Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionEasy
A company is using Azure AD and wants to standardize user access to all corporate resources based on job function. They plan to use Azure AD groups to manage permissions. What type of Azure AD group should be used to assign licenses and access to Microsoft 365 applications, as well as access to non-Microsoft SaaS applications integrated with Azure AD for SSO?
- ADynamic user group
- BSecurity group
- CMail-enabled security group
- DMicrosoft 365 group
Show answer & explanationAnswer & explanation
Correct answer: B. Security group
Azure AD security groups are the primary type of group used for managing access to Azure resources, assigning licenses, and granting access to applications (both Microsoft 365 and integrated SaaS apps). They are designed for managing user and computer access.
Why the other options are wrong
- A. Dynamic user groups are based on rules and automatically manage membership, but they are still either security groups or Microsoft 365 groups in terms of their capabilities; the core group type for access is 'Security group'.
- C. Mail-enabled security groups are primarily for email distribution lists and security, but for pure access management, a standard security group is sufficient.
- D. Microsoft 365 groups are primarily for collaboration (e.g., shared inbox, calendar, SharePoint site) and also provide access to associated resources, but security groups are the general-purpose choice for access control.
Azure AD Security Group
A collection of users, devices, or other security groups that can be used to manage access to resources and assign permissions.
- Can be used to assign licenses to users.
- Can be used to grant access to Azure resources and applications.
- Supports both assigned and dynamic membership.
Memory trick: Groups: Security for access, O365 for collaboration.