Entra ID Connect Authentication Pass-Through with Microsoft Defender for Identity

Dalton Reeves 136 Reputation points
2025-04-16T17:34:23.4166667+00:00

I was reviewing options today in regard to Entra ID Connect, currently we use Password Hash Synchronization. However, after review, Pass-through authentication sounds like it would be a better overall user experience but the poor documentation and even worse document linking leaves questions unanswered.

One area states that PTA can't detect or nullifies Entra ID's ability to alert on users with leaked credentials and doesn't work with Entra ID Connect Health -- which sounds as if identity protections and other insights to the health of your tenants identity infrastructure take a big hit, not ideal at all.

I would like to assume that with the implementation of Microsoft Defender for Identity AKA MDI, w/e protections or insights that were otherwise lost with PTA turned on, MDI compensates for and improves/delivers better overall protections with the sensors being installed on the DC(s) etc. -- but there isn't a single shred of info that tells the customer that and it is maddening. They don't even both stating "if you use PTA, it would be in your best interest to use MDI or other Identity Protection Platform".

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
839 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.