A global media company is designing a Zero Trust architecture for its content creation and distribution workflows, which involve numerous third-party contractors and freelancers. The company needs to ensure that these external users can securely access specific applications and data in Azure, but their identities are managed by their respective organizations, not by the media company's Azure AD. Which Azure AD capability is crucial for enabling this secure, identity-federated access?
- AAzure AD Connect
- BAzure AD Domain Services
- CAzure AD B2B collaboration
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD B2B collaboration
Azure AD B2B collaboration allows organizations to securely share their applications and services with external users (guest users) from any organization, while allowing those guest users to sign in with their own identities (managed by their home directory). This aligns perfectly with the scenario's requirement for federated access for external contractors.
Why the other options are wrong
- A. Azure AD Connect synchronizes on-premises Active Directory identities with Azure AD and is not for federating external organizations.
- B. Azure AD Domain Services provides managed domain services (like traditional AD DS) in Azure and is not for external identity federation.
- D. Azure AD Identity Protection detects and remediates identity-based risks within an organization's own Azure AD, not for managing external federated identities.
Azure AD B2B Collaboration
A feature of Azure Active Directory that allows you to securely share your applications and services with external users from any organization, while maintaining control over your own corporate data. Guest users sign in with their own identities, federating access with their home directory.
- Securely share apps with external users
- External users sign in with their own identities
- No need to manage external user accounts
- Integrates with Conditional Access
Memory trick: B2B lets external users bring their own identity to your cloud party.