nerdexam
Microsoft

AZ-305 · Question #24

Drag and Drop Question Your on-premises network contains a server named Server1 that runs an ASP.NET application named App1. You have a hybrid deployment of Azure Active Directory (Azure AD). You…

The correct sequence is: (1) Deploy Azure AD Application Proxy, which installs a connector on the on-premises network to securely publish App1 to the internet without opening inbound firewall ports; (2) Configure an Azure AD Enterprise Application, which is automatically…

Submitted by amina.ke· Mar 6, 2026Design and implement identity and access management - specifically securing on-premises applications with Azure AD authentication and MFA using Application Proxy and Conditional Access (AZ-305 / SC-300 / AZ-104 domain: Identity and Access)

Question

Drag and Drop Question Your on-premises network contains a server named Server1 that runs an ASP.NET application named App1. You have a hybrid deployment of Azure Active Directory (Azure AD). You need to recommend a solution to ensure that users sign in by using their Azure AD account and Azure Multi-Factor Authentication (MFA) when they connect to App1 from the internet. Which three features should you recommend be deployed and configured in sequence? To answer, move the appropriate features from the list of features to the answer area and arrange them in the correct order. Answer:

Exhibit

AZ-305 question #24 exhibit

Options

  • Box1Azure AD Application Proxy
  • Box2an Azure AD enterprise application
  • Box3a Conditional Access policy

Explanation

The correct sequence is: (1) Deploy Azure AD Application Proxy, which installs a connector on the on-premises network to securely publish App1 to the internet without opening inbound firewall ports; (2) Configure an Azure AD Enterprise Application, which is automatically created when you set up Application Proxy and serves as the representation of App1 in Azure AD for identity and access management; (3) Apply a Conditional Access policy, which enforces Azure AD authentication and MFA requirements when users attempt to access App1 from the internet. This sequence is logical because the proxy must exist before the enterprise app can be configured, and the enterprise app must exist before a Conditional Access policy can target it. There are no wrong options in this question - all three listed features are the correct answers and must simply be arranged in the right deployment order.

Topics

#Azure AD Application Proxy#Conditional Access#Multi-Factor Authentication#Hybrid Identity

Community Discussion

No community discussion yet for this question.

Full AZ-305 Practice