Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsHard
A large enterprise is migrating its legacy applications to Azure. These applications rely heavily on Kerberos and NTLM authentication and require domain join capabilities. The enterprise does not want to manage domain controllers in Azure but needs to extend its on-premises Active Directory functionality to support these applications in the cloud seamlessly. Which Azure service should be implemented?
- AAzure AD Connect
- BAzure AD B2B
- CAzure AD Domain Services (AAD DS)
- DAzure Active Directory (Azure AD)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Domain Services (AAD DS)
Azure AD Domain Services (AAD DS) provides managed domain services in Azure, including domain join, group policy, LDAP, and Kerberos/NTLM authentication. It synchronizes with Azure AD (which can be synced from on-premises AD via Azure AD Connect) and eliminates the need to deploy and manage domain controllers in Azure while supporting legacy application requirements.
Why the other options are wrong
- A. Azure AD Connect synchronizes identities but doesn't provide domain services like Kerberos or NTLM authentication directly.
- B. Azure AD B2B is for external collaboration with guest users, not for internal legacy application authentication.
- D. Azure AD alone does not support Kerberos/NTLM or domain join for VMs.
Azure AD Domain Services (AAD DS)
Azure AD Domain Services (AAD DS) provides managed domain services like domain join, group policy, LDAP, Kerberos, and NTLM authentication, compatible with Windows Server Active Directory.
- Eliminates the need to deploy and manage domain controllers in Azure.
- Integrates with your existing Azure AD tenant.
- Supports legacy applications that require traditional AD features.
Memory trick: AAD DS: Your old castle, now in the cloud, fully managed.