Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsHard
A company is migrating a legacy application to Azure. The application currently runs on Windows Server and relies heavily on Active Directory Domain Services (AD DS) for authentication and authorization. The company wants to maintain a single identity plane across on-premises and Azure, allowing users to use their existing credentials. The solution must minimize administrative overhead and avoid deploying domain controllers in Azure. Which Azure identity solution should be used?
- AAzure AD B2C
- BAzure Active Directory (Azure AD)
- CAzure AD Connect and Azure AD DS
- DAzure AD Connect and on-premises AD DS
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD Connect and Azure AD DS
Azure AD Connect synchronizes on-premises AD DS identities to Azure AD. Azure AD DS (Domain Services) provides managed domain services compatible with Windows Server AD DS, allowing legacy applications to use traditional Kerberos/NTLM authentication without deploying and managing domain controllers in Azure. This combination fulfills all requirements.
Why the other options are wrong
- A. Azure AD B2C is for customer-facing applications (Business-to-Consumer) and is not designed for integrating internal enterprise legacy applications with on-premises AD DS identities.
- B. Azure Active Directory is a cloud-native identity service, but it does not natively support Kerberos/NTLM or LDAP required by many legacy Windows Server applications. It's for modern applications.
- D. Using Azure AD Connect with only on-premises AD DS means the Azure resources would still need line-of-sight to on-premises domain controllers, which can introduce latency, dependency, and might not be ideal for minimizing administrative overhead in Azure.
Azure AD Connect with Azure AD DS
A hybrid identity solution where Azure AD Connect synchronizes identities from on-premises AD DS to Azure AD, and Azure AD Domain Services provides managed domain controllers in Azure for legacy applications.
- Extends on-premises AD DS to Azure without deploying DCs.
- Supports Kerberos, NTLM, and LDAP for legacy apps.
- Managed service, reduces administrative overhead.
Memory trick: Connect + AD DS: 'Connect' your old 'AD' to the new 'DS' in the cloud.