Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is migrating several legacy enterprise applications to Azure Virtual Machines as part of a lift-and-shift migration. These legacy applications require traditional directory features, including Kerberos authentication, LDAP directory lookups, and Group Policy management, but the IT team wants to avoid the administrative overhead of deploying, managing, and patching dedicated domain controller virtual machines in the cloud.
Which identity service should the organization deploy to meet these requirements?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Microsoft Entra Domain Services provides managed domain services such as domain join, Group Policy, Lightweight Directory Access Protocol (LDAP/LDAPS), and Kerberos/NTLM authentication. It enables organizations to run legacy applications in the cloud without requiring administrators to deploy, configure, patch, or maintain traditional Active Directory Domain Services (AD DS) domain controllers.
Microsoft Entra Domain Services delivers full compatibility with traditional Active Directory protocols in a fully managed Platform as a Service (PaaS) model, making it the ideal choice for migrating legacy workloads without managing server infrastructure.