Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A large enterprise with multiple subsidiary companies, each with its own Azure AD tenant, wants to implement a centralized application portal. Users from any subsidiary tenant should be able to access applications hosted in the central tenant's application portal using their own tenant's credentials. The enterprise wants to minimize administrative overhead for managing user accounts and ensure a seamless single sign-on experience. What is the most appropriate solution to achieve this cross-tenant access?

  1. AAzure AD B2B collaboration with guest accounts for each user in the central tenant.
  2. BAzure AD organizations (multi-tenant organization) with cross-tenant synchronization.
  3. CCreating shadow accounts in the central tenant and synchronizing passwords.
  4. DAzure AD B2C for consumer identity management.
Show answer & explanation

Correct answer: B. Azure AD organizations (multi-tenant organization) with cross-tenant synchronization.

Azure AD multi-tenant organization (MTO) with cross-tenant synchronization is specifically designed for scenarios involving multiple Azure AD tenants within the same organization (e.g., subsidiaries). It allows for seamless collaboration and resource access across tenants, including synchronized user profiles and simplified access to applications, without requiring guest accounts for every user, thereby minimizing administrative overhead and ensuring a seamless SSO experience.

Why the other options are wrong

  • A. Azure AD B2B collaboration with guest accounts would work but introduces significant administrative overhead for managing individual guest accounts for potentially thousands of users across multiple subsidiaries, and the user experience might not be as seamless as MTO.
  • C. Creating shadow accounts and synchronizing passwords is a legacy, insecure, and unsupported method for cross-tenant access in Azure AD.
  • D. Azure AD B2C is for consumer-facing applications and external identities, not for internal enterprise cross-tenant scenarios.

Azure AD Multi-Tenant Organization (MTO)

A feature in Azure AD that enables seamless collaboration and resource access between multiple Azure AD tenants belonging to the same organization, using cross-tenant synchronization.

  • Designed for enterprise scenarios with multiple internal tenants.
  • Synchronizes user profiles across tenants.
  • Provides seamless access to resources without individual guest accounts.

Memory trick: MTO: Many Tenants, One Org.

More Implement an authentication and access management solution questions