Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A company is migrating various legacy applications to Azure. These applications rely on traditional Lightweight Directory Access Protocol (LDAP) and Kerberos authentication. The company wants to avoid deploying and managing domain controllers in Azure Virtual Machines. Which Microsoft Entra capability can provide managed domain services for these applications?

  1. AMicrosoft Entra ID Protection
  2. BMicrosoft Entra Domain Services
  3. CMicrosoft Entra Application Proxy
  4. DMicrosoft Entra Connect
Show answer & explanation

Correct answer: B. Microsoft Entra Domain Services

Microsoft Entra Domain Services provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication. It's ideal for lifting and shifting legacy applications to Azure without deploying and managing your own domain controllers.

Why the other options are wrong

  • A. ID Protection detects and remediates identity risks, which is unrelated to domain services for legacy apps.
  • C. Application Proxy provides remote access to on-premises web apps, not managed domain services for Azure VMs.
  • D. Entra Connect synchronizes on-premises AD with Entra ID, not for providing managed domain services in Azure.

Microsoft Entra Domain Services

A managed domain service in Azure that provides AD DS-compatible services (like domain join, Group Policy, LDAP, Kerberos/NTLM) for Azure virtual machines and applications.

  • Eliminates need to deploy/manage AD DCs
  • Integrates with existing Microsoft Entra ID
  • Supports legacy application requirements

Memory trick: Old apps get new life with managed domain magic.

More Describe the capabilities of Microsoft Entra questions