You have the following Azure Active Directory (Azure AD) tenants:
Contoso.onmicrosoft.com: Linked to a Microsoft Office 365 tenant and syncs to an Active Directory forest named contoso.com by using password hash synchronization Contosoazure.onmicrosoft.com: Linked to an Azure subscription named Subscription1 You need to ensure that you can assign the users in contoso.com access to the resources in Subscription1.
What should you do?
A. Associate Subscription1 to contoso.onmicrosoft.com. Reassign all the roles in Subscription1.
B. Configure the existing Azure AD Connect server to sync contoso.com to contosoazure.onmicrosoft.com.
C. Configure contoso.onmicrosoft.com to use pass-through authentication.
D. Configure contosoazure.onmicrosoft.com to use pass-through authentication.