Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company uses Azure Active Directory (Azure AD) to manage its user accounts. They need to implement a solution that allows external vendors to self-register for access to a specific application hosted in Azure. The vendors should be able to use their existing social media accounts (e.g., Google, Microsoft) or create a local account within the Azure AD tenant. What Azure AD feature should you configure?

  1. AAzure AD B2C
  2. BAzure AD Connect
  3. CAzure AD Identity Protection
  4. DAzure AD Domain Services (Azure AD DS)
Show answer & explanation

Correct answer: A. Azure AD B2C

Azure AD B2C (Business-to-Consumer) is designed for customer-facing applications, allowing external users to sign up and sign in using various identity providers, including social accounts or local accounts. This perfectly matches the requirement for external vendors to self-register.

Why the other options are wrong

  • B. Azure AD Connect synchronizes on-premises directories with Azure AD, which is not for external self-registration.
  • C. Azure AD Identity Protection helps detect and remediate identity-based risks, but does not handle external user self-registration.
  • D. Azure AD Domain Services provides managed domain services for Azure VMs, not for external user self-registration.

Azure AD B2C

Azure Active Directory B2C (Business-to-Consumer) is a customer identity access management (CIAM) solution that enables customizable, secure sign-up, sign-in, and profile management experiences for customer-facing applications.

  • Manages identities for customer-facing applications.
  • Supports various identity providers (social, local accounts).
  • Allows customization of user journeys and branding.

Memory trick: B2C is for 'Business To Customers' – think external, self-service, social logins.

More Manage Azure identities and governance questions