Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionEasy
A company is integrating a new Human Resources (HR) system with Azure AD. They need to automate the creation, update, and deletion of user accounts in Azure AD based on changes in the HR system. This integration should also ensure that user attributes like department and job title are consistently synchronized. Which Azure AD feature is best suited for this requirement?
- AAzure AD Connect
- BAzure AD Identity Protection
- CAzure AD B2B Collaboration
- DAzure AD Application Provisioning (SCIM)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Application Provisioning (SCIM)
Azure AD Application Provisioning, leveraging the SCIM (System for Cross-domain Identity Management) protocol, is specifically designed to automate the lifecycle management of user identities between Azure AD and other cloud applications or HR systems.
Why the other options are wrong
- A. Azure AD Connect is primarily for synchronizing identities from on-premises Active Directory to Azure AD, not from HR systems.
- B. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on user lifecycle management.
- C. Azure AD B2B Collaboration is for inviting and managing external guest users, not for internal user lifecycle management from an HR system.
Azure AD Application Provisioning (SCIM)
Automates the creation, maintenance, and removal of user identities across various cloud applications and HR systems.
- Uses the SCIM protocol for interoperability.
- Supports inbound (HR to AD) and outbound (AD to SaaS) provisioning.
- Ensures attribute consistency and reduces manual overhead.
Memory trick: Provisioning is the 'HR hand-off' to Azure AD, keeping everyone in sync.