Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Contoso's Azure AD tenant already enforces Conditional Access with MFA. A legacy HR web app runs on-premises and uses Windows Integrated (Kerberos) authentication. Contoso must let remote employees use the app over the Internet without installing VPN clients or opening inbound firewall ports. The app must keep authenticating against on-prem Active Directory, and existing Conditional Access rules must apply. Which solution should you recommend?
Create a point-to-site VPN gateway in Azure that enforces Conditional Access and require users to connect before accessing the HR application.
Configure Azure AD Connect pass-through authentication with seamless single sign-on and expose the HR web server through a reverse-proxy firewall rule.
Deploy Azure AD Domain Services in Azure, synchronize on-premises identities, and establish a site-to-site VPN so remote users can reach the HR application.
Deploy an Azure AD Application Proxy connector on-premises and publish the HR application with Kerberos constrained delegation enabled.
Publishing the HR application through Azure AD Application Proxy satisfies all requirements. The on-premises connector initiates only outbound traffic, so no inbound firewall rules are needed. Users authenticate to Azure AD in the cloud, where Conditional Access and MFA are enforced. The connector can use Kerberos constrained delegation to obtain service tickets and sign users in to the application, so authorization continues against on-premises Active Directory. A point-to-site VPN would require client software and broad network exposure, while exposing the app directly or using Azure AD Domain Services would not automatically apply Conditional Access and would still need additional infrastructure or inbound access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Application Proxy?
Open an interactive chat with Bash
What is Kerberos Constrained Delegation (KCD) and how does it work?
Open an interactive chat with Bash
Why aren't VPNs or reverse-proxy firewalls ideal for this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .