Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium
A company is migrating a legacy application to Azure. The application currently runs on Windows Server virtual machines and relies heavily on Active Directory Domain Services (AD DS) for user authentication and authorization. The company wants to minimize changes to the application and continue using existing Group Policies and user accounts. However, they prefer to avoid deploying domain controllers directly in Azure IaaS virtual machines. Which identity solution should be implemented?
- AAzure AD Connect with Azure AD DS
- BAzure Active Directory (Azure AD)
- CAzure Active Directory Domain Services (Azure AD DS)
- DAzure AD Connect with on-premises AD DS
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Connect with on-premises AD DS
To continue using existing Group Policies and user accounts without deploying domain controllers in Azure IaaS, the best approach is to extend the on-premises AD DS to Azure using Azure AD Connect. This synchronizes identities to Azure AD, and the Azure VMs can join the on-premises domain over a VPN or ExpressRoute connection, leveraging the existing AD DS infrastructure.
Why the other options are wrong
- A. This option is redundant; Azure AD Connect syncs to Azure AD, and Azure AD DS is a separate managed domain service. The goal is to avoid deploying DCs in Azure IaaS.
- B. Azure AD is a cloud-native identity service, but it does not support traditional Group Policies or domain-joining of VMs in the same way as on-premises AD DS.
- C. Azure AD Domain Services (Azure AD DS) provides managed domain services but does not directly use or extend existing on-premises Group Policies.
Hybrid AD DS with Azure
Extending an on-premises Active Directory Domain Services (AD DS) to Azure, allowing Azure resources to utilize the existing domain infrastructure.
- Uses Azure AD Connect for identity synchronization
- Azure VMs join the on-premises domain
- Leverages existing Group Policies and user accounts
Memory trick: AD Connect: Bridging your old 'AD' with the 'Cloud'.