An on-premises Active Directory syncs to Azure AD. App1 on Server1 uses LDAP against the on-premises domain. Server1 will be migrated to a VM in Subscription1, but the subscription must be prevented from accessing the on-premises network. Which solution ensures App1 continues to function while complying with the security policy?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure AD Domain Services (Azure AD DS).
Why this is the answer
Azure AD Domain Services (Azure AD DS) provides managed domain services like those of traditional Active Directory, including LDAP, without requiring domain controllers on Azure VMs. This allows App1 to continue using LDAP against a domain synchronized with Azure AD, while keeping Subscription1 isolated from the on-premises network. Azure AD Application Proxy is for publishing internal web applications to external users, not for providing LDAP services to Azure VMs. The Active Directory Domain Services role on a virtual machine would require deploying and managing domain controllers in Azure, which Azure AD DS automates. An Azure VPN gateway would connect Subscription1 to the on-premises network, violating the security policy.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed