Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

Contoso will migrate all workloads to Azure within six months and wants to decommission its on-premises Active Directory Domain Services (AD DS) as soon as possible. Identity requirements are:

  • Provide single sign-on for new Azure-hosted applications that use SAML or OpenID Connect.
  • Keep several legacy line-of-business VMs that authenticate by using LDAP and NTLM.
  • Let external partners who already use Microsoft Entra ID access selected resources with minimal overhead.
  • Minimize ongoing infrastructure administration.

Which solution should you recommend?

  • Deploy domain controllers on Azure IaaS VMs, configure Active Directory Federation Services for single sign-on, and invite partners through AD FS claims.

  • Create an Azure AD B2C tenant, migrate internal identities into it, and federate partner tenants through custom identity providers.

  • Keep the on-premises AD DS environment, synchronize it to Azure AD with password hash sync, and use Conditional Access policies for partner users.

  • Create a cloud-only Microsoft Entra ID tenant, enable Azure AD Domain Services for the virtual network, and use Azure AD B2B guest collaboration for partner access.

Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot