Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company hosts several legacy ASP.NET applications on-premises that use Windows Integrated Authentication (Kerberos). Identities are synchronized to Azure Active Directory with Azure AD Connect. Management wants staff working from home to reach these applications over the internet without requiring a VPN. Access must be evaluated by Azure AD Conditional Access and the solution must avoid exposing the internal network or adding significant new infrastructure. Which approach should you recommend?
Deploy an Azure VPN Gateway and require users to establish a Point-to-Site VPN before accessing the applications.
Publish the applications by using Azure AD Application Proxy and configure Kerberos Constrained Delegation for single sign-on.
Deploy Azure AD Domain Services, join the web servers to the managed domain, and control access through Azure role assignments.
Migrate the applications to Azure App Service and enable Azure AD authentication with Conditional Access.
Azure AD Application Proxy can publish on-premises web applications externally while providing Azure AD pre-authentication, including support for Kerberos Constrained Delegation to the backend servers. Because traffic is proxied through an outbound connection initiated by the on-premises connector, no inbound firewall ports or site-to-site networking are required, and Conditional Access policies are enforced before the user reaches the application. The Point-to-Site VPN option meets the connectivity requirement but violates the mandate to avoid a VPN and would expose more of the network. Azure AD Domain Services does not provide external application publishing or Conditional Access by itself. Migrating the apps to Azure App Service would necessitate significant redevelopment and infrastructure changes, contradicting the requirement to minimize changes on-premises.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Application Proxy?
Open an interactive chat with Bash
What is Kerberos Constrained Delegation and how does it work with Azure AD Application Proxy?
Open an interactive chat with Bash
Why is Azure AD Application Proxy better than an Azure VPN Gateway for this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .