Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is migrating its on-premises applications to Azure. Many of these applications rely on Lightweight Directory Access Protocol (LDAP) for authentication and cannot be easily re-architected to use modern authentication protocols. The company needs to minimize changes to these legacy applications while providing secure access in Azure.

  1. AMigrate applications to use Azure AD Application Proxy.
  2. BImplement Azure AD Connect to synchronize identities to Azure AD.
  3. CDeploy Azure AD Domain Services (Azure AD DS).
  4. DRe-write applications to use OAuth 2.0 with Azure AD.
Show answer & explanation

Correct answer: C. Deploy Azure AD Domain Services (Azure AD DS).

Azure AD Domain Services provides managed domain services, including LDAP, compatible with Active Directory, allowing legacy applications to authenticate against Azure AD without re-architecting.

Why the other options are wrong

  • A. Application Proxy provides remote access to on-premises apps but doesn't solve the LDAP authentication requirement for apps within Azure.
  • B. Azure AD Connect synchronizes identities but doesn't provide an LDAP endpoint for applications.
  • D. Re-writing applications is explicitly what the company wants to avoid due to cost and effort.

Azure AD Domain Services (Azure AD DS)

Azure AD DS provides managed domain services like domain join, group policy, LDAP, and Kerberos/NTLM authentication, compatible with Active Directory, for cloud-based applications.

  • Provides LDAP for legacy applications.
  • Managed service, no domain controllers to manage.
  • Integrates with existing Azure AD tenant.

Memory trick: Azure AD DS is the bridge for old apps to live in the cloud.

More Implement an identity management solution questions