Upgrading Your Skills to MCSA Windows Server 2012 — Question 42
You administer an Active Directory Domain Services forest that includes an Active Directory Federation Services (AD FS) server and Azure Active Directory. The fully qualified domain name of the AD FS server is adfs.contoso.com.
You must implement single sign-on (SSO) for a cloud application that is hosted in Azure. All domain users must be able to use SSO to access the application. You need to configure SSO for the application.
Which two actions should you perform? Each correct answer presents part of the solution.
Answer options
- A. Use the Azure Active Directory Synchronization tool to configure user synchronization.
- B. Use the AD FS Configuration wizard to specify the domain and administrator for the Azure Active Directory service.
- C. Create a trust between AD FS and Azure Active Directory.
- D. In the Azure management portal, activate directory synchronization.
Correct answer: A, C
Explanation
The correct steps to configure SSO involve using the Azure Active Directory Synchronization tool to ensure users are synchronized and establishing a trust relationship between AD FS and Azure Active Directory. The other options either do not contribute directly to SSO configuration or are unnecessary steps for this scenario.