Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company is integrating a new SaaS application with Azure AD for single sign-on (SSO). The application supports SAML 2.0 for authentication. The company wants to ensure that users are automatically provisioned and deprovisioned in the SaaS application based on their group membership in Azure AD. Which Azure AD feature should be configured to automate this user lifecycle management?

  1. AAzure AD Application Proxy
  2. BAzure AD B2B collaboration
  3. CAzure AD Connect Health
  4. DAzure AD provisioning (SCIM)
Show answer & explanation

Correct answer: D. Azure AD provisioning (SCIM)

Azure AD provisioning (often using the SCIM protocol) automates the creation, maintenance, and removal of user identities in target applications based on changes in Azure AD, such as group membership.

Why the other options are wrong

  • A. Azure AD Application Proxy provides secure remote access to on-premises web applications, not user provisioning for SaaS apps.
  • B. Azure AD B2B collaboration is for inviting external guest users to your tenant, not for provisioning internal users to SaaS apps.
  • C. Azure AD Connect Health monitors the health of your identity infrastructure, not for provisioning users to SaaS apps.

Azure AD Provisioning (SCIM)

An Azure AD service that automates the lifecycle management of user identities across various cloud and on-premises applications.

  • Uses the SCIM protocol for communication with target applications.
  • Automates creating, updating, and deleting user accounts.
  • Synchronizes user attributes and group memberships.

Memory trick: App Integration: SSO for login, Provisioning for users, Proxy for on-prem.

More Implement an identity management solution questions