Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is migrating its applications to Azure. Some legacy applications require LDAP authentication against on-premises Active Directory. The company wants to extend its on-premises AD to Azure to support these applications without deploying domain controllers in Azure IaaS VMs. Which Azure AD service should be used to provide LDAP authentication for Azure-hosted applications against a managed domain controller equivalent?

  1. AAzure AD Domain Services (Azure AD DS)
  2. BAzure AD Connect
  3. CAzure AD B2C
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: A. Azure AD Domain Services (Azure AD DS)

Azure AD Domain Services (Azure AD DS) provides managed domain services like domain join, LDAP, and Kerberos/NTLM authentication for Azure-hosted applications, effectively extending on-premises AD to Azure without deploying IaaS domain controllers.

Why the other options are wrong

  • B. Azure AD Connect synchronizes identities between on-premises AD and Azure AD, but does not provide managed LDAP services.
  • C. Azure AD B2C is for customer identity and access management, not for extending corporate AD services to Azure applications.
  • D. Azure AD Application Proxy provides secure remote access to on-premises web applications, not LDAP services.

Azure AD Domain Services (Azure AD DS)

A managed domain service in Azure that provides AD-compatible services (LDAP, Kerberos, NTLM) for virtual machines and applications in Azure.

  • Synchronizes with Azure AD (which can be synced from on-premises AD).
  • No need to deploy, manage, or patch domain controllers.
  • Supports domain-join, group policy, LDAP, and Kerberos/NTLM authentication.

Memory trick: Extend AD: Domain Services for legacy, Connect for sync, Proxy for apps.

More Implement an identity management solution questions