AZ-700 exam dumps

AZ-700 practice question 116 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 116

Select 2

Your organization is rolling out Always On VPN so employees can securely connect to the corporate network from anywhere. You have an on-premises Network Policy Server (NPS) for RADIUS-based authentication and plan to integrate Azure AD Multi-Factor Authentication (MFA). You will deploy an Azure VPN Gateway in a dedicated subnet to handle incoming VPN connections. Which two actions must you ensure are configured in Azure so that remote users can connect with Always On VPN and be verified by the on-premises NPS using Azure AD MFA?

  1. A

    Deploy a route-based Azure VPN gateway (Sku: VpnGw1 or higher) that supports IKEv2 or SSTP protocols.

  2. B

    Enable Azure AD Domain Services on the same virtual network as the Azure VPN gateway.

  3. C

    Configure forced tunneling on the Azure VPN gateway to route all traffic through on-premises resources.

  4. D

    Open inbound UDP ports (e.g., UDP 1812) in Network Security Groups to allow RADIUS traffic to reach the NPS server.

  5. E

    Install the NPS extension for Azure MFA directly on the Azure VPN gateway.

Show answer and explanation

Correct answers: A, D

Explanation

When integrating Always On VPN with Azure AD MFA using a RADIUS-based NPS server, Azure requires a route-based VPN gateway (such as VpnGw1 or higher) for remote connections. Additionally, you must configure Network Security Groups (NSGs) or firewalls to permit RADIUS traffic (UDP 1812) from the Azure VPN gateway subnet to the on-premises NPS. Microsoft� official documentation recommends installing the NPS extension for Azure MFA on the on-premises NPS server to enable MFA, not on the VPN gateway, and does not require enabling Azure AD Domain Services for this scenario.

  • A. Correct.

    Option 1 is correct. Always On VPN requires a route-based Azure VPN gateway supporting IKEv2 or SSTP. VpnGw1 or higher is appropriate for production scenarios.

  • B. Incorrect.

    Option 2 is incorrect. Azure AD Domain Services is not a requirement for Always On VPN. RADIUS authentication can be handled by your on-prem NPS without enabling Azure AD DS.

  • C. Incorrect.

    Option 3 is incorrect. Forced tunneling in this context routes all internet-bound traffic via on-premises, which is not mandatory for Always On VPN. Forced tunneling is an optional configuration and not a core requirement for basic NPS authentication.

  • D. Correct.

    Option 4 is correct. RADIUS communication requires opening inbound UDP ports (typically UDP 1812) so that the Azure VPN gateway can reach the on-premises NPS for authentication.

  • E. Incorrect.

    Option 5 is incorrect. The NPS extension for Azure MFA must be installed on the on-premises NPS server, not on the Azure VPN gateway.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam