A company is migrating a legacy application to Azure. The application currently runs on Windows Server VMs and uses an Active Directory Domain Services (AD DS) forest for authentication and authorization. The company wants to extend its existing AD DS to Azure with minimal latency and maintain a single, unified identity management solution. Which Azure identity solution is most appropriate?
- ADeploying domain controllers on Azure VMs
- BAzure Active Directory (Azure AD)
- CAzure AD Connect Health
- DAzure Active Directory Domain Services (Azure AD DS)
Show answer & explanationAnswer & explanation
Correct answer: A. Deploying domain controllers on Azure VMs
Extending an existing on-premises AD DS forest to Azure with minimal latency and a single, unified identity solution is best achieved by deploying additional domain controllers as Azure VMs within virtual networks connected to the on-premises network. This creates a hybrid AD DS environment.
Why the other options are wrong
- B. Azure Active Directory (Azure AD) is a cloud-native identity service, not a direct extension of on-premises AD DS for legacy applications requiring traditional domain join or LDAP.
- C. Azure AD Connect Health is a monitoring service for Azure AD Connect, not an identity solution itself.
- D. Azure Active Directory Domain Services (Azure AD DS) provides managed domain services but operates as a separate domain. It would not extend the existing on-premises AD DS forest directly.
Hybrid AD DS
A hybrid Active Directory Domain Services (AD DS) environment extends an on-premises AD DS forest to Azure by deploying additional domain controllers as Azure Virtual Machines. This allows seamless authentication and authorization for legacy applications in Azure while maintaining a single identity plane.
- Extends existing on-premises AD DS forest
- Deploys AD DS domain controllers on Azure VMs
- Seamless for legacy applications requiring traditional domain services
Memory trick: To make your old AD feel at home in the cloud, just build it a new house (VM) right next door.