Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A company is designing a new solution that requires a custom application to programmatically provision and deprovision users from Azure AD to a third-party SaaS application. This process needs to be automated and run on a schedule. Which protocol is commonly used by Azure AD for this type of automated identity provisioning?

  1. ASAML 2.0
  2. BSCIM
  3. COAuth 2.0
  4. DOpenID Connect
Show answer & explanation

Correct answer: B. SCIM

SCIM (System for Cross-domain Identity Management) is an open standard protocol specifically designed for automating the exchange of user and group identity information between identity domains, making it ideal for provisioning and deprovisioning users to SaaS applications.

Why the other options are wrong

  • A. SAML 2.0 is primarily for single sign-on (authentication), not for automated user provisioning and deprovisioning.
  • C. OAuth 2.0 is an authorization framework for granting delegated access, not for identity provisioning.
  • D. OpenID Connect is an identity layer on top of OAuth 2.0, primarily for authentication and obtaining basic user profile information, not for provisioning.

SCIM (System for Cross-domain Identity Management)

An open standard protocol for automating the exchange of user and group identity information between identity domains or cloud applications.

  • Used for automated provisioning and deprovisioning.
  • Simplifies identity lifecycle management.
  • Reduces manual administration and human error.

Memory trick: SCIM is for 'Synchronizing' 'Cloud' 'Identities' 'Magically'.

More Manage identity and access questions