Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is developing a new customer-facing web application that needs to authenticate users using their social media accounts (e.g., Google, Facebook) or their existing email addresses. They want to integrate this authentication process seamlessly with Azure AD while also allowing for custom user attributes to be collected during sign-up. Which Azure AD service should they use?

  1. AAzure AD B2B Collaboration
  2. BAzure AD B2C
  3. CAzure AD Managed Identities
  4. DAzure AD Application Proxy
Show answer & explanation

Correct answer: B. Azure AD B2C

Azure AD B2C (Business-to-Consumer) is specifically designed for customer-facing applications, enabling authentication with social identities, local accounts (email/password), and offering highly customizable user flows for sign-up and sign-in, including collecting custom attributes.

Why the other options are wrong

  • A. Azure AD B2B Collaboration is for inviting external business partners (guest users) to access internal organizational resources, not for customer applications with social logins.
  • C. Azure AD Managed Identities are for Azure resources to authenticate to other Azure services, not for authenticating external customers.
  • D. Azure AD Application Proxy provides secure remote access to on-premises web applications, not identity management for customer applications.

Azure AD B2C

A cloud-based identity and access management service that enables customer-facing applications to authenticate users using social accounts, enterprise accounts, or local credentials.

  • Designed for consumer applications.
  • Supports social identity providers (Google, Facebook, etc.).
  • Highly customizable user journeys for sign-up/sign-in.

Memory trick: B2C is for your 'Customers' (Consumers) and their 'Casual' logins.

More Manage identity and access questions