Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A company uses Azure AD and has deployed a new application that uses the OpenID Connect protocol for authentication. The application requires specific user attributes, such as employee ID and department, to be included in the ID token for authorization purposes. Which feature in Azure AD should be configured to ensure these attributes are sent in the ID token?
- AConditional Access policies
- BToken configuration (Optional claims)
- CApplication proxy
- DUser attributes & properties
Show answer & explanationAnswer & explanation
Correct answer: B. Token configuration (Optional claims)
Token configuration, specifically optional claims, allows you to customize the claims included in tokens (ID tokens, access tokens, SAML tokens) issued by Azure AD for your application. This is the direct mechanism to add specific user attributes like employee ID and department.
Why the other options are wrong
- A. Conditional Access policies are for enforcing access controls, not for customizing token contents.
- C. Application proxy provides secure remote access to on-premises web applications, not for customizing token attributes.
- D. User attributes & properties is where the data is stored, but not where you configure what gets sent in a token.
Azure AD Optional Claims
Optional claims in Azure AD allow you to customize the claims emitted in tokens (ID tokens, access tokens, SAML tokens) for your application. This includes adding standard claims, custom directory attributes, or specific application-specific claims.
- Configured per application registration in Azure AD.
- Can include schema extension attributes.
- Used to provide applications with additional user information.
Memory trick: Token config is like ordering a custom pizza with optional toppings.