Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A company is migrating various legacy applications to Azure and needs to provide managed domain services, such as domain join, group policy, and LDAP authentication, without deploying and maintaining domain controllers in Azure VMs. Which Microsoft Entra capability should they use?
- AMicrosoft Entra Domain Services
- BMicrosoft Entra Application Proxy
- CMicrosoft Entra PIM
- DMicrosoft Entra Connect
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Entra Domain Services
Microsoft Entra Domain Services provides managed domain services in Azure, compatible with traditional Active Directory features like domain join, group policy, LDAP, and Kerberos/NTLM authentication, without the need to deploy and manage domain controllers.
Why the other options are wrong
- B. Application Proxy provides remote access to on-premises apps, not managed domain services.
- C. PIM manages privileged roles, unrelated to providing domain services.
- D. Entra Connect synchronizes on-premises AD, it doesn't provide managed domain services in Azure.
Microsoft Entra Domain Services
A managed domain service provided by Microsoft Entra ID that offers compatibility with traditional Active Directory features for applications requiring LDAP, Kerberos, NTLM, and Group Policy in Azure.
- Provides managed domain services in Azure.
- Compatible with traditional AD features (LDAP, Kerberos, NTLM, GPO).
- Eliminates the need to deploy/manage domain controllers in Azure VMs.
Memory trick: Domain Services: Your AD 'domain' in the Azure 'cloud', managed for you.