6Comments  Â·  Source: MicrosoftDocs/azure-docs

Several times on this page, it is indicated that Password Hash Sync can be setup to allow for fail-over for Pass-through Authentication. On the Pass-through Authentication FAQ, it says that it is not the case.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq#does-password-hash-synchronization-act-as-a-fallback-to-pass-through-authentication

Additionally, I can find no where in AADC where adding Password Hash Sync to the Pass-through Auth option, it is just one or the other. There is no option that I can find that relates to this statement - "So it's critical to enable password hash synchronization no matter what authentication method you use, whether that's federated or pass-through authentication."


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

active-directorsvc assigned-to-author doc-provided triaged

Most helpful comment

The FAQ is correct. The key point is "automatic". If you enable PTA and PHS it will not automatically fail-over to use PHS if PTA fails, but an admin can manually switch to PHS if PTA fails. If you previously enabled in PHS, the change will be near instant.

All 6 comments

We have a document that explains how to do this with federation. It is essentially the same if you use PTA. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tutorial-phs-backup

please-close

We have a document that explains how to do this with federation. It is essentially the same if you use PTA. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tutorial-phs-backup

So is the FAQ for PTA incorrect?

The FAQ is correct. The key point is "automatic". If you enable PTA and PHS it will not automatically fail-over to use PHS if PTA fails, but an admin can manually switch to PHS if PTA fails. If you previously enabled in PHS, the change will be near instant.

Thanks for the clarification. The documentation I have found thus far is that I would have to switch to PHS from PTA using AADC. Do you have a link to enabling that without AADC, since that would most likely be offline if Azure couldn't communicate with the PTA connectors? Or is that a service ticket to Azure support?

That will be a service ticket request.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

paulmarshall picture paulmarshall  Â·  3Comments

spottedmahn picture spottedmahn  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments

ianpowell2017 picture ianpowell2017  Â·  3Comments