Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your organization is migrating a legacy on-premises application to Azure. The application uses a proprietary authentication protocol that is not supported by Microsoft Entra ID. You need to integrate the application with Microsoft Entra ID without modifying the application code. What should you do?

⚠ Common exam trap

Many exam-takers confuse pass-through authentication (which validates passwords against on-premises AD) with Application Proxy's pass-through mode (which forwards authentication headers unchanged), leading them to incorrectly select Microsoft Entra Connect with pass-through authentication (Option D) instead of the correct Application Proxy solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra ID Application Proxy to provide secure remote access and pass through authentication.

Microsoft Entra ID Application Proxy can be configured to publish on-premises applications that use legacy authentication protocols. It acts as a reverse proxy, terminating the external connection and forwarding requests to the internal application. Because it can be set to pass through authentication without requiring any changes to the application code, it allows the proprietary authentication protocol to continue working while still integrating with Microsoft Entra ID for access control and conditional access policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Active Directory B2C with custom policies to translate the authentication protocol.

    Why it's wrong here

    Azure AD B2C is a customer-facing identity service designed for external identities and standards-based protocols like OAuth 2.0, OpenID Connect, and SAML. Custom policies orchestrate claims transformations and user journeys but cannot translate proprietary or legacy on-premises authentication protocols into Microsoft Entra ID tokens. It also lacks the on-premises connector infrastructure needed to reach or secure a legacy application inside your network, so it is not a fit for this scenario.

  • ✗

    Deploy Microsoft Entra Domain Services and domain-join the application servers.

    Why it's wrong here

    Microsoft Entra Domain Services provides a managed domain with NTLM and Kerberos authentication, and domain-joining the application servers would give local domain authentication. However, it does not create a bridge from the legacy application's proprietary protocol to Microsoft Entra ID, nor does it provide secure remote access for external users. You would still need a separate mechanism such as Microsoft Entra application proxy to publish the app and connect it to Microsoft Entra ID.

  • ✓

    Configure Microsoft Entra ID Application Proxy to provide secure remote access and pass through authentication.

    Why this is correct

    Microsoft Entra ID Application Proxy is the correct service because it publishes on-premises legacy applications through an outbound connector on your network without requiring a VPN or DMZ. In pass-through mode, the proxy forwards requests directly to the app and lets the app perform its own authentication, which is ideal for protocols that Microsoft Entra ID cannot understand. In pre-authentication mode, it can also use Kerberos constrained delegation or header injection to enable single sign-on while keeping Microsoft Entra ID as the front-end identity provider.

  • ✗

    Implement Microsoft Entra ID Connect with pass-through authentication.

    Why it's wrong here

    Microsoft Entra Connect with pass-through authentication is a directory synchronization and authentication validation feature that enables users to sign in to Microsoft Entra ID with their on-premises password. It does not publish application endpoints, route traffic, or translate the legacy application's authentication protocol; it only confirms password validity against Active Directory. Therefore, it cannot give users access to the legacy application itself — that requires an application proxy or an agent on the app server.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.