Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A client is deploying a new web application in Azure that needs to authenticate employees using their existing Azure AD identities. The application will also need to securely obtain an access token to call an Azure API Management instance on behalf of the user. Which industry-standard protocol is best suited for this scenario, allowing the web application to securely delegate user consent for accessing the API?
- AKerberos
- BWS-Federation
- CLDAP
- DOAuth 2.0 / OpenID Connect
Show answer & explanationAnswer & explanation
Correct answer: D. OAuth 2.0 / OpenID Connect
OAuth 2.0 is an authorization framework that enables a web application to obtain delegated access to protected resources (like an API) on behalf of a user. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, providing identity verification. Together, they are the standard for modern web applications integrating with Azure AD for both authentication and delegated authorization to APIs.
Why the other options are wrong
- A. Kerberos is a network authentication protocol primarily used in on-premises Windows environments.
- B. WS-Federation is an older federation protocol, primarily used for interoperability with ADFS, less common for modern cloud-native web apps and APIs.
- C. LDAP is a protocol for accessing and maintaining distributed directory information services, not for modern web SSO or API authorization.
OAuth 2.0 / OpenID Connect (OIDC)
OAuth 2.0 is an authorization framework, and OpenID Connect is an identity layer built on OAuth 2.0, enabling clients to verify end-user identity and obtain basic profile information.
- OAuth 2.0 focuses on authorization (delegated access to resources).
- OpenID Connect focuses on authentication (identity verification).
- Widely adopted for modern web, mobile, and API security with Azure AD.
Memory trick: OAuth and OIDC are the modern keys for web apps and APIs.