You have the following Azure Active Directory (Azure AD) tenants:
Contoso.onmicrosoft.com: Linked to a Microsoft 365 tenant and syncs to an Active Directory forest named contoso.com by using password hash synchronization Contosoazure.onmicrosoft.com: Linked to an Azure subscription named Subscription1 You need to ensure that you can assign the users in contoso.com access to the resources in Subscription1.
What should you do?
A. Create an Azure management group that contains Subscription1.
B. Configure contoso.onmicrosoft.com to use pass-through authentication.
C. Create guest accounts for all the contoso.com users in contosoazure.onmicrosoft.com.
D. Configure Active Directory Federation Services (AD FS) federation between contosoazure.onmicrosoft.com and contoso.com.