Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is implementing a new HR application that requires user provisioning and deprovisioning to be automated based on user lifecycle events in Azure AD. This application supports the System for Cross-domain Identity Management (SCIM) protocol. Which Azure AD feature should be configured to automatically create, update, and delete user accounts in the HR application?
- AAzure AD Enterprise Applications (SSO)
- BAzure AD Application Provisioning
- CAzure AD Identity Governance
- DAzure AD Connect Health
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Application Provisioning
Azure AD Application Provisioning automates the creation, maintenance, and removal of user identities in cloud applications (SaaS apps) based on user lifecycle events in Azure AD, often utilizing the SCIM protocol for integration.
Why the other options are wrong
- A. Azure AD Enterprise Applications (SSO) primarily handles single sign-on, not automated user lifecycle management.
- C. Azure AD Identity Governance provides advanced identity management features like access reviews and entitlement management but does not directly handle automated provisioning to SaaS apps itself; provisioning is a separate, complementary feature.
- D. Azure AD Connect Health monitors the health of your on-premises identity infrastructure, not for provisioning users to SaaS apps.
Azure AD Application Provisioning (SCIM)
An Azure AD service that automates the creation, update, and deletion of user accounts in integrated SaaS applications, typically using the SCIM protocol, based on user lifecycle events in Azure AD.
- Automates identity lifecycle management.
- Supports SCIM-based applications.
- Reduces manual administrative overhead.
Memory trick: Provisioning: People Flow Seamlessly