azure ad PTA and PHS signin

testuser7 286 Reputation points
2023-01-05T15:13:40.703+00:00

Hello,

I have 2 verified domains in my AAD tenant i.e., contoso.com and fabrikam.com
and
I have 2 corresponding AD-domains in my Active-directory forest.

When I sync my users from these 2 domains through the single AAD-Connect installation, I want to configure PTA for contoso.com and PHS for fabrikam.com user-base as sign-in method.

Is this set up possible and if YES, please explain how.

Thanks.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-01-05T20:25:31.043+00:00

    Hi @testuser7 ,

    Thanks for your post! It is not currently possible to mix PTA and PHS in one tenant and enable them at the same time. This is because it is only possible to configure these methods via Azure AD Connect, and it only allows you to complete this configuration at the per-tenant level.

    If you have a business case for this requirement though, I would be happy to share this with the product team. There have been some requests in the past for tools that would allow such a thing, but an ETA has not been shared. You can also leave feedback in the Ideas forum. https://feedback.azure.com/

    -

    If the information answered your question, please Accept the answer. This will help us as well as others in the community who might be researching similar information.

    0 comments No comments

  2. testuser7 286 Reputation points
    2023-01-05T20:43:49.667+00:00

    I see...
    @Marilee Turscak-MSFT So what you are saying is, when I am installing and configuring AAD-connect and if I select PHS or PTA on following screen then that means that this setting is applicable to all the directories (domains) that I configure in subsequent screens that I want to sync from various forests. Am I right ??

    276694-image.png


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.