Hi ネパリ サンデャ, I want to help you with this question.
License:
Azure AD Premium P1 or P2 is required to use Azure AD App proxy. Keep in mind, when the required license type expires, the app proxy does not work anymore.
Technical prerequisites:
- Your identities must be already synced to AzureAD or have to be created in the Azure AD directly.
- Configuration of a Windows Server which works as a Proxy Server (by the way, it is also possible to have an app deployed on Azure that doesn't support modern auth. Then you can deploy an app proxy server in Azure and do modern authentication with it - so it's not only a solution in hybrid scenarios)
Please read the following article as well: https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-application#prerequisites
Limitations:
I can't think of any limitations right now. do you already have some in mind?
It must be said, however, that the workflow runs somewhat differently and other considerations must be made than for a pure on-premise application.
here I am mainly talking about timeout intervals, which have to be increased or double authentication flow if the application does not support modern authentication yet.
If you have further or more detailed questions, please write them.
If the reply was helpful, please don’t forget to upvote or accept it as an answer, thank you.