Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
An organization is deploying a new web application in Azure that needs to authenticate employees using their existing Azure AD identities. The application developers want to implement a secure and standardized authentication protocol that supports single sign-on (SSO) and can also acquire access tokens for calling other Azure AD-protected APIs (e.g., Microsoft Graph). Which modern authentication protocol is most suitable for this scenario?
- AKerberos
- BNTLM
- CSAML 2.0
- DOAuth 2.0 / OpenID Connect
Show answer & explanationAnswer & explanation
Correct answer: D. OAuth 2.0 / OpenID Connect
OAuth 2.0 is an authorization framework, and OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. Together, they provide modern authentication, SSO, and the ability to acquire access tokens for calling APIs, which is ideal for web applications in Azure AD.
Why the other options are wrong
- A. Kerberos is an older authentication protocol primarily used in on-premises Windows environments, not directly for web applications with Azure AD.
- B. NTLM is an older challenge-response authentication protocol, also primarily for on-premises Windows, and not suitable for modern web applications with Azure AD.
- C. SAML 2.0 is an XML-based protocol for exchanging authentication and authorization data, commonly used for SSO, but OAuth 2.0/OIDC is more modern and better suited for API access in web applications.
OAuth 2.0 / OpenID Connect
OAuth 2.0 is an authorization framework, and OpenID Connect (OIDC) is an identity layer built on OAuth 2.0, providing authentication.
- OIDC provides identity (who the user is), OAuth 2.0 provides authorization (what the user can do).
- Widely adopted for modern web and mobile applications.
- Enables Single Sign-On (SSO) and secure API access using access tokens.
Memory trick: For web apps, choose the modern key for identity and permissions.