Your organization has a hybrid identity environment with Microsoft Entra Connect. You are planning to migrate to cloud-only authentication using Microsoft Entra Cloud Sync. However, some legacy applications still require NTLM authentication. What should you do to ensure those applications can authenticate after the migration?
Microsoft Entra Application Proxy publishes legacy on-premises applications through a cloud entry point, and after the user authenticates to Microsoft Entra ID, the connector uses Kerberos Constrained Delegation (KCD) to communicate with the back-end application using NTLM or Kerberos. This provides true single sign-on for legacy apps that require integrated Windows authentication without modifying the application code. It is the only option here that actually relays the app-level authentication protocol.
Why this answer
Microsoft Entra Application Proxy allows you to publish on-premises legacy applications that rely on NTLM authentication without requiring any changes to the application itself. It acts as a reverse proxy, terminating the external connection and then forwarding the request to the internal application using Kerberos or NTLM, thus enabling cloud-only authentication while preserving NTLM support for legacy apps.
Exam trap
The trap here is that candidates often confuse authentication methods (like PTA or PHS) with application publishing solutions, mistakenly thinking that changing the authentication flow itself will fix legacy app compatibility, when in fact a reverse proxy like Application Proxy is required to relay NTLM traffic.
How to eliminate wrong answers
Option B is wrong because pass-through authentication (PTA) is an authentication method for validating user passwords against on-premises Active Directory, but it does not provide a mechanism to publish or proxy legacy NTLM-based applications; it only handles user sign-in. Option C is wrong because Microsoft Entra Cloud Sync with password hash sync synchronizes password hashes to the cloud for cloud authentication, but it does not enable legacy applications to continue using NTLM after migration; those apps still need a way to receive NTLM requests from external users. Option D is wrong because Microsoft Entra Password Protection is a feature to block weak passwords and enforce custom banned password lists; it has no role in enabling NTLM authentication for legacy applications.