Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global manufacturing company is implementing a Zero Trust strategy. They need to integrate existing on-premises applications that use Integrated Windows Authentication (IWA) into their Azure AD-centric identity model without exposing them directly to the internet. The solution must provide secure remote access for employees and partners. Which Azure AD component should the security architect recommend?

  1. AAzure AD B2B Collaboration
  2. BAzure VPN Gateway
  3. CAzure Application Proxy
  4. DAzure AD Connect
Show answer & explanation

Correct answer: C. Azure Application Proxy

Azure AD Application Proxy allows secure remote access to on-premises web applications, including those using IWA, by acting as a reverse proxy. It integrates with Azure AD for authentication and conditional access policies without requiring a VPN or exposing internal network infrastructure.

Why the other options are wrong

  • A. Azure AD B2B Collaboration is for managing external guest users, not for providing secure access to internal applications for employees and partners.
  • B. Azure VPN Gateway creates a secure tunnel to the on-premises network, but Application Proxy offers a more fine-grained, application-specific access without full network exposure.
  • D. Azure AD Connect synchronizes identities between on-premises AD and Azure AD but does not provide remote access to applications.

Azure AD Application Proxy

An Azure AD service that provides secure remote access to on-premises web applications through Azure AD, without requiring a VPN or exposed DMZ servers.

  • Acts as a reverse proxy.
  • Integrates with Azure AD authentication and Conditional Access.
  • Supports various authentication methods, including IWA.
  • No inbound firewall rules needed for on-premises network.

Memory trick: Proxy your apps, not your network.

More Design a Zero Trust strategy and architecture questions