Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A company uses Azure AD and has several line-of-business (LOB) applications. One critical application requires that users accessing it must be registered with Microsoft Entra ID and have a specific 'Partner' attribute set to 'True'. The company wants to enforce this condition before users are granted access to the application, without modifying the application code. Which Azure AD feature should be used to achieve this?

  1. AExternal Identities settings
  2. BGroups and dynamic membership rules
  3. CApplication Proxy
  4. DConditional Access policies with custom security attributes
Show answer & explanation

Correct answer: D. Conditional Access policies with custom security attributes

Conditional Access policies, when combined with custom security attributes, provide the exact solution. The 'Partner' attribute can be defined as a custom security attribute in Azure AD, assigned to users, and then a Conditional Access policy can be configured to grant access to the application only if the user's 'Partner' attribute is set to 'True'. This enforcement happens before access is granted and requires no application code changes.

Why the other options are wrong

  • A. External Identities settings manage how external users (guests) collaborate, not for enforcing attribute-based access for internal users to LOB apps.
  • B. Groups and dynamic membership rules can assign users to groups based on attributes, but Conditional Access policies are still needed to enforce access based on group membership or directly on attributes for application access.
  • C. Application Proxy provides secure remote access to on-premises web apps, but it does not enforce granular attribute-based access conditions.

Conditional Access with Custom Security Attributes

Leveraging Azure AD Conditional Access policies to enforce access control based on user-defined custom security attributes, enabling highly granular authorization without modifying application code.

  • Custom attributes are defined in Azure AD.
  • Conditional Access policies evaluate these attributes.
  • Enforcement happens at the authentication boundary.
  • No changes to application code required.

Memory trick: Custom Attributes Condition Access.

More Implement an authentication and access management solution questions