nerdexam
Microsoft

SC-300 · Question #49

Hotspot Question You have an on-premises datacenter that contains the hosts shown in the following table. You have an Azure Active Directory (Azure AD) tenant that syncs to the Active Directory…

The correct answer is Service to install on Server4:: Azure AD Application Proxy; Rule to configure on Firewall1:: Allow outbound HTTPS connections from Server4 to Azure AD. Azure AD Application Proxy connector must be installed on an internal server (Server4) that can reach the on-premises application (App1). The connector communicates outbound to Azure AD over HTTPS (port 443), so Firewall1 must allow outbound HTTPS from Server4 to Azure AD - no…

Submitted by certguy· Mar 6, 2026Implement and manage hybrid identity - specifically publishing on-premises applications to Azure AD users using Azure AD Application Proxy (AZ-104 / AZ-500 / MS-100 domain: Identity and Access Management)

Question

Hotspot Question You have an on-premises datacenter that contains the hosts shown in the following table. You have an Azure Active Directory (Azure AD) tenant that syncs to the Active Directory forest. Multi-factor authentication (MFA) is enforced for Azure AD. You need to ensure that you can publish App1 to Azure AD users. What should you configure on Server and Firewall1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

SC-300 question #49 exhibit

Answer Area

  • Service to install on Server4:Azure AD Application Proxy
    Azure AD Application ProxyThe Azure AD Password Protection DC agentThe Azure AD Password Protection proxy serviceWeb Application Proxy in Windows Server
  • Rule to configure on Firewall1:Allow outbound HTTPS connections from Server4 to Azure AD.
    Allow incoming HTTPS connections from Azure AD to Server4.Allow incoming IPsec connections from Azure AD to Server4.Allow outbound HTTPS connections from Server4 to Azure AD.Allow outbound IPsec connections from Server4 to Azure AD.

Explanation

Azure AD Application Proxy connector must be installed on an internal server (Server4) that can reach the on-premises application (App1). The connector communicates outbound to Azure AD over HTTPS (port 443), so Firewall1 must allow outbound HTTPS from Server4 to Azure AD - no inbound firewall rules or DMZ configuration is required, which is a key security advantage of this architecture. This setup enables external Azure AD users to securely access internal apps without exposing them directly to the internet.

Topics

#Azure AD Application Proxy#Hybrid Identity#Application Publishing#Network Security / Firewall Rules

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice