nerdexam
Microsoft

SC-100 · Question #41

You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service. You are migrating the on-premises infrastructure to…

The correct answer is A. Azure Active Directory Domain Services (Azure AD DS). The correct answer is A: Azure Active Directory Domain Services (Azure AD DS). Azure AD DS is a fully managed PaaS service that provides traditional Active Directory capabilities - including LDAP, Kerberos, and NTLM authentication - in Azure without requiring you to deploy or…

Design security operations, identity, and compliance capabilities

Question

You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service. You are migrating the on-premises infrastructure to a cloud-only infrastructure. You need to recommend an identity solution for the infrastructure that supports the legacy applications. The solution must minimize the administrative effort to maintain the infrastructure. Which identity service should you include in the recommendation?

Exhibit

SC-100 question #41 exhibit

Options

  • AAzure Active Directory Domain Services (Azure AD DS)
  • BAzure Active Directory (Azure AD) B2C
  • CAzure Active Directory (Azure AD)
  • DActive Directory Domain Services (AD DS)

How the community answered

(35 responses)
  • A
    80% (28)
  • B
    6% (2)
  • C
    11% (4)
  • D
    3% (1)

Explanation

The correct answer is A: Azure Active Directory Domain Services (Azure AD DS). Azure AD DS is a fully managed PaaS service that provides traditional Active Directory capabilities - including LDAP, Kerberos, and NTLM authentication - in Azure without requiring you to deploy or manage domain controllers. Legacy applications that rely on LDAP queries are fully compatible. It minimizes administrative overhead because Microsoft manages the underlying infrastructure, patching, and availability. Standard Azure AD (C) does not support LDAP or Kerberos natively - it uses modern protocols (OAuth 2.0, SAML, OpenID Connect). Azure AD B2C (B) is for external/consumer identity scenarios, not internal legacy apps. Running on-premises AD DS (D) would require migrating to cloud VMs and managing domain controllers yourself, which does not minimize administrative effort.

Topics

#Azure AD DS#Legacy Application Integration#Cloud Identity#Managed Services

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice