Entra Application Proxy for Passwordless On-Premises Apps
You are designing a hybrid identity solution for an organization that uses Microsoft Entra ID and an on-premises Active Directory. The organization requires that users who are located in a remote office without a direct VPN connection to the main office can authenticate against on-premises resources using their Entra ID credentials. The solution must minimize latency and support passwordless authentication. Which feature should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement Microsoft Entra Kerberos authentication
Microsoft Entra Kerberos authentication enables users to authenticate to on-premises resources using their Entra ID credentials without requiring a VPN, and it supports passwordless methods like FIDO2 and Windows Hello for Business. Option A is incorrect because Entra Application Proxy is designed for publishing on-premises web applications, not for general authentication. Option C is incorrect because Conditional Access policies enforce access controls but do not provide authentication or passwordless capabilities. Option D is incorrect because Entra Connect Sync with password hash synchronization only syncs password hashes and does not support real-time passwordless authentication without a VPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Entra Application Proxy
Why it's wrong here
Microsoft Entra Application Proxy is designed to publish on-premises HTTP-based web applications to external users through a reverse proxy with Entra ID pre-authentication. It does not expose a general Kerberos authentication service, and while it can leverage Kerberos constrained delegation for specific selected apps, it cannot authenticate a user's identity to arbitrary on-premises resources, file servers, or domain-joined systems. Thus it fails to satisfy the requirement for a hybrid identity sign-in mechanism.
- ✓
Implement Microsoft Entra Kerberos authentication
Why this is correct
Implement Microsoft Entra Kerberos authentication is the correct approach because it lets Entra ID issue a Kerberos ticket-granting ticket (TGT) for a synchronized user, enabling access to on-premises Kerberos-protected resources without the user authenticating directly against local Active Directory. This works with passwordless credentials such as FIDO2 security keys and Windows Hello for Business, and it reduces latency by avoiding a separate on-premises authentication round-trip. The Entra ID instance effectively acts as a cloud-based KDC, but it still relies on on-premises domain controllers to issue service tickets.
- ✗
Enable Microsoft Entra Conditional Access policies
Why it's wrong here
Conditional Access is an administrative policy engine that evaluates signals like risk, device compliance, location, and MFA state to allow or block access to cloud and, with Application Proxy, some on-premises applications. It enforces authorization decisions at the time of sign-in, but it does not generate Kerberos tickets or perform any actual interaction with the on-premises domain security infrastructure. As a result, enabling Conditional Access alone leaves users without a credential path to access traditional on-premises resources.
- ✗
Deploy Microsoft Entra Connect Sync with password hash synchronization
Why it's wrong here
Deploying Entra Connect Sync with password hash synchronization synchronizes user objects and password hashes to Entra ID, enabling the user to sign in to Microsoft cloud services using the same password as on-premises. However, password hash sync only authenticates the user to Entra ID; it does not produce Kerberos tickets or otherwise provide an authentication channel that on-premises resources recognize. Without an additional mechanism such as Microsoft Entra Kerberos authentication, a remote user would still need a VPN or domain-joined tunnel to reach on-premises resource servers.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.