Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A global company is integrating a critical line-of-business application with Azure AD. The application requires highly granular authorization based on custom user attributes that are specific to the company's business processes (e.g., 'ProjectRole', 'SecurityClearanceLevel'). These attributes are not standard Azure AD properties. The company wants to use Conditional Access policies to enforce access based on these custom attributes. How can these custom attributes be integrated with Azure AD Conditional Access?

  1. ABy creating custom claims in the application registration's optionalClaims and using them in Conditional Access.
  2. BBy defining custom security attributes in Azure AD and using them in Conditional Access policy conditions.
  3. CBy using application roles in the application manifest and assigning users to these roles.
  4. DBy extending the Azure AD schema and synchronizing attributes from on-premises AD.
Show answer & explanation

Correct answer: B. By defining custom security attributes in Azure AD and using them in Conditional Access policy conditions.

Custom security attributes in Azure AD are designed precisely for this scenario. They allow organizations to define their own business-specific attributes in Azure AD and then use them in Conditional Access policies, as well as for other purposes like access control and filtering. This directly addresses the need for highly granular authorization based on custom user attributes.

Why the other options are wrong

  • A. Custom claims in optionalClaims can be added to tokens, but Conditional Access policies currently do not have a built-in condition type to directly evaluate arbitrary custom claims from tokens for policy enforcement.
  • C. Application roles are defined within an application and assigned to users, but Conditional Access policies cannot directly evaluate application roles as conditions.
  • D. Extending on-premises AD schema and synchronizing to Azure AD is for standard attributes or well-known extensions, but Conditional Access policies cannot directly consume arbitrary synchronized extension attributes for conditions.

Azure AD Custom Security Attributes

A feature in Azure AD that allows organizations to define their own business-specific attributes for directory objects (users, applications, devices) and use them for authorization and policy enforcement.

  • User-defined attributes in Azure AD.
  • Can be assigned to users, applications, etc.
  • Integrates with Conditional Access for policy enforcement.

Memory trick: Custom Attributes Control Access.

More Implement an authentication and access management solution questions