AZ-700 exam dumps

AZ-700 practice question 110 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 110

Select 2

Your organization hosts an internal line-of-business web application behind an Azure Application Gateway. You want to enforce authentication by using Microsoft Entra ID (formerly Azure AD) before users can access the application. You enable Azure AD pre-authentication on the gateway. Which two configuration steps must you perform to complete the setup?

  1. A

    Register the backend application in Microsoft Entra ID and specify the corresponding reply URL pointing to the Application Gateway� endpoint.

  2. B

    Enable multi-factor authentication (MFA) on every account in the tenant before selecting Azure AD as the identity provider in the Application Gateway.

  3. C

    Supply the tenant ID and client ID in the Application Gateway� Azure AD authentication settings to allow proper token validation.

  4. D

    Use an Azure DNS private zone to map the application� internal hostname directly to Microsoft Entra ID.

Show answer and explanation

Correct answers: A, C

Explanation

To configure Microsoft Entra ID (Azure AD) pre-authentication with Azure Application Gateway, you must register the application in Azure AD to generate tokens and establish a reply URL. You then provide the tenant ID and client ID to the Application Gateway so that it can validate the tokens it receives. For detailed guidance, see Microsoft� documentation on 'Azure AD authentication with Application Gateway' at https://learn.microsoft.com/azure/application-gateway/how-to-appgw-auth-azure-ad .

  • A. Correct.

    Correct: You must register the application in Microsoft Entra ID (Azure AD) so the authentication platform knows how to issue tokens. Specifying the reply (or redirect) URL in the registration ensures that once users authenticate, Azure AD can redirect them correctly back to the Application Gateway� endpoint.

  • B. Incorrect.

    Incorrect: While MFA can be a good security practice, simply enabling it on every account is not a mandatory requirement to configure Azure AD pre-authentication in Application Gateway. Pre-auth and MFA are separate steps; MFA is an optional layer of security, not a setup necessity for the initial configuration.

  • C. Correct.

    Correct: The Application Gateway needs the tenant ID and client ID to trust the Microsoft Entra ID instance and validate tokens issued by Azure AD. Without these details, the gateway cannot complete the authentication flow.

  • D. Incorrect.

    Incorrect: Using a private DNS zone for internal name resolution doesn�t replace the need to configure proper Azure AD authentication settings in Application Gateway. DNS mapping alone won�t establish the trust relationship required for pre-authentication using Azure AD.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam