Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy

A company is integrating a new third-party Software-as-a-Service (SaaS) application into its environment. This SaaS application is listed in the Azure AD application gallery. The company wants to enable single sign-on (SSO) for its users to this application using their existing Azure AD credentials and ensure that user provisioning and deprovisioning are automated. Which type of Azure AD object should be created to represent this SaaS application within the company's Azure AD tenant?

  1. AAzure AD application registration.
  2. BAzure AD managed identity.
  3. CAzure AD enterprise application.
  4. DAzure AD custom roles.
Show answer & explanation

Correct answer: C. Azure AD enterprise application.

An Azure AD enterprise application (service principal) is created when you add an application from the Azure AD gallery or register a custom application. It represents the application within your tenant and is used for configuring SSO, assigning users/groups, and setting up provisioning.

Why the other options are wrong

  • A. An application registration defines the application's identity and its permissions in Azure AD; an enterprise application is the instance of that registration in a tenant.
  • B. Managed identities are for Azure services to authenticate to other Azure services, not for integrating third-party SaaS applications with user SSO.
  • D. Azure AD custom roles define granular permissions for administrators, not for representing SaaS applications.

Azure AD Enterprise Application

An instance of an application (either from the Azure AD gallery or a custom app registration) created within a specific Azure AD tenant, used for managing access, single sign-on, and provisioning for that application.

  • Represents an application instance in a tenant.
  • Used for configuring SSO (SAML, OIDC, password).
  • Enables user/group assignment and automated provisioning.

Memory trick: Enterprise App: The tenant's bridge, to external SaaS, no more login fidget.

More Implement and manage workload identities questions