Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your organization has a hybrid identity environment with Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You need to design a solution that allows users to access cloud applications using their on-premises credentials, and also enables single sign-on (SSO) for legacy on-premises applications that do not support modern authentication protocols. What should you recommend?

⚠ Common exam trap

Watch out — candidates often confuse pass-through authentication (which validates passwords on-premises) with the need for a reverse proxy solution like Application Proxy to handle legacy app publishing and SSO, mistakenly thinking Seamless SSO alone suffices for on-premises legacy applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Microsoft Entra Connect with password hash synchronization and Microsoft Entra application proxy.

Microsoft Entra Connect with password hash synchronization enables users to authenticate to cloud applications using their on-premises credentials, while Microsoft Entra application proxy provides secure remote access and SSO for legacy on-premises applications that do not support modern authentication protocols (such as Kerberos, SAML, or OAuth). The Application Proxy can pass Kerberos constrained delegation tickets to legacy apps, enabling SSO without requiring those apps to be domain-joined or modified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Entra Domain Services and domain-join the legacy application servers.

    Why it's wrong here

    Microsoft Entra Domain Services is a managed domain service that provides LDAP, Kerberos, and NTLM within a Microsoft-managed domain, but it does not synchronize or federate on-premises AD credentials into Microsoft Entra ID for cloud SSO. Domain-joining legacy servers to AAD DS only addresses the need for domain-joined infrastructure for migrated workloads; it does not give users single sign-on to Microsoft Entra ID-integrated applications with their existing on-premises identities. For hybrid SSO you need Microsoft Entra Connect to sync identities and, for legacy apps, Application Proxy.

  • ✗

    Use Microsoft Entra ID B2B collaboration for internal users.

    Why it's wrong here

    Microsoft Entra B2B collaboration creates guest user objects for external partners and vendors so they can access resources using their own home-directory credentials; it is not intended for internal employees. Inviting internal users as B2B guests would create duplicate, separate identities alongside their normal employee accounts, leading to inconsistent access and management, and it does nothing to validate or sync on-premises AD passwords. Therefore, it cannot provide SSO for internal users accessing legacy applications in a hybrid environment.

  • ✓

    Implement Microsoft Entra Connect with password hash synchronization and Microsoft Entra application proxy.

    Why this is correct

    Microsoft Entra Connect with password hash synchronization synchronizes a cryptographic hash of each user's on-premises AD password to Microsoft Entra ID, enabling the user to sign in to cloud services using the same credentials. Microsoft Entra application proxy then publishes legacy on-premises applications that use non-modern protocols (for example, Kerberos or LDAP) and enforces Microsoft Entra ID pre-authentication, so after the initial Microsoft Entra ID sign-in, users are seamlessly authenticated to the legacy app. Together these components deliver the needed SSO experience without requiring additional on-premises infrastructure. This is the correct combination for extending SSO to legacy apps in a hybrid identity environment.

  • ✗

    Configure Microsoft Entra ID Seamless SSO and use Microsoft Entra Connect with pass-through authentication.

    Why it's wrong here

    Pass-through authentication validates passwords directly against on-premises Active Directory and Microsoft Entra ID Seamless SSO silently signs in domain-joined users when they access Microsoft Entra ID from corporate network. However, these features only influence the Microsoft Entra ID authentication flow; they do not convert a legacy application's protocol so it can accept Microsoft Entra ID tokens. Without Microsoft Entra application proxy (or a similar connector) to publish the legacy app and handle pre-authentication, Seamless SSO and PTA alone will not grant SSO access to that app. Thus this option is incomplete.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.