Topic: HPE6-A84 topic 1 question 18

Refer to the scenario.
A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).
The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).
The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients’ privileges, ClearPass also should use information collected by Intune to make access control decisions.
You are planning to use Azure AD as the authentication source in 802.1X services.
What should you make sure that the customer understands is required?

A.
An app registration on Azure AD that references the CPPM's FQDN
B.
Windows 365 subscriptions
C.
CPPM's RADIUS certificate was imported as trusted in the Azure AD directory
D.
Azure AD Domain Services

Re: HPE6-A84 topic 1 question 18

Inorder to authenticate directly to Azure AD, You need establish "Azure AD Directory Services" to support the LDAP queries from CPPM.
"directory services" imposes additional cost on top on Azure AD.