Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsHard

A company is migrating a legacy application to Azure. The application currently uses LDAP to authenticate users against an on-premises Active Directory. The company wants to lift and shift the application to Azure Virtual Machines (VMs) and continue using LDAP for authentication without making significant code changes to the application. They also want to avoid deploying and managing domain controllers in Azure. Which Azure service should be used to provide LDAP authentication for the application in Azure?

  1. AAzure AD Application Proxy
  2. BAzure AD Domain Services (AAD DS)
  3. CAzure Active Directory B2C
  4. DAzure AD Connect
Show answer & explanation

Correct answer: B. Azure AD Domain Services (AAD DS)

Azure AD Domain Services (AAD DS) provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication that are fully compatible with Windows Server Active Directory. This allows legacy applications to migrate to Azure VMs and continue using LDAP without deploying and managing your own domain controllers.

Why the other options are wrong

  • A. Azure AD Application Proxy provides secure remote access to on-premises web applications but does not provide LDAP services itself.
  • C. Azure AD B2C is for customer-facing applications and external identities, not for providing LDAP services for internal legacy applications.
  • D. Azure AD Connect synchronizes identities between on-premises AD and Azure AD, but it does not provide LDAP services for applications in Azure.

Azure AD Domain Services (AAD DS)

A managed domain service provided by Azure that offers domain join, group policy, lightweight directory access protocol (LDAP), and Kerberos/NTLM authentication compatible with Windows Server Active Directory.

  • Provides AD-compatible services in Azure without managing DCs
  • Supports legacy applications requiring LDAP, Kerberos, NTLM
  • Synchronizes with Azure AD for user identities

Memory trick: AAD DS is the 'Legacy Bridge' for AD services.

More Design identity, governance, and monitoring solutions questions