Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
Also called Azure AD Application Proxy, Application Proxy, Azure AD Application Proxy, Entra Application Proxy.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500SC-300
Each book explains Microsoft Entra application proxy in context, with comparison tables and the common traps.
Terms in this definition
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
Related terms
- AD FS
Short for Active Directory Federation Services, a federation server hosted on-premises. Its older publishing role, Web Application Proxy, is a separate thing from Microsoft Entra application proxy.
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Cloud Application Administrator
Entra role matching Application Administrator except that it can't manage application proxy.
- Connector group
Groups Microsoft Entra private network connectors so they serve an app together, providing load balancing and high availability. Private Access and application proxy share them; put two or more connectors in every group.
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.
- Header-based single sign-on
A sign-in method for on-premises web apps that work out who is signed in by reading HTTP headers. Either application proxy injects those headers itself, or PingAccess is used to inject them.
- IWA
Sign-in method where domain users access apps with their existing Windows credentials over Kerberos or NTLM. To expose such apps outside the network, Microsoft Entra application proxy can publish them using Kerberos Constrained Delegation.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.