Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company is integrating a new SaaS application with Azure AD for single sign-on (SSO). They also need to automate the creation, updating, and deletion of user accounts in the SaaS application based on changes in Azure AD group memberships. Which Azure AD feature, utilizing the SCIM protocol, should be configured to achieve this automated provisioning?

  1. AAzure AD B2B Collaboration
  2. BAzure AD Enterprise Application Provisioning
  3. CAzure AD Connect
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: B. Azure AD Enterprise Application Provisioning

Azure AD Enterprise Application Provisioning (often leveraging the SCIM protocol) is specifically designed to automate the lifecycle management of user identities between Azure AD and third-party SaaS applications, matching the requirement for automated creation, updating, and deletion based on group memberships.

Why the other options are wrong

  • A. B2B Collaboration is for inviting external users, not for provisioning internal users to SaaS apps.
  • C. Azure AD Connect synchronizes on-premises AD to Azure AD, not Azure AD to SaaS apps.
  • D. Application Proxy provides remote access to on-premises apps, not user provisioning for SaaS apps.

Azure AD Provisioning (SCIM)

A feature in Azure AD that automates the creation, maintenance, and removal of user identities in external applications (typically SaaS apps) based on changes in Azure AD. It commonly uses the System for Cross-domain Identity Management (SCIM) protocol.

  • Automates identity lifecycle management.
  • Reduces manual administrative overhead.
  • Ensures consistent access rights between Azure AD and target applications.

Memory trick: SCIM syncs users, making SaaS seamless.

More Implement an identity management solution questions