Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is developing a new customer-facing application that requires users to sign up and sign in using their social media accounts (e.g., Google, Facebook) or by creating a local account within the application's identity system. The company needs a scalable and secure identity solution that integrates seamlessly with Azure and allows for customization of the user experience. Which Azure AD service should they use?

  1. AAzure AD Identity Protection
  2. BAzure AD Connect
  3. CAzure AD B2C
  4. DAzure AD Domain Services
Show answer & explanation

Correct answer: C. Azure AD B2C

Azure AD B2C (Business-to-Consumer) is designed for customer-facing applications, allowing users to sign up, sign in, and manage their profiles using social identities or local accounts, with extensive customization options.

Why the other options are wrong

  • A. Azure AD Identity Protection detects identity-based risks, but doesn't provide the core customer identity platform.
  • B. Azure AD Connect synchronizes on-premises AD with Azure AD, primarily for employees, not external customers.
  • D. Azure AD Domain Services provides managed domain services for Azure VMs, not customer identity management.

Azure AD B2C

A cloud identity management service that enables your applications to authenticate customers and consumers.

  • Supports millions of users and billions of authentications per day.
  • Allows sign-up/sign-in with social identity providers (Google, Facebook) and local accounts.
  • Offers full customization of user flows (sign-up, sign-in, profile editing).

Memory trick: Customers use their own identities to shop.

More Manage identity and access questions