Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A global organization is integrating a new third-party SaaS application that requires users to authenticate using their Azure AD credentials. The application supports SAML 2.0. The organization needs to ensure that when a user signs into the SaaS application, a specific custom attribute from their Azure AD user profile (e.g., 'EmployeeID') is sent to the SaaS application as part of the SAML token. Which configuration is required in Azure AD?
- ACustomize user attributes and claims in the enterprise application
- BModify the SAML token signing certificate
- CConfigure SCIM for attribute provisioning
- DEnable single sign-on with OpenID Connect
Show answer & explanationAnswer & explanation
Correct answer: A. Customize user attributes and claims in the enterprise application
To include custom attributes in the SAML token sent to a SaaS application, you must customize the user attributes and claims within the enterprise application's single sign-on configuration in Azure AD. This allows you to map specific Azure AD user properties to SAML claims.
Why the other options are wrong
- B. Modifying the SAML token signing certificate relates to trust and security, not the content of the claims within the token.
- C. SCIM is for synchronizing user identities and attributes between systems, not for sending attributes in a SAML token during single sign-on.
- D. OpenID Connect is a different authentication protocol; the question specifies SAML 2.0.
SAML Claims Mapping
The process of configuring which attributes from Azure AD user profiles are included as claims in the SAML token sent to a service provider (SaaS application) during single sign-on.
- Crucial for passing user data to applications.
- Configured within the enterprise application's SSO settings.
- Allows mapping Azure AD attributes to custom SAML claim names.
Memory trick: SAML claims mapping is like packing a custom lunchbox of user info for the app.