Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is integrating an older, on-premises web application into Azure AD for single sign-on. This application uses Integrated Windows Authentication (IWA) and is only accessible from within the corporate network. The company wants to allow external users to securely access this application via the internet using their Azure AD credentials. Which Azure AD service should be deployed?

  1. AAzure AD Pass-through Authentication (PTA)
  2. BAzure AD Connect Health
  3. CAzure AD B2B Collaboration
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: D. Azure AD Application Proxy

Azure AD Application Proxy provides secure remote access to on-premises web applications. It acts as a reverse proxy, allowing users to access internal web apps from outside the corporate network using their Azure AD credentials, and it supports IWA applications.

Why the other options are wrong

  • A. Azure AD Pass-through Authentication (PTA) is an authentication method for Azure AD, not a service for exposing on-premises applications externally.
  • B. Azure AD Connect Health monitors the health of Azure AD Connect and other identity components, not for application access.
  • C. Azure AD B2B Collaboration is for inviting guest users, not for providing external access to internal web applications.

Azure AD Application Proxy

A service that provides secure remote access to on-premises web applications, allowing users to access them from outside the corporate network using their Azure AD credentials.

  • Acts as a reverse proxy.
  • Supports IWA, header-based, and form-based authentication.
  • No VPN required for external users.

Memory trick: Application Proxy is your secure bridge to on-prem apps from the outside world.

More Manage identity and access questions