Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A company is integrating a custom-developed web application with Azure AD for single sign-on (SSO). The application uses the OpenID Connect protocol. After a user successfully authenticates with Azure AD, the application needs to retrieve additional user profile information, such as the user's department and employee ID, which are not included in the default ID token. Which manifest property of the application registration in Azure AD should be modified to include these claims in the ID token?
- Aapi
- Boauth2Permissions
- CoptionalClaims
- DrequiredResourceAccess
Show answer & explanationAnswer & explanation
Correct answer: C. optionalClaims
The 'optionalClaims' property in the application manifest allows developers to specify additional claims that Azure AD should return in tokens (ID tokens, access tokens, or SAML tokens) for a given application. This is the correct way to include non-default user profile information like department and employee ID in the ID token.
Why the other options are wrong
- A. The 'api' property defines the properties of the application as an API, including its App ID URI and exposed scopes, but not for requesting additional claims in tokens.
- B. oauth2Permissions defines custom scopes (permissions) that an API exposes, not for requesting additional claims in tokens.
- D. requiredResourceAccess specifies the API permissions that the application needs to consume from other APIs, not for customizing claims in its own issued tokens.
Azure AD Optional Claims
A feature in Azure AD application registrations that allows developers to add standard or custom claims to tokens (ID, access, SAML) issued for their application.
- Configured in the application manifest.
- Used to include additional user or tenant information.
- Enhances application functionality without extra API calls.
Memory trick: Manifest My Claims for Identity.