SC-300 · Question #49
Hotspot Question You have an on-premises datacenter that contains the hosts shown in the following table. You have an Azure Active Directory (Azure AD) tenant that syncs to the Active Directory…
The correct answer is Service to install on Server4:: Azure AD Application Proxy; Rule to configure on Firewall1:: Allow outbound HTTPS connections from Server4 to Azure AD. Azure AD Application Proxy connector must be installed on an internal server (Server4) that can reach the on-premises application (App1). The connector communicates outbound to Azure AD over HTTPS (port 443), so Firewall1 must allow outbound HTTPS from Server4 to Azure AD - no…
Question
Exhibit
Answer Area
- Service to install on Server4:Azure AD Application ProxyAzure AD Application ProxyThe Azure AD Password Protection DC agentThe Azure AD Password Protection proxy serviceWeb Application Proxy in Windows Server
- Rule to configure on Firewall1:Allow outbound HTTPS connections from Server4 to Azure AD.Allow incoming HTTPS connections from Azure AD to Server4.Allow incoming IPsec connections from Azure AD to Server4.Allow outbound HTTPS connections from Server4 to Azure AD.Allow outbound IPsec connections from Server4 to Azure AD.
Explanation
Azure AD Application Proxy connector must be installed on an internal server (Server4) that can reach the on-premises application (App1). The connector communicates outbound to Azure AD over HTTPS (port 443), so Firewall1 must allow outbound HTTPS from Server4 to Azure AD - no inbound firewall rules or DMZ configuration is required, which is a key security advantage of this architecture. This setup enables external Azure AD users to securely access internal apps without exposing them directly to the internet.
Topics
Community Discussion
No community discussion yet for this question.
