Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A company is developing a multi-tenant SaaS application that will run in Azure. Customers will use their own Azure AD tenants to authenticate to the application. You need to configure the application in Azure AD to allow customers from different tenants to sign in. Which property must be configured when registering the application?

  1. AThe 'Redirect URI' property must point to a specific tenant's login page.
  2. BThe 'API permissions' property must include 'Microsoft Graph / User.Read.All'.
  3. CThe 'Supported account types' property must be set to 'Accounts in any organizational directory (Any Azure AD directory - Multitenant)'.
  4. DThe 'Implicit grant and hybrid flows' property must be enabled for access tokens.
Show answer & explanation

Correct answer: C. The 'Supported account types' property must be set to 'Accounts in any organizational directory (Any Azure AD directory - Multitenant)'.

To enable a multi-tenant application in Azure AD, the 'Supported account types' property of the application registration must be explicitly set to 'Accounts in any organizational directory (Any Azure AD directory - Multitenant)'. This configures the application to accept sign-ins from users in any Azure AD tenant, fulfilling the multi-tenant requirement.

Why the other options are wrong

  • A. The Redirect URI specifies where Azure AD should send the authentication response; for multi-tenant apps, it typically points to the application's callback URL, not a specific tenant's login page.
  • B. API permissions define what data the application can access, not whether it's multi-tenant. While User.Read.All might be needed, it's not the primary setting for multi-tenancy.
  • D. Implicit grant and hybrid flows are authentication flow types, not the property that defines an application's multi-tenant capability.

Multi-tenant Application Registration

An Azure AD application registration configured to accept sign-ins from users in any Azure AD tenant, allowing a single application instance to serve multiple organizations.

  • Requires 'Supported account types' to be set to 'Multitenant'.
  • Involves user consent from each tenant's administrators.
  • Service principal is created in each tenant where consent is granted.
  • Essential for SaaS applications serving multiple customers.

Memory trick: Supported Accounts Span All Tenants.

More Implement and manage workload identities questions