Question 1
A financial services firm is deploying Microsoft 365 E5 and needs to secure access to an on-premises legacy application that uses header-based authentication. The firm wants to leverage Microsoft Entra ID for modern authentication (MFA, Conditional Access) and provide single sign-on (SSO) for users. The on-premises network is connected to Azure via a site-to-site VPN. Which Microsoft Entra service should be deployed to meet these requirements?
Answer and explanation
Correct answer: C
Microsoft Entra application proxy is the correct service for publishing on-premises web applications externally and integrating them with Microsoft Entra ID. It can translate modern authentication from Entra ID into legacy authentication methods, including header-based authentication, required by the on-premises app. This allows the firm to enforce Conditional Access policies and MFA while providing SSO.