Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A client is migrating several on-premises applications that use Integrated Windows Authentication (IWA) to Azure. These applications are critical and must remain accessible to users who are primarily working remotely. The client wants to avoid exposing their internal network directly to the internet. Which Azure AD feature can securely provide remote access to these on-premises IWA applications?

  1. AAzure AD B2C
  2. BAzure AD Application Proxy
  3. CAzure AD Connect Health
  4. DAzure AD Domain Services
Show answer & explanation

Correct answer: B. Azure AD Application Proxy

Azure AD Application Proxy allows remote users to securely access on-premises web applications. It uses an internal connector to establish an outbound connection to Azure AD, eliminating the need to open inbound firewall ports. It also supports Integrated Windows Authentication (IWA) through Kerberos Constrained Delegation (KCD).

Why the other options are wrong

  • A. Azure AD B2C is for customer-facing identity management, not for internal on-premises application access.
  • C. Azure AD Connect Health monitors the health of identity components, it does not provide application access.
  • D. Azure AD Domain Services provides managed domain services in Azure, not remote access to existing on-premises applications.

Azure AD Application Proxy

A service that provides secure remote access to on-premises web applications and other internal resources through Azure AD.

  • Uses an outbound connection from an internal connector, no inbound firewall ports needed.
  • Integrates with Azure AD authentication features like MFA and Conditional Access.
  • Supports various authentication methods, including Integrated Windows Authentication (IWA).

Memory trick: App Proxy opens the secure door for remote access to your internal apps.

More Manage identity and access questions