Chapter 3
We should consider which technologies to use for performing authentication. Because the customer needs a resilient system that would not be affected by communications outages, PHS would be a good choice because it does not require an always-on connection between the two environments.
For two-factor authentication, we should enable MFA but with a defined IP range for Mega Corp's networks to prevent prompts when signing in from an office. We would also enable Seamless SSO to remove any credential prompts when accessing Azure apps from these locations.
This example scenario highlights how you can use the different authentication tools in Azure to meet different requirements; however, the presented solution is only one possible option.