SC-100 Design security solutions for infrastructure Practice Question
You are designing a secure remote access solution for on-premises web applications using Microsoft Entra ID. The solution must support multifactor authentication (MFA) and conditional access. Which service should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra application proxy
Microsoft Entra application proxy (option A) is correct because it is the service designed to publish on-premises web applications for secure remote access through Microsoft Entra ID, and it natively supports Entra ID authentication, multifactor authentication (MFA), and conditional access policies. It works via a lightweight connector on the on-premises network, so users authenticate to Entra ID before reaching the internal web app, satisfying the MFA and conditional access requirements. Windows Server DirectAccess (B) provides seamless intranet connectivity for domain-joined Windows clients but does not integrate with Entra ID conditional access for publishing web apps. A VPN gateway with RADIUS authentication (C) provides network-level access and can use MFA via RADIUS, but it does not natively enforce Entra ID conditional access for individual web applications. Microsoft Entra ID (D) is the identity provider itself, not the remote-access publishing service, so it alone cannot expose on-premises web applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra application proxy
Why this is correct
Microsoft Entra Application Proxy publishes internal web applications through an outbound connector, so remote users access the app via an external URL without opening inbound firewall ports. It relies on Entra ID for pre-authentication, which lets you enforce MFA, Conditional Access, and device compliance before a session is established, and it supports Kerberos Constrained Delegation for seamless SSO to the backend app. This is the only option that delivers identity-aware, application-level access control specifically for on-premises web apps.
- ✗
Windows Server DirectAccess
Why it's wrong here
Windows Server DirectAccess uses IPsec with IPv6 to create an always-on, transparent tunnel for domain-joined client computers, making it effectively an automatic VPN at the network layer. It does not integrate natively with Microsoft Entra ID for MFA or Conditional Access; classic DirectAccess relies on NLA and PKI, so enforcing Entra ID MFA requires complex workarounds or third-party NPS extensions. Additionally, it is a legacy technology that Microsoft no longer actively develops, and it grants network-wide access rather than scoped application-level publishing.
- ✗
VPN gateway with RADIUS authentication
Why it's wrong here
A VPN gateway with RADIUS authentication validates credentials only at the network boundary, allowing the user to join the corpnet's IP space and reach many internal resources. RADIUS itself does not provide application-layer awareness, interactive MFA prompts, or Conditional Access policies that can be tailored per on-premises app; even if you add MFA via NPS, the VPN inherently grants broad network access rather than selective application access. This makes it unsuitable when the requirement is precise, app-centric remote access with Entra ID policies.
- ✗
Microsoft Entra ID (Azure AD)
Why it's wrong here
Microsoft Entra ID (Azure AD) by itself is an identity provider and directory service; it can authenticate users and issue tokens, but it has no built-in reverse-proxy or forwarding component to reach on-premises applications. Without a connector-based proxy like Application Proxy or a similar gateway, Entra ID cannot bridge the network boundary to an internal web server, so it cannot publish or mediate access to on-premises apps. It is the underlying authentication and policy authority, not the access delivery mechanism, and thus insufficient on its own for this scenario.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.