AZ-305 Design business continuity solutions Practice Question
Your organization has a hybrid identity infrastructure using Microsoft Entra ID (formerly Azure AD) and Active Directory Domain Services (AD DS) on-premises. You plan to deploy a critical application on Azure VMs that must remain available even if the on-premises network connection fails. The application authenticates users via on-premises AD DS. You need to design an identity disaster recovery solution that works during a network outage. What should you implement?
⚠ Common exam trap
Many exam-takers confuse Microsoft Entra ID (a cloud identity service) with a domain-joined environment; they may choose password hash synchronization (Option B) thinking it provides domain services, but it only enables cloud authentication, not a managed domain for VMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Microsoft Entra Domain Services and join the Azure VMs to the managed domain.
Microsoft Entra Domain Services provides a managed domain that is synchronized from your on-premises AD DS via Microsoft Entra Connect. By joining the Azure VMs to this managed domain, the application can authenticate users against the managed domain even when the on-premises network connection fails, ensuring local authentication within Azure without dependency on the on-premises AD DS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a site-to-site VPN connection with a secondary on-premises data center.
Why it's wrong here
A site-to-site VPN to a secondary on-premises data center does not remove the hard dependency on on-premises domain controllers. Even if the secondary DC is healthy, Azure VMs still rely on the VPN tunnel for every Kerberos and LDAP request; if the tunnel or that secondary site fails, domain authentication breaks again. This option only adds network redundancy, it does not place a directory service inside Azure where identity can be resolved independently.
- ✗
Configure Microsoft Entra Connect with password hash synchronization and enable seamless single sign-on.
Why it's wrong here
Password hash synchronization copies password hashes into Microsoft Entra ID, but it does not replicate the actual Active Directory domain services — it creates no Kerberos ticket-issuing authority, no LDAP endpoint, and no domain-join capability in Azure. Seamless SSO with pass-through authentication or PHS only streamlines Microsoft Entra ID resource authentication for domain-joined devices; it cannot make an Azure VM a member of a traditional AD domain or answer legacy protocols from domain-dependent workloads. When on-premises DCs are unreachable, a PHS-configured Azure VM joined to the on-prem domain still cannot obtain a domain-issued Kerberos ticket.
- ✓
Deploy Microsoft Entra Domain Services and join the Azure VMs to the managed domain.
Why this is correct
Microsoft Entra Domain Services provides a fully managed, Microsoft-owned Active Directory domain in the cloud that supports Kerberos, NTLM, LDAP, group policy, and domain join without any Azure-to-on-premises network dependency. User and group objects flow into the managed domain from your Microsoft Entra ID tenant, which is populated from on-premises AD via Microsoft Entra Connect, so existing domain users continue to authenticate. When you join Azure VMs to the Entra DS managed domain, the Azure VMs authenticate directly against the cloud managed domain, allowing them to keep working even if the primary data center and all on-premises domain controllers are offline.
- ✗
Use Microsoft Entra application proxy to publish the application and authenticate via Microsoft Entra ID.
Why it's wrong here
Microsoft Entra application proxy is a reverse proxy designed to publish web applications remotely through Microsoft Entra ID pre-authentication; it is not an Active Directory domain service and provides no Kerberos, NTLM, or LDAP protocol endpoint for Azure VMs. It does not join VMs to a domain, and for legacy Windows-integrated apps it relies on Kerberos Constrained Delegation performed by an on-premises connector that must still contact a domain controller. This addresses external access to a web app, not the availability of domain authentication when the on-premises environment is down.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.