Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is migrating several legacy applications to Azure. These applications require integrated Windows authentication using Kerberos and LDAP for directory lookups. The company does not want to deploy and manage domain controllers in Azure. Which Azure AD service should they implement to support these legacy application requirements?

  1. AAzure AD Connect
  2. BAzure AD Application Proxy
  3. CAzure AD Identity Protection
  4. DAzure Active Directory Domain Services (Azure AD DS)
Show answer & explanation

Correct answer: D. Azure Active Directory Domain Services (Azure AD DS)

Azure Active Directory Domain Services (Azure AD DS) provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication, which are essential for legacy applications that rely on traditional Active Directory functionalities, without requiring the deployment and management of domain controllers.

Why the other options are wrong

  • A. Azure AD Connect synchronizes identities from on-premises AD to Azure AD, but does not provide managed domain services in Azure.
  • B. Azure AD Application Proxy provides secure remote access to on-premises web applications, not domain services for applications running in Azure.
  • C. Azure AD Identity Protection focuses on risk detection and remediation, not on providing domain services for applications.

Azure AD Domain Services (Azure AD DS)

Provides managed domain services (like domain join, LDAP, Kerberos/NTLM) in Azure, compatible with traditional Active Directory, without deploying domain controllers.

  • Fully managed service, no need to patch/manage DCs.
  • Supports Kerberos, NTLM, and LDAP for legacy apps.
  • Integrates with existing Azure AD tenant for identities.

Memory trick: Legacy apps need DS to 'Do Stuff' in Azure.

More Implement an identity management solution questions