Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A software development company is migrating an older, on-premises ASP.NET web application to Azure. This application uses Integrated Windows Authentication (IWA) and needs to remain accessible to users who are currently in the corporate network. The company wants to avoid re-writing the application's authentication logic. Which Azure AD feature should be used to enable secure remote access to this application?

  1. AAzure AD Connect Health
  2. BAzure AD B2C
  3. CAzure AD Domain Services
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: D. Azure AD Application Proxy

Azure AD Application Proxy allows you to publish on-premises web applications to external users securely. It supports Integrated Windows Authentication (IWA) applications by using Kerberos Constrained Delegation (KCD) to authenticate users to the on-premises application without requiring changes to the application code or a VPN.

Why the other options are wrong

  • A. Azure AD Connect Health monitors the health of identity components, it's not an access solution.
  • B. B2C is for customer-facing applications and does not serve as a proxy for internal on-premises apps.
  • C. Azure AD Domain Services provides managed domain services for Azure VMs, not a proxy for on-premises web applications.

Azure AD Application Proxy

A service that enables secure remote access to on-premises web applications from anywhere, without a VPN.

  • Publishes on-premises apps to Azure AD.
  • Supports Integrated Windows Authentication (IWA).
  • Uses a lightweight connector in the on-premises network.

Memory trick: App Proxy: Publish On-Prem, Protect Remote.

More Manage identity and access questions