You are designing an Azure Point-to-Site (P2S) VPN that will use the OpenVPN protocol. Users will authenticate against your on-premises Active Directory domain. Which additional component should you deploy to validate VPN authentication requests?
Choose an answer
Tap an option to check your answer.
Correct answer: a RADIUS server.
Why this is the answer
For Azure Point-to-Site (P2S) VPNs using OpenVPN and requiring authentication against an on-premises Active Directory, a RADIUS server is the correct component. Azure VPN Gateway can be configured to use an external RADIUS server for authentication. This RADIUS server, which can be integrated with your on-premises Active Directory, will handle the authentication requests from the VPN gateway. An Azure Key Vault is used for securely storing secrets and certificates, not for authentication. A Certification Authority is used for issuing and managing digital certificates, which can be part of a certificate-based authentication scheme, but it doesn't directly handle Active Directory authentication for OpenVPN P2S. Azure Active Directory (Azure AD) Application Proxy is used for providing secure remote access to on-premises web applications, not for VPN authentication.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed