Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A global company is deploying a new web application that needs to authenticate users from multiple Azure Active Directory (Azure AD) tenants, including external partners. The application is registered in the company's home tenant. What type of user account should be used to allow users from external Azure AD tenants to access this application?

  1. ACloud-only users
  2. BMember users
  3. CGuest users (B2B collaboration)
  4. DSynchronized users
Show answer & explanation

Correct answer: C. Guest users (B2B collaboration)

Guest users, facilitated by Azure AD B2B collaboration, are specifically designed for inviting external users from other Azure AD tenants, Microsoft accounts, or social identities to access applications and resources in your tenant. This allows the global company to onboard external partners securely.

Why the other options are wrong

  • A. Cloud-only users are internal users created directly in Azure AD, not external users from other tenants.
  • B. Member users are internal users of the home tenant.
  • D. Synchronized users are internal users from an on-premises Active Directory synchronized to Azure AD, not external users.

Azure AD B2B Collaboration

A feature of Azure AD that allows organizations to securely share applications and resources with external users from other organizations.

  • External users are represented as guest users in the inviting tenant.
  • Supports various identity providers (Azure AD, Microsoft accounts, social identities).
  • Enables self-service sign-up workflows for onboarding external partners.

Memory trick: Users are either from inside, or invited from outside.

More Implement an authentication and access management solution questions