Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionHard

A company wants to allow external contractors to access specific applications hosted in their Azure AD tenant. These contractors use their existing Google accounts for authentication. The company needs to configure a method that allows these external users to sign in using their Google credentials and access the applications with minimal administrative overhead. Which external identity configuration should be implemented?

  1. ACreating guest user accounts manually in Azure AD
  2. BAzure AD B2B invitation with Google federation
  3. CAzure AD B2C tenant setup
  4. DAzure AD B2B direct connect
Show answer & explanation

Correct answer: B. Azure AD B2B invitation with Google federation

Azure AD B2B collaboration allows inviting external users. By configuring Google federation in Azure AD, these invited users can sign in using their existing Google accounts, streamlining the process and reducing administrative overhead.

Why the other options are wrong

  • A. Creating guest accounts manually doesn't leverage their existing Google accounts for sign-in and increases administrative overhead for each user.
  • C. Azure AD B2C is for customer-facing applications, not typically for inviting specific external business partners/contractors.
  • D. B2B direct connect is for seamless collaboration between two Azure AD tenants, not for external users with social IDs.

Azure AD B2B Federation

Azure AD B2B federation allows external users from other organizations (e.g., Azure AD, Google, Facebook) to sign in to your Azure AD tenant using their existing credentials.

  • Supports various identity providers (Azure AD, Google, Facebook, SAML/WS-Fed).
  • Streamlines guest user sign-in experience.
  • Reduces administrative overhead for guest account management.

Memory trick: B2B federation is the 'easy pass' for guests with their own keys.

More Implement an identity management solution questions