Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A client is integrating a custom-built Line-of-Business (LOB) application with Azure AD for single sign-on (SSO). The application expects user attributes like 'department' and 'employee ID' to be sent in the SAML token during the authentication process. Which part of the Azure AD application registration configuration needs to be modified to include these custom attributes in the SAML token?

  1. AAuthentication methods
  2. BToken configuration (Optional claims)
  3. CAPI Permissions
  4. DEnterprise applications (Single sign-on settings)
Show answer & explanation

Correct answer: D. Enterprise applications (Single sign-on settings)

For SAML-based SSO with Azure AD, custom user attributes (claims) are configured within the 'Single sign-on' settings of the Enterprise application registration. Specifically, in the 'User Attributes & Claims' section, you can add new claims and map them to Azure AD user properties or directory extension attributes, ensuring they are included in the SAML token sent to the LOB application.

Why the other options are wrong

  • A. Authentication methods configure how users authenticate to Azure AD (e.g., MFA), not the attributes sent in a token.
  • B. Token configuration (Optional claims) is for adding claims to JWT (OAuth/OIDC) tokens, not SAML tokens.
  • C. API Permissions define what an application can do in Azure AD or other APIs, not what claims are issued in a SAML token.

Azure AD SAML Claims Mapping

Configuring custom user attributes (claims) to be included in the SAML token issued by Azure AD for an enterprise application.

  • Configured in Enterprise Applications > Single sign-on.
  • Maps Azure AD user properties to SAML claims.
  • Essential for LOB applications requiring specific attributes.

Memory trick: SAML Claims: Send Attributes, Make it Known.

More Manage identity and access questions