Soru

Zorluk: ZorMigration Assessment and Strategy

An international financial services firm plans to transition its on-premises customer portal to Microsoft Azure. The portal is hosted on VMware vSphere 7.0 virtual machines. The underlying database runs on Microsoft SQL Server 2022 and relies heavily on cross-database queries and several SQL Server Agent jobs. To comply with the firm's strict security regulations: 1. No software agents may be installed on any production virtual machines at any stage of the assessment or discovery process. 2. Synchronized user credentials must not leave the on-premises boundary, meaning no password hashes (even encrypted) can be synchronized to the cloud. 3. The deployment of complex on-premises federation infrastructures, such as Active Directory Federation Services (AD FS), is strictly prohibited. Which combination of dependency assessment strategy, database migration target, and hybrid identity synchronization mechanism should you recommend?

  1. A
    Agentless dependency analysis, Azure SQL Database, and Password Hash Synchronization (PHS)
  2. Agentless dependency analysis, Azure SQL Managed Instance, and Pass-through Authentication (PTA)Cevap
  3. C
    Agent-based dependency analysis, Azure SQL Database, and Active Directory Federation Services (AD FS)
  4. D
    Agent-based dependency analysis, Azure SQL Managed Instance, and Password Hash Synchronization (PHS)

Cevap

The correct recommendation is agentless dependency analysis, Azure SQL Managed Instance, and Pass-through Authentication (PTA).
The correct recommendation is agentless dependency analysis, Azure SQL Managed Instance, and Pass-through Authentication (PTA). This option meets all technical and organizational constraints: agentless dependency mapping is native to Azure Migrate for VMware VMs and requires no agent installations; Azure SQL Managed Instance provides compatibility with SQL Server Agent jobs and cross-database queries; and Pass-through Authentication provides hybrid sign-in without uploading password hashes to the cloud or requiring complex Active Directory Federation Services (AD FS) deployments.

Adım Adım Çözüm

1
Determine the appropriate dependency assessment mechanism based on VM agent restrictions.
Since the source VMs run on VMware vSphere and agents are forbidden, agentless dependency analysis via Azure Migrate is the only compliant option.
Agent-based dependency analysis requires deploying the Dependency Agent and Log Analytics Agent, which violates the security constraint.
2
Evaluate the database tier requirements against Azure SQL options.
Azure SQL Managed Instance is chosen as the target database tier.
The database uses cross-database queries and SQL Server Agent jobs, which are not supported in Azure SQL Database but are fully supported in Azure SQL Managed Instance.
3
Identify the hybrid identity integration solution matching the security and infrastructure guidelines.
Pass-through Authentication (PTA) is selected.
PTA validates passwords directly on-premises without storing password hashes in Entra ID (satisfying the security rule), and it does not require deploying AD FS servers (satisfying the simplicity rule).

Anahtar Kavram

Mapping multi-dimensional constraints (agentless discovery, legacy SQL engine features, and zero-cloud-password-hash storage rules) to compatible Azure assessment, database, and identity solutions.
Tahmini Süre:2m 30s
Bu soruyu puanla