You have an Azure Active Directory (Azure AD) tenant that syncs with an on-premises Active Directory domain. You have an internal web app named WebApp1 that is hosted on-premises. WebApp1 uses Integrated Windows authentication.
Some users work remotely and do NOT have VPN access to the on-premises network. You need to provide the remote users with single sign-on (SSO) access to WebApp1.
Which two features should you include in the solution?
Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a) Azure AD Application Proxy
b) Azure AD Privileged Identity Management (PIM)
c) Conditional Access policies
d) Azure Arc
e) Azure AD enterprise applications
f) Azure Application Gateway
