Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A client is migrating their on-premises services to Azure. They have several legacy applications that require LDAP authentication and integration with their existing on-premises Active Directory Domain Services (AD DS). The client wants to avoid deploying and managing domain controllers in Azure IaaS VMs. Which Azure service should be recommended to facilitate this migration while meeting the authentication requirements?

  1. AAzure AD Connect
  2. BAzure Active Directory (Azure AD)
  3. CAzure AD B2C
  4. DAzure Active Directory Domain Services (Azure AD DS)
Show answer & explanation

Correct answer: D. Azure Active Directory Domain Services (Azure AD DS)

Azure AD Domain Services (Azure AD DS) provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication, compatible with existing AD DS. It eliminates the need to deploy and manage domain controllers in Azure IaaS VMs.

Why the other options are wrong

  • A. Azure AD Connect synchronizes identities between on-premises AD DS and Azure AD but does not provide domain services for Azure-hosted VMs or applications.
  • B. Azure AD is a cloud-native identity service and does not natively support traditional LDAP or Kerberos/NTLM authentication required by many legacy applications.
  • C. Azure AD B2C is for customer-facing applications and does not integrate with corporate on-premises AD DS for internal legacy applications.

Azure AD Domain Services (Azure AD DS)

A managed domain service provided by Azure that offers domain join, group policy, LDAP, Kerberos/NTLM authentication, and DNS, compatible with traditional Active Directory.

  • Provides domain services without IaaS domain controllers.
  • Integrates with existing on-premises AD DS via Azure AD Connect.
  • Supports legacy applications requiring traditional authentication protocols.

Memory trick: Legacy apps in the cloud need a familiar identity door: AD DS.

More Manage Azure identities and governance questions