Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsHard

A company is migrating a legacy application to Azure. The application currently runs on Windows Server and relies heavily on Active Directory Domain Services (AD DS) for authentication and authorization. The company wants to maintain a single identity plane across on-premises and Azure, allowing users to use their existing credentials. The solution must minimize administrative overhead and avoid deploying domain controllers in Azure. Which Azure identity solution should be used?

  1. AAzure AD B2C
  2. BAzure Active Directory (Azure AD)
  3. CAzure AD Connect and Azure AD DS
  4. DAzure AD Connect and on-premises AD DS
Show answer & explanation

Correct answer: C. Azure AD Connect and Azure AD DS

Azure AD Connect synchronizes on-premises AD DS identities to Azure AD. Azure AD DS (Domain Services) provides managed domain services compatible with Windows Server AD DS, allowing legacy applications to use traditional Kerberos/NTLM authentication without deploying and managing domain controllers in Azure. This combination fulfills all requirements.

Why the other options are wrong

  • A. Azure AD B2C is for customer-facing applications (Business-to-Consumer) and is not designed for integrating internal enterprise legacy applications with on-premises AD DS identities.
  • B. Azure Active Directory is a cloud-native identity service, but it does not natively support Kerberos/NTLM or LDAP required by many legacy Windows Server applications. It's for modern applications.
  • D. Using Azure AD Connect with only on-premises AD DS means the Azure resources would still need line-of-sight to on-premises domain controllers, which can introduce latency, dependency, and might not be ideal for minimizing administrative overhead in Azure.

Azure AD Connect with Azure AD DS

A hybrid identity solution where Azure AD Connect synchronizes identities from on-premises AD DS to Azure AD, and Azure AD Domain Services provides managed domain controllers in Azure for legacy applications.

  • Extends on-premises AD DS to Azure without deploying DCs.
  • Supports Kerberos, NTLM, and LDAP for legacy apps.
  • Managed service, reduces administrative overhead.

Memory trick: Connect + AD DS: 'Connect' your old 'AD' to the new 'DS' in the cloud.

More Design infrastructure solutions questions