SC-300 · Question #10
You need to implement on-premises application and SharePoint Online restrictions to meet the authentication requirements and the access requirements. What should you do? To answer, select the…
The correct answer is For on-premises applications:: Publish the applications by using Azure AD Application Proxy.; For SharePoint Online:: Publish an application by using Azure AD Application Proxy. This hotspot question tests knowledge of Azure AD Connect authentication modes, Cloud App Security capabilities, and the implications of pass-through authentication (PTA) without password hash synchronization (PHS) in a hybrid identity environment.
Question
Answer Area
- For on-premises applications:Publish the applications by using Azure AD Application Proxy.Configure Cloud App Security policies.Modify the User consent settings for the enterprise applications.Publish the applications by using Azure AD Application Proxy.
- For SharePoint Online:Publish an application by using Azure AD Application Proxy.Configure Cloud App Security policies.Modify the User consent settings for the enterprise applications.Publish an application by using Azure AD Application Proxy.
Explanation
This hotspot question tests knowledge of Azure AD Connect authentication modes, Cloud App Security capabilities, and the implications of pass-through authentication (PTA) without password hash synchronization (PHS) in a hybrid identity environment.
Approach. With pass-through authentication enabled and password hash synchronization disabled, leaked credential detection in Azure AD Identity Protection is NOT available because that feature requires password hashes to be synced to the cloud. Azure AD Application Proxy allows on-premises apps to be published securely without inbound firewall rules, and guest accounts from fabrikam.com can access litware.com resources via B2B collaboration. Microsoft Cloud App Security anomaly detection works on cloud activity regardless of PTA/PHS configuration, and Azure Sentinel can ingest signals from both AAD and MCAS regardless of sync mode.
Concept tested. Hybrid identity authentication trade-offs: pass-through authentication vs password hash sync, and the downstream security feature dependencies (Identity Protection leaked credentials report requires PHS). Also tests understanding of Azure AD B2B guest access, Application Proxy architecture, and which Microsoft 365 E5 security features operate independently of on-premises sync configuration.
Reference. https://learn.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn
Topics
Community Discussion
No community discussion yet for this question.