Courseiva

AZ-305 Design infrastructure solutions Practice Question

Your organization plans to migrate a legacy on-premises application that uses a proprietary authentication mechanism to Azure. The application must run as a virtual machine and must not require any code changes. You need to design an identity solution that integrates with the application without modifying it. What should you use?

⚠ Common exam trap

It's easy for candidates to confuse network-level solutions (VPN, Bastion) or domain services (Entra DS) with identity proxy solutions, failing to recognize that Application Proxy with KCD is the only option that provides seamless authentication integration without code changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Application Proxy with Kerberos Constrained Delegation

Microsoft Entra Application Proxy with Kerberos Constrained Delegation (KCD) allows you to publish on-premises applications that use Kerberos authentication without modifying the application code. The Application Proxy pre-authenticates users via Entra ID, then uses KCD to obtain a Kerberos ticket on behalf of the user and pass it to the legacy application running on a VM. This meets the requirement of no code changes while integrating the proprietary authentication mechanism with Azure identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure VPN Gateway

    Why it's wrong here

    Azure VPN Gateway is a network-layer tunnel (IPsec/IKE) that securely connects your on-premises network to an Azure virtual network. It does not operate at the application layer, so it cannot proxy HTTP requests, perform pre-authentication, or translate legacy authentication protocols like Kerberos/NTLM into modern identity flows. As a result, legacy app authentication would remain unchanged and users would still need direct access to on-premises domain controllers—so it fails to solve the identity integration challenge.

  • ✓

    Microsoft Entra Application Proxy with Kerberos Constrained Delegation

    Why this is correct

    Microsoft Entra Application Proxy with Kerberos Constrained Delegation is the correct approach because it publishes the legacy on-premises web app as an enterprise application in Entra ID, allowing pre-authentication via Entra ID (including MFA and conditional access). The Application Proxy connector, running on-premises, then uses KCD to obtain a Kerberos ticket for the user and forwards it to the backend app, enabling Windows-integrated authentication without any code changes. This gives a seamless SSO experience while protecting the app from direct exposure.

  • ✗

    Microsoft Entra Domain Services

    Why it's wrong here

    Microsoft Entra Domain Services provides managed domain capabilities such as LDAP, Kerberos/NTLM authentication, and group policy within Azure, but it does not act as a reverse proxy or application gateway. To use it, you would need to re-architect or move the legacy application into the managed domain boundary, which is not a drop-in solution for an existing on-premises app. Furthermore, it cannot intercept and translate Entra ID pre-authentication into the legacy app's expected authentication flow, so it does not satisfy the requirement for identity integration without code changes.

  • ✗

    Azure Bastion

    Why it's wrong here

    Azure Bastion is designed solely for secure, browser-based RDP and SSH access to Azure virtual machines, providing TLS-secured administrative connectivity without exposing public IP addresses. It is a remote administration service for the VM control plane, not an application-level proxy, and it has no ability to relay or authenticate web application protocols. Consequently, it cannot facilitate Entra ID sign-on to a legacy application or handle Kerberos/NTLM challenge-response flows, making it irrelevant to the stated identity migration goal.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.