Courseiva
mediumMultiple Choice

SC-100 Migrating on-premises applications to Azure Practice Question

A company is migrating on-premises applications to Azure. They need to ensure that applications can use their existing Active Directory credentials for authentication. Which Azure service should they use?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Entra ID (a modern identity platform) with Microsoft Entra Domain Services (a managed domain service that provides legacy AD protocols), leading candidates to pick Microsoft Entra ID because they think it handles all authentication scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Domain Services

Microsoft Entra Domain Services (Microsoft Entra Domain Services) provides managed domain services such as domain join, group policy, and Kerberos/NTLM authentication. This allows legacy on-premises applications that rely on Active Directory credentials to authenticate without needing to deploy and manage domain controllers in Azure. It bridges the gap by synchronizing identities from Microsoft Entra ID and exposing traditional AD features over a virtual network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Domain Services

    Why this is correct

    Microsoft Entra Domain Services is the correct service because it provides a fully managed Microsoft Entra Domain Services domain that supports the legacy LDAP binds, Kerberos authentication, and NTLM hash-based authentication required by many line-of-business applications during a lift-and-shift migration. It effectively acts as a managed domain controller in Azure, allowing you to domain-join VMs and use Group Policy without deploying and patching your own domain controllers. This is exactly the set of protocols an on-premises app might depend on, so it is the correct choice.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID is wrong because it is a cloud-native identity and access management service designed for modern authentication protocols such as OAuth 2.0, SAML, and OpenID Connect. It does not expose an LDAP interface, nor does it support Kerberos or NTLM authentication for legacy applications. While Microsoft Entra ID can authenticate users with protocols like Integrated Windows Authentication via conditional access and hybrid joins, it does not provide the managed domain endpoint that an unmodified on-prem application needs for direct LDAP binds or Kerberos ticket requests.

  • ✗

    Microsoft Entra Connect

    Why it's wrong here

    Microsoft Entra Connect is wrong because it is not a domain service; it is a synchronization tool that replicates identity objects (users, groups, passwords) between on-premises Active Directory and Microsoft Entra ID. It enables single sign-on and identity synchronization, but it does not host an LDAP endpoint, nor does it speak the Kerberos or NTLM protocols on behalf of applications. In fact, Microsoft Entra Connect is often deployed alongside Microsoft Entra Domain Services—the former keeps identities in sync, while the latter actually provides the legacy domain services that applications consume, making them complementary rather than interchangeable.

  • ✗

    Azure AD B2C

    Why it's wrong here

    Azure AD B2C is wrong because it is a customer identity and access management (CIAM) service built specifically for external identities—consumers, citizens, or business partners—who sign in with social or local accounts. It supports extensible custom policies and modern protocols like OAuth and OpenID Connect, but it has no concept of a domain, LDAP directory, or Kerberos/NTLM authentication. It is a completely isolated identity platform for customer-facing apps, not a replacement for the managed domain services that an internal enterprise application would rely on after migration.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.