Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is migrating its applications to Azure. Some legacy applications require LDAP authentication against on-premises Active Directory. The company wants to extend its on-premises AD to Azure to support these applications without deploying domain controllers in Azure IaaS VMs. Which Azure AD service should be used to provide LDAP authentication for Azure-hosted applications against a managed domain controller equivalent?
- AAzure AD Domain Services (Azure AD DS)
- BAzure AD Connect
- CAzure AD B2C
- DAzure AD Application Proxy
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD Domain Services (Azure AD DS)
Azure AD Domain Services (Azure AD DS) provides managed domain services like domain join, LDAP, and Kerberos/NTLM authentication for Azure-hosted applications, effectively extending on-premises AD to Azure without deploying IaaS domain controllers.
Why the other options are wrong
- B. Azure AD Connect synchronizes identities between on-premises AD and Azure AD, but does not provide managed LDAP services.
- C. Azure AD B2C is for customer identity and access management, not for extending corporate AD services to Azure applications.
- D. Azure AD Application Proxy provides secure remote access to on-premises web applications, not LDAP services.
Azure AD Domain Services (Azure AD DS)
A managed domain service in Azure that provides AD-compatible services (LDAP, Kerberos, NTLM) for virtual machines and applications in Azure.
- Synchronizes with Azure AD (which can be synced from on-premises AD).
- No need to deploy, manage, or patch domain controllers.
- Supports domain-join, group policy, LDAP, and Kerberos/NTLM authentication.
Memory trick: Extend AD: Domain Services for legacy, Connect for sync, Proxy for apps.