Courseiva

AZ-305 Design infrastructure solutions Practice Question

A company is designing a hybrid identity solution that allows users to access both on-premises applications and Microsoft 365 using a single identity. The solution must support legacy authentication protocols for on-premises apps and modern authentication for cloud apps. Which Azure service should the company use?

⚠ Common exam trap

Many exam-takers confuse Microsoft Entra Connect (a sync tool) with the application proxy capability, or assume AD FS is required for hybrid scenarios, but the question specifically requires support for legacy authentication protocols on on-premises apps, which Application Proxy handles through its connector and KCD integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Application Proxy

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by publishing them through the Microsoft Entra ID service. It supports legacy authentication protocols (such as Integrated Windows Authentication) for on-premises apps while enabling modern authentication (OAuth 2.0, OpenID Connect) for cloud apps like Microsoft 365, all using a single identity from Microsoft Entra ID. This makes it the correct choice for a hybrid identity solution that bridges on-premises and cloud authentication requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Active Directory Federation Services (AD FS)

    Why it's wrong here

    AD FS is an on-premises federation service that runs on Windows Server and issues security tokens for claims-based authentication. It is not a managed Azure service and requires its own server farm, certificates, and network infrastructure, and it must be configured with a federation trust to Microsoft Entra ID. While AD FS can provide SSO and supports some legacy protocols, it does not act as a reverse proxy that publishes individual on-premises applications, so it is not the right choice when a fully managed hybrid application-access layer is needed.

  • ✓

    Microsoft Entra Application Proxy

    Why this is correct

    Microsoft Entra Application Proxy is a cloud-managed reverse proxy that publishes on-premises web applications through your Microsoft Entra tenant without requiring a VPN or inbound firewall rules. It pre-authenticates users with Entra ID, supports MFA and Conditional Access, and can work with legacy apps that use Integrated Windows Authentication via Kerberos constrained delegation or forms-based authentication. The service installs a connector on-premises, which makes an outbound connection to the cloud, keeping internal endpoints hidden while providing modern identity controls.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID is a cloud identity and access management directory that provides authentication for cloud and SaaS apps using modern protocols like OAuth 2.0 and SAML. However, it is not an application delivery or reverse-proxy service; it cannot publish on-premises web apps, relay traffic into the corporate network, or translate modern authentication into the legacy protocols that a legacy app expects. Without an intermediary like Application Proxy, Entra ID alone leaves the on-premises app inaccessible or would require you to expose the app directly to the internet.

  • ✗

    Microsoft Entra Connect

    Why it's wrong here

    Microsoft Entra Connect is an on-premises tool that synchronizes identity data such as users, groups, and password hashes from Active Directory Domain Services to Microsoft Entra ID. It is not an application access or publishing component; it simply ensures that users have the same identity and credentials in both directory systems. Even after synchronization is complete, Entra Connect does nothing to make an on-premises legacy application reachable or to enable modern authentication for that application, so it cannot provide secure hybrid application access.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.