Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A global company uses Azure AD and has deployed a new application that uses the OpenID Connect protocol for authentication. The application requires specific custom attributes from the user's profile, such as 'DepartmentID' and 'CostCenter', to be included in the ID token. How can these attributes be added to the ID token?

  1. ACreate an application role in the application's manifest.
  2. BUse Microsoft Graph API to retrieve the attributes post-authentication.
  3. CConfigure a custom security attribute in Azure AD.
  4. DConfigure optional claims in the application's manifest.
Show answer & explanation

Correct answer: D. Configure optional claims in the application's manifest.

Azure AD optional claims allow you to add standard or custom attributes to tokens issued by Azure AD. By configuring optional claims in the application's manifest, you can specify 'DepartmentID' and 'CostCenter' to be included directly in the ID token for OpenID Connect applications.

Why the other options are wrong

  • A. Application roles are for defining permissions within an application, not for adding user attributes to tokens.
  • B. While possible, retrieving attributes post-authentication via Graph API adds complexity and latency. The requirement is to 'be included in the ID token', which optional claims achieve directly.
  • C. Custom security attributes are for authorization decisions, not for inclusion in tokens by default for OpenID Connect apps.

Azure AD Optional Claims

A feature in Azure AD that allows administrators to configure additional claims to be included in the security tokens (ID, access, SAML) issued to applications.

  • Can include standard claims or directory extension attributes.
  • Configured in the application's manifest or through Azure portal.
  • Reduces the need for applications to make additional Graph API calls.

Memory trick: Claims make tokens rich, Optional adds the extras.

More Implement an authentication and access management solution questions