Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is migrating its applications to Azure. Some legacy applications require LDAP authentication and rely on Kerberos for single sign-on within a domain. These applications are being containerized and deployed to Azure Kubernetes Service (AKS). The company wants to leverage Azure AD identities for these applications without deploying and managing traditional domain controllers in Azure VMs. Which Azure service should be implemented?

  1. AAzure AD Connect
  2. BAzure AD Identity Protection
  3. CAzure AD Application Proxy
  4. DAzure AD Domain Services (Azure AD DS)
Show answer & explanation

Correct answer: D. Azure AD Domain Services (Azure AD DS)

Azure AD Domain Services (Azure AD DS) provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication. This allows legacy applications to use Azure AD identities without deploying traditional domain controllers.

Why the other options are wrong

  • A. Azure AD Connect synchronizes identities; it doesn't provide LDAP/Kerberos services directly to applications.
  • B. Identity Protection focuses on risk detection, not domain services.
  • C. Application Proxy provides secure remote access to web applications, not domain services for containerized apps.

Azure AD Domain Services (Azure AD DS)

A managed domain service provided by Microsoft Azure that offers domain services functionality (like LDAP, Kerberos, group policy) compatible with traditional Active Directory, without the need to deploy and manage domain controllers.

  • Enables lift-and-shift of legacy applications to Azure.
  • Integrates with your existing Azure AD tenant.
  • Supports LDAP, Kerberos, NTLM, and Group Policy.

Memory trick: Legacy apps find a home with Azure AD DS.

More Implement an identity management solution questions