Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company has several legacy on-premises web applications that use Integrated Windows Authentication (IWA) and are not directly accessible from outside the corporate network. They want to enable secure remote access to these applications for their employees without exposing the internal network directly to the internet or rewriting the applications. Which Azure AD service should be used?

  1. AAzure AD Application Proxy
  2. BAzure AD Domain Services
  3. CAzure AD Connect
  4. DAzure VPN Gateway
Show answer & explanation

Correct answer: A. Azure AD Application Proxy

Azure AD Application Proxy provides secure remote access to on-premises web applications, including those using Integrated Windows Authentication, by routing traffic through an Azure AD connector without opening inbound firewall ports.

Why the other options are wrong

  • B. Azure AD Domain Services provides managed domain services for Azure VMs, not remote access for on-premises apps.
  • C. Azure AD Connect synchronizes identities, it doesn't provide remote access to applications.
  • D. Azure VPN Gateway creates a secure connection to the Azure virtual network, but doesn't specifically publish individual web applications or handle IWA translation for external users.

Azure AD Application Proxy

A feature of Azure AD that provides secure remote access to on-premises web applications.

  • Acts as a reverse proxy, allowing users to access internal apps from anywhere.
  • Requires an on-premises connector to establish an outbound connection to Azure.
  • Supports single sign-on (SSO) and applications using Integrated Windows Authentication (IWA).

Memory trick: Proxy brings your home apps to the world, securely.

More Manage identity and access questions