Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company with an existing on-premises Active Directory environment plans to migrate some applications to Azure. These applications are critical and require seamless single sign-on (SSO) and LDAP authentication against the same user accounts stored in their on-premises Active Directory. The company wants to avoid deploying and managing domain controllers in Azure IaaS virtual machines. Which Azure AD feature should be implemented to meet these requirements?
- AAzure AD B2B collaboration
- BAzure AD Domain Services (Azure AD DS)
- CAzure AD Connect with Pass-through Authentication (PTA)
- DAzure AD Connect with Password Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Domain Services (Azure AD DS)
Azure AD Domain Services (Azure AD DS) provides managed domain services, including LDAP and Kerberos/NTLM authentication, directly from Azure AD. It synchronizes with an existing Azure AD tenant (which can be synchronized from on-premises AD) and eliminates the need to deploy IaaS domain controllers.
Why the other options are wrong
- A. Azure AD B2B collaboration is for inviting external users, not for providing domain services for internal applications.
- C. PTA enables SSO for modern apps by validating passwords against on-premises AD but does not provide LDAP or Kerberos for Azure-hosted legacy apps.
- D. PHS provides SSO for modern apps but does not offer LDAP or Kerberos/NTLM authentication directly for legacy applications.
Azure AD Domain Services (Azure AD DS)
A managed domain service provided by Microsoft Azure that offers LDAP, Kerberos, and NTLM authentication compatible with legacy applications.
- Provides domain services without managing IaaS DCs.
- Supports LDAP, Kerberos, NTLM authentication.
- Synchronizes with Azure AD (which can be synced from on-prem AD).
Memory trick: DS for Legacy Apps: Domain Services for Direct Support.