Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard
A company is developing a multi-tenant SaaS application that will run in Azure. Customers will subscribe to this application, and it needs to access data in each customer's Azure AD tenant (e.g., read user profiles). The application developers need to ensure that customers can easily grant consent for the application to access their tenant's data. Which authentication flow and application registration configuration is required?
- ASingle-tenant application registration with device code flow.
- BMulti-tenant application registration with an OAuth 2.0 authorization code flow.
- CSingle-tenant application registration with client credentials flow.
- DMulti-tenant application registration with a SAML 2.0 flow.
Show answer & explanationAnswer & explanation
Correct answer: B. Multi-tenant application registration with an OAuth 2.0 authorization code flow.
For a multi-tenant SaaS application needing access to customer tenants, a multi-tenant application registration is essential. The OAuth 2.0 authorization code flow is the standard and most secure flow for web applications to obtain delegated permissions to access user data, as it involves user consent and issues tokens securely.
Why the other options are wrong
- A. A single-tenant registration won't work for multiple customers. Device code flow is for input-constrained devices, not typical web SaaS applications requiring user consent.
- C. A single-tenant registration cannot be used by multiple customer tenants. Client credentials flow doesn't involve user consent, which is typically required for accessing user profiles.
- D. SAML 2.0 is primarily for single sign-on (authentication), not directly for authorizing an application to access API data with user consent in a multi-tenant fashion. OAuth is the correct protocol for API authorization.
Multi-tenant Application Registration
An Azure AD application registration configured to allow users from any Azure AD tenant to sign in and grant consent for the application to access resources in their tenant.
- Allows other Azure AD tenants to use your application.
- Requires the 'Supported account types' to be set to 'Accounts in any organizational directory'.
- Involves an admin/user consent process for each customer tenant.
- Commonly used with OAuth 2.0 authorization code flow for web applications.
Memory trick: Multi-tenant app, OAuth's the way, for all your customers to play!