AZ-305 exam dumps

AZ-305 practice question 34 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 34

Single answer

A company hosts a line-of-business web application on-premises that employees can currently access only from within the corporate network. The organization has synchronized its on-premises Active Directory accounts to Azure Active Directory (Azure AD) using password hash synchronization. They want remote employees to access the on-premises web application using their Azure AD credentials and maintain single sign-on (SSO), while minimizing additional infrastructure and management overhead. Which solution should you recommend?

  1. A

    Publish the on-premises application using Azure AD Application Proxy with Kerberos Constrained Delegation for SSO.

  2. B

    Deploy Azure AD Domain Services, migrate the web application servers to Azure, and domain-join them to Azure AD DS.

  3. C

    Implement Azure AD Connect Pass-through Authentication to verify credentials directly against on-premises Active Directory.

  4. D

    Install Active Directory Federation Services (AD FS) in a perimeter network and configure a federation trust with Azure AD.

Show answer and explanation

Correct answer: A

Explanation

Azure AD Application Proxy is often recommended to securely publish on-premises apps for remote users authenticated with Azure AD. By configuring Kerberos Constrained Delegation, you can maintain single sign-on for domain-joined on-premises apps without deploying additional complex infrastructure. This approach aligns with Microsoft best practices for hybrid identity solutions.

  • A. Correct.

    Correct. Azure AD Application Proxy allows secure publishing of on-premises applications for remote access using Azure AD credentials. Configuring Kerberos Constrained Delegation (KCD) provides an end-to-end single sign-on experience. This approach requires minimal additional infrastructure while integrating with existing Azure AD authentication.

  • B. Incorrect.

    Incorrect. While Azure AD DS offers domain-join capabilities for Azure VMs, it forces you to migrate the application to Azure and manage a separate domain environment. This approach adds complexity rather than minimizing overhead.

  • C. Incorrect.

    Incorrect. Pass-through Authentication is primarily for authenticating users to cloud-based applications by verifying credentials against on-premises AD in real time. It doesn't directly publish on-premises web applications for remote access or provide a built-in SSO experience on its own.

  • D. Incorrect.

    Incorrect. Deploying AD FS can provide Federation SSO, but it requires additional on-premises servers, load balancing, and certificate management, which increases infrastructure overhead. Application Proxy is a simpler option for this scenario.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam