Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to enforce that all users accessing the company's internal application from mobile devices must be compliant with device management policies (e.g., require a PIN and encryption). The application does not support modern authentication. Which Microsoft Entra ID feature should they use?

⚠ Common exam trap

Test-takers frequently assume Conditional Access alone can enforce device compliance on any application, but they miss the critical requirement that the application must support modern authentication; Application Proxy is the bridge that enables Conditional Access to work with legacy apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Application Proxy

Microsoft Entra ID Application Proxy is the correct choice because it enables secure remote access to on-premises web applications that do not support modern authentication. By publishing the internal application through Application Proxy, you can enforce device compliance policies (e.g., requiring a PIN and encryption) via Conditional Access policies applied to the Application Proxy service, even though the application itself uses legacy authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID Conditional Access

    Why it's wrong here

    Conditional Access is a powerful policy engine, but it only evaluates sign-ins to applications that support modern authentication protocols such as OpenID Connect and OAuth 2.0. The legacy application in question uses an older authentication flow, so a device compliance policy would never be triggered even if Conditional Access is configured. Application Proxy is necessary to give this app a modern authentication endpoint that Conditional Access can govern.

  • ✓

    Microsoft Entra ID Application Proxy

    Why this is correct

    Application Proxy is the correct choice because it publishes the legacy on-premises application as an enterprise application in Microsoft Entra ID, adding a modern OAuth/OIDC authentication layer in front of it. Once published, the app becomes visible to Conditional Access, so device compliance requirements can be enforced during pre-authentication. The connector then forwards the authenticated request to the legacy backend using Kerberos or NTLM, preserving the original app's behavior without changing its code.

  • ✗

    Microsoft Entra ID Identity Protection

    Why it's wrong here

    Identity Protection uses risk signals like anonymous IP addresses, impossible travel, and leaked credentials to label sign-ins and users as risky, but it cannot apply a device compliance requirement to a legacy app that lacks modern authentication. Its output is consumed by Conditional Access policies, so it is purely a detection mechanism rather than a way to expose or modernize a legacy endpoint. Even if a user is deemed risky, there is nothing in Identity Protection that can enforce device health on a legacy protocol.

  • ✗

    Microsoft Entra ID Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) provides just-in-time, time-bound role activation and approval workflows for elevated administrator roles, such as Global Administrator or Application Administrator. This requirement involves ordinary users accessing a legacy application and needing device compliance checks, not the granting or monitoring of privileged administrative access. PIM does not interact with the application's authentication flow and cannot enforce device health policies.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.