Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is implementing a new HR application that requires user provisioning and deprovisioning to be automated based on changes in the company's HR system (Workday). They want to ensure that user accounts are automatically created, updated, and deleted in Azure AD and connected SaaS applications when changes occur in Workday. Which Azure AD feature should be used to integrate Workday with Azure AD for identity provisioning?

  1. AAzure AD provisioning (SCIM-based)
  2. BAzure AD Connect synchronization
  3. CAzure AD B2B collaboration
  4. DAzure AD Connect cloud sync
Show answer & explanation

Correct answer: A. Azure AD provisioning (SCIM-based)

Azure AD provisioning, often referred to as SCIM-based provisioning, is specifically designed to automate the creation, updating, and deletion of user identities between Azure AD and external systems like HR applications or SaaS apps.

Why the other options are wrong

  • B. Azure AD Connect synchronization is for on-premises AD to Azure AD, not HR systems.
  • C. B2B collaboration is for managing external guest users, not for provisioning internal users from an HR system.
  • D. Cloud sync is for synchronizing on-premises AD to Azure AD, not HR systems to Azure AD.

Azure AD SCIM Provisioning

Azure AD supports System for Cross-domain Identity Management (SCIM) for automated user provisioning and deprovisioning between Azure AD and various cloud applications or HR systems.

  • Automates identity lifecycle management.
  • Uses the SCIM protocol for integration.
  • Supports HR-driven provisioning to Azure AD and then to SaaS apps.

Memory trick: SCIM is the 'seamless' way to manage identities across systems.

More Implement an identity management solution questions