Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company is migrating its on-premises applications to Azure. These applications currently use Active Directory Domain Services (AD DS) for authentication. The company wants to lift and shift these applications without modifying their authentication code. Which Azure service should they use?

  1. AAzure Active Directory Domain Services (Azure AD DS)
  2. BAzure AD B2C
  3. CAzure AD Connect
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: A. Azure Active Directory Domain Services (Azure AD DS)

Azure AD Domain Services (Azure AD DS) provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication that are fully compatible with existing Active Directory-aware applications, allowing for a lift-and-shift migration without code changes.

Why the other options are wrong

  • B. Azure AD B2C is for customer-facing applications, not for enterprise lift-and-shift of AD-dependent apps.
  • C. Azure AD Connect synchronizes on-premises AD with Azure AD, not a managed domain service.
  • D. Azure AD Application Proxy provides secure remote access to on-premises web apps, not a domain service itself.

Azure AD Domain Services (Azure AD DS)

A managed domain service provided by Azure that offers compatibility with traditional Active Directory Domain Services (AD DS) for applications requiring features like domain join, group policy, LDAP, and Kerberos/NTLM authentication.

  • Provides managed domain controllers as a service
  • Compatible with Kerberos, NTLM, LDAP, Group Policy
  • Enables lift-and-shift of AD-dependent applications to Azure

Memory trick: AD DS in Azure lets old apps feel right at home.

More Manage Azure identities and governance questions