Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A global manufacturing company is implementing a Zero Trust strategy. They need to integrate existing on-premises applications that use Integrated Windows Authentication (IWA) into their Azure AD-centric identity model without exposing them directly to the internet. The solution must provide secure remote access for employees and partners. Which Azure AD component should the security architect recommend?
- AAzure AD B2B Collaboration
- BAzure VPN Gateway
- CAzure Application Proxy
- DAzure AD Connect
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Application Proxy
Azure AD Application Proxy allows secure remote access to on-premises web applications, including those using IWA, by acting as a reverse proxy. It integrates with Azure AD for authentication and conditional access policies without requiring a VPN or exposing internal network infrastructure.
Why the other options are wrong
- A. Azure AD B2B Collaboration is for managing external guest users, not for providing secure access to internal applications for employees and partners.
- B. Azure VPN Gateway creates a secure tunnel to the on-premises network, but Application Proxy offers a more fine-grained, application-specific access without full network exposure.
- D. Azure AD Connect synchronizes identities between on-premises AD and Azure AD but does not provide remote access to applications.
Azure AD Application Proxy
An Azure AD service that provides secure remote access to on-premises web applications through Azure AD, without requiring a VPN or exposed DMZ servers.
- Acts as a reverse proxy.
- Integrates with Azure AD authentication and Conditional Access.
- Supports various authentication methods, including IWA.
- No inbound firewall rules needed for on-premises network.
Memory trick: Proxy your apps, not your network.