Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A company is integrating a new third-party SaaS application with Azure AD for single sign-on (SSO). The application requires specific user attributes (e.g., employee ID, department) to be sent as claims within the security token during the authentication process. Which part of the Azure AD application configuration allows an administrator to define and map these custom user attributes to claims for the SaaS application?
- ASingle sign-on (SAML/OpenID Connect) configuration
- BUsers and groups assignment
- CConditional Access policies
- DProvisioning settings
Show answer & explanationAnswer & explanation
Correct answer: A. Single sign-on (SAML/OpenID Connect) configuration
Within the Single sign-on configuration of an enterprise application in Azure AD (for SAML or OpenID Connect), administrators can define and map user attributes to claims that will be included in the security token issued to the application. This allows the application to receive the necessary user information for authorization and personalization.
Why the other options are wrong
- B. Users and groups assignment controls who can access the application, not what attributes are sent.
- C. Conditional Access policies define access conditions, not attribute mapping for claims.
- D. Provisioning settings manage automated user account creation and updates in the target application, not real-time claims during SSO.
SAML Claims Mapping
The process of defining which user attributes from Azure AD are included as claims in the SAML token issued to a service provider during single sign-on.
- Allows customization of the information sent to the application.
- Essential for applications requiring specific user data for authorization or personalization.
- Configured within the enterprise application's SSO settings in Azure AD.
Memory trick: SSO configuration maps attributes to claims, like a personalized ID.