Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company is migrating its legacy applications to Azure. These applications currently rely on traditional LDAP and Kerberos authentication against an on-premises Active Directory Domain Services (AD DS) environment. The company wants to move these applications to Azure IaaS VMs and ensure they can authenticate against a managed domain service in Azure without requiring a domain controller to be deployed and managed by the company. Which Azure AD feature should be implemented?

  1. AAzure AD Application Proxy
  2. BAzure AD Domain Services (Azure AD DS)
  3. CAzure AD Identity Protection
  4. DAzure AD Connect
Show answer & explanation

Correct answer: B. Azure AD Domain Services (Azure AD DS)

Azure AD Domain Services (Azure AD DS) provides managed domain services, including LDAP and Kerberos, compatible with on-premises Active Directory. It allows legacy applications to authenticate against a domain in Azure without customers needing to deploy or manage their own domain controllers.

Why the other options are wrong

  • A. Azure AD Application Proxy provides secure remote access to on-premises web applications, not a managed domain service for IaaS VMs.
  • C. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on providing domain services for legacy applications.
  • D. Azure AD Connect synchronizes identities between on-premises AD DS and Azure AD, but it does not provide a managed domain service for legacy authentication protocols.

Azure AD Domain Services (Azure AD DS)

Azure AD Domain Services provides managed domain services in Azure, offering compatibility with traditional AD DS features like LDAP, Kerberos, and Group Policy, without the need to deploy and manage domain controllers.

  • Integrates with an existing Azure AD tenant.
  • Supports domain-join for Azure VMs.
  • Enables lift-and-shift of legacy applications requiring traditional AD authentication.

Memory trick: AD DS is the bridge for old apps to live in the cloud.

More Manage Azure identities and governance questions