Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A company is integrating a custom-developed web application with Azure AD for single sign-on (SSO) using OpenID Connect. The application requires two specific custom attributes, 'EmployeeID' and 'ProjectRole', to be present in the user's ID token upon successful authentication. These attributes are stored as extension attributes in Azure AD. How should the administrator configure Azure AD to include these attributes in the ID token?

  1. AConfigure Optional Claims in the application registration to include the extension attributes.
  2. BDefine new application roles in the application manifest for 'EmployeeID' and 'ProjectRole'.
  3. CCreate custom security attributes for 'EmployeeID' and 'ProjectRole' and assign them to users.
  4. DUse a Claims Mapping Policy to transform existing claims into 'EmployeeID' and 'ProjectRole'.
Show answer & explanation

Correct answer: A. Configure Optional Claims in the application registration to include the extension attributes.

Azure AD Optional Claims allow you to include standard or extension attributes (like custom extension attributes) in tokens. By configuring optional claims in the application registration, 'EmployeeID' and 'ProjectRole' can be directly added to the ID token for OpenID Connect applications.

Why the other options are wrong

  • B. Application roles define permissions within an application, not attributes to be included in tokens.
  • C. Custom security attributes are for defining and assigning attributes to directory objects for authorization purposes, not for automatic inclusion in ID tokens via OpenID Connect without additional configuration like optional claims.
  • D. Claims Mapping Policy is primarily used for SAML tokens and transforming claims, not for directly adding extension attributes to OpenID Connect ID tokens.

Azure AD Optional Claims for Extension Attributes

A feature that enables the inclusion of Azure AD directory extension attributes as claims within security tokens issued to applications by Azure AD, particularly useful for custom application requirements.

  • Configured via the Azure portal or application manifest.
  • Supports both standard claims and directory extension attributes.
  • Ensures custom user data is available in the ID or access token.

Memory trick: Optional Claims ADD attributes, Claims Mapping TRANSFORMS.

More Implement an authentication and access management solution questions