Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is developing a new multi-tenant SaaS application that needs to authenticate users from various Azure AD tenants. The application must be able to securely access resources on behalf of the authenticated users, such as reading their profiles from their respective Azure AD tenants. Which authentication and authorization framework should the application use?

  1. AKerberos
  2. BOAuth 2.0 and OpenID Connect (OIDC)
  3. CSAML 2.0
  4. DWS-Federation
Show answer & explanation

Correct answer: B. OAuth 2.0 and OpenID Connect (OIDC)

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. OIDC handles user authentication and provides identity tokens, while OAuth 2.0 handles authorization, allowing the application to securely access protected resources (like user profiles) on behalf of the user. This combination is ideal for multi-tenant SaaS applications needing both authentication and delegated authorization.

Why the other options are wrong

  • A. Kerberos is an authentication protocol mainly used in on-premises Windows environments and is not suitable for cloud-native multi-tenant SaaS applications.
  • C. SAML 2.0 is primarily for single sign-on (SSO) and federation, but less suited for delegated authorization to access APIs on behalf of a user.
  • D. WS-Federation is an older federation protocol, less commonly used than OIDC/OAuth 2.0 for modern cloud applications and APIs.

OAuth 2.0 & OpenID Connect (OIDC)

OAuth 2.0 is an authorization framework, and OpenID Connect is an identity layer built on OAuth 2.0 for authentication.

  • OIDC for authentication (who is the user).
  • OAuth 2.0 for authorization (what can the app do).
  • Widely adopted for modern web and mobile apps.

Memory trick: OIDC/OAuth: Open Doors for Identity and Access.

More Manage identity and access questions