A company is developing a new multi-tenant SaaS application that needs to integrate with various customer Azure AD tenants for user authentication. The application will need to read basic user profiles and potentially update specific user attributes (e.g., phone number) in the customer's Azure AD. The development team wants to ensure that customers can easily grant the necessary permissions to the application without requiring a Global Administrator for every single tenant, while still maintaining control over the consented permissions. Which Azure AD feature facilitates this requirement?
- AAzure AD managed identities
- BAzure AD application proxy
- CAzure AD admin consent workflow
- DAzure AD B2B collaboration
Show answer & explanationAnswer & explanation
Correct answer: C. Azure AD admin consent workflow
The Azure AD admin consent workflow allows users to request administrator approval for an application to access resources. This enables non-global administrators to initiate a consent request that a designated administrator (who might not be a Global Admin but has a role like Application Administrator) can review and approve.
Why the other options are wrong
- A. Managed identities are for Azure services authenticating to other Azure services, not for external SaaS apps integrating with multiple customer tenants.
- B. Application Proxy provides secure remote access to on-premises web apps, unrelated to multi-tenant application consent.
- D. B2B collaboration is for inviting external users to a tenant, not for multi-tenant application registration and consent management.
Azure AD Admin Consent Workflow
The Azure AD admin consent workflow enables users to request administrator approval for an application that requires permissions an ordinary user cannot grant. It streamlines the process by allowing non-admin users to initiate a request for an admin to review and approve the application's access to tenant resources.
- Users can request admin approval for applications.
- Admins can review requests in the Azure portal.
- Allows delegation of consent approval to roles like Application Administrator.
- Crucial for multi-tenant applications requiring elevated permissions.
Memory trick: Consent Workflow: Ask, Delegate, Approve.