A legacy application being lifted onto Azure virtual machines authenticates users with Kerberos, reads a directory over LDAP, and needs its server domain joined. The team does not want to build, patch and replicate domain controllers. What do you use?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Microsoft Entra Domain Services

Correct. It provides managed domain services — domain join, group policy, LDAP and the older authentication protocols — without you deploying or maintaining any domain controllers yourself.

Not correct Microsoft Entra ID on its own

Wrong. Entra ID is a cloud identity service that speaks modern protocols such as OAuth, SAML and OpenID Connect. It does not offer LDAP binds, Kerberos tickets or domain join — which is exactly the gap Domain Services fills.

Not correct Azure role-based access control

Wrong layer. Role-based access control authorises actions against Azure resources. It is not a directory an application can authenticate its own users against.

Not correct Microsoft Entra Conditional Access

Wrong. Conditional Access decides whether a sign-in to Entra ID proceeds and on what terms. The legacy application is not asking Entra ID anything in the first place.

Why

Split the directory question by protocol. An application speaking modern web protocols talks to Entra ID. An application that wants Kerberos, LDAP or a domain to join needs domain services, and Entra Domain Services provides those as a managed service so nobody has to run domain controllers on virtual machines. The two are complementary rather than alternatives: the managed domain is populated from the same directory.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services