An Azure AD tenant synchronizes with on-premises Active Directory. An internal web application (WebApp1) hosted on-premises uses Integrated Windows Authentication. Some remote users do not have VPN access but require single sign-on (SSO) to WebApp1. Which two Azure features should you include in the solution? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Azure AD Application Proxy, Azure AD enterprise applications.
Why this is the answer
Azure AD Application Proxy provides secure remote access to on-premises web applications. It publishes internal applications to external users without requiring a VPN, making it suitable for remote users needing SSO to WebApp1. Azure AD enterprise applications are necessary to register WebApp1 within Azure AD. This registration allows Azure AD to manage authentication and authorization for the application, enabling SSO through Application Proxy. Azure AD Privileged Identity Management (PIM) is for managing, controlling, and monitoring access to important resources, not for publishing applications. Conditional Access policies could be used in conjunction with Application Proxy for granular access control but are not a core component for publishing the application itself. Azure Arc extends Azure management to on-premises resources but doesn't publish applications for remote access. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, but it doesn't provide the secure remote access to on-premises applications that Application Proxy does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed