Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A company is integrating a new cloud-based SaaS application with Microsoft Entra ID. They need to ensure that users are automatically provisioned to the application when their account is created in Microsoft Entra ID and de-provisioned when their account is disabled. Which Microsoft Entra capability should be configured?
- AMicrosoft Entra Connect Sync
- BMicrosoft Entra Conditional Access
- CMicrosoft Entra Application Provisioning
- DMicrosoft Entra Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Entra Application Provisioning
Microsoft Entra Application Provisioning automates the creation, maintenance, and removal of user identities across various cloud applications. This directly addresses the requirement for automatic provisioning and de-provisioning based on account status in Microsoft Entra ID.
Why the other options are wrong
- A. Microsoft Entra Connect Sync synchronizes identities from on-premises AD to Microsoft Entra ID, not from Microsoft Entra ID to SaaS apps.
- B. Conditional Access grants or denies access based on conditions but does not manage the creation or deletion of user accounts in target applications.
- D. PIM manages just-in-time access for privileged roles, not the automated provisioning of standard user accounts to SaaS applications.
Microsoft Entra Application Provisioning
An Entra ID feature that automates the creation, maintenance, and removal of user identities and roles in cloud applications (SaaS apps) based on rules defined in Entra ID.
- Automates identity lifecycle management.
- Connects Microsoft Entra ID to SaaS applications.
- Supports both inbound and outbound provisioning.
Memory trick: Application Provisioning is the automatic butler for your SaaS users.