exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 52 discussion

Actual exam question from Microsoft's AZ-304
Question #: 52
Topic #: 2
[All AZ-304 Questions]

DRAG DROP -
Your on-premises network contains a server named Server1 that runs an ASP.NET application named App1.
You have a hybrid deployment of Azure Active Directory (Azure AD).
You need to recommend a solution to ensure that users sign in by using their Azure AD account and Azure Multi-Factor Authentication (MFA) when they connect to App1 from the internet.
Which three Azure services should you recommend be deployed and configured in sequence? To answer, move the appropriate services from the list of services to the answer area and arrange them in the correct order.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Step 1: Azure AD Application proxy
Azure AD Application Proxy is a prerequisite for a scenario with an on-premises legacy applications published for cloud access,
Note: Application Proxy is a feature of Azure AD that enables users to access on-premises web applications from a remote client. Application Proxy includes both the Application Proxy service which runs in the cloud, and the Application Proxy connector which runs on an on-premises server.
Step 2: an Azure AD managed identity
Microsoft's identity solutions span on-premises and cloud-based capabilities. These solutions create a common user identity for authentication and authorization to all resources, regardless of location. We call this hybrid identity.
Step 3: an Azure AD conditional access policy
Conditional Access is the tool used by Azure Active Directory to bring signals together, to make decisions, and enforce organizational policies. Conditional Access is at the heart of the new identity driven control plane.
With hybrid identity to Azure AD and hybrid identity management these scenarios become possible.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
norbitek
Highly Voted 3 years, 10 months ago
For me it should be: AD Application Proxy AD Enterprise Application AD Conditional access policy
upvoted 117 times
norbitek
3 years, 10 months ago
Following blog describes how to do that: https://thesleepyadmins.com/2019/02/
upvoted 10 times
...
...
vitol
Highly Voted 3 years, 10 months ago
First AD Enterprise APPLICATION to register APP Second APP Proxy (only IWA,SAML,WSFED authentication methods are available) Third Conditional Access
upvoted 19 times
pentium75
3 years, 8 months ago
Question is in which order to DEPLOY the services. And before you can configure application proxy for your registered enterprise app, you must first deploy application proxy connector. MS document lists it in this order: 1. Deploy Application Proxy connector 2. Create Enterprise App 3. Configure Application Proxy in Enterprise App
upvoted 10 times
...
...
DChilds
Most Recent 2 years, 8 months ago
AD Application Proxy AD Enterprise Application https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-application. AD Conditional access policy
upvoted 4 times
...
AubinBakana
2 years, 8 months ago
How could they get this wrong? The App does get a Managed ID once added to Enterprise App, so no need for that. The answer should be: - Enterprise App - Application Proxy - Conditional Access
upvoted 3 times
...
cloudera
3 years, 1 month ago
Based on this article, the correct answer should be: https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-application 1. Application Proxy 2. Enterprise Application Registration 3. Conditional Access - the article doesn't cover but it is obvious to enable MFA which is one of the requirements in the question.
upvoted 5 times
...
itenginerd
3 years, 1 month ago
On my exam today.
upvoted 1 times
...
plmmsg
3 years, 1 month ago
1. AD Application Proxy 2. AD Enterprise App 3. AD Conditional Access Policy
upvoted 3 times
...
Preeto18
3 years, 1 month ago
Answer is : AD Application Proxy AD Enterprise Application AD Conditional access policy
upvoted 2 times
...
[Removed]
3 years, 4 months ago
AD proxy AD enterprise app Conditional policy
upvoted 4 times
...
ScubaDiver123456
3 years, 4 months ago
I believe it should be AD App Proxy Enterprise App registration Conditional Access https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-application
upvoted 2 times
...
Dpejic
3 years, 4 months ago
On exam 24.12.2021
upvoted 2 times
...
Dpejic
3 years, 4 months ago
In exam today 22-dec-2021
upvoted 2 times
...
Foxywolf
3 years, 4 months ago
https://youtu.be/_2kWq5H4NhY
upvoted 3 times
...
sharepoint_Azure_pp
3 years, 6 months ago
It should be: AD Application Proxy AD Enterprise Application AD Conditional access policy is correct choose the same cleared with 900 on 17th October 2021
upvoted 13 times
...
sharepoint_Azure_pp
3 years, 6 months ago
it should be: AD Application Proxy AD Enterprise Application AD Conditional access policy Choose the same cleared with 900 on 17th October 2021
upvoted 3 times
...
syu31svc
3 years, 7 months ago
https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-application Install and register a connector Under Manage, select Application proxy (Step1) Add an on-premises app to Azure AD Select Enterprise applications, and then select New application (Step 2) Need MFA so last step is Conditional Access
upvoted 3 times
...
souvik123
3 years, 7 months ago
AD Application Proxy AD Enterprise Application AD Conditional access policy
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago