Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy

A security architect is designing an authentication solution for a new internal web application hosted on Azure App Service. The application needs to authenticate users from the company's Azure AD tenant. The architect wants to leverage Azure AD's built-in authentication capabilities for App Service to minimize development effort and ensure secure token validation. Which authentication provider should be configured directly within the Azure App Service Authentication / Authorization settings?

  1. AFacebook
  2. BMicrosoft
  3. CGoogle
  4. DOpenID Connect
Show answer & explanation

Correct answer: B. Microsoft

When configuring Azure App Service Authentication / Authorization (Easy Auth) for users from your Azure AD tenant, the 'Microsoft' provider is used. This integrates directly with your Azure AD for authentication.

Why the other options are wrong

  • A. Facebook is a social identity provider, used for external users with Facebook accounts, not for internal Azure AD users.
  • C. Google is a social identity provider, used for external users with Google accounts, not for internal Azure AD users.
  • D. OpenID Connect is the underlying protocol, but 'Microsoft' is the specific provider option in App Service for Azure AD.

Azure App Service Authentication (Easy Auth)

Azure App Service Authentication/Authorization (often called 'Easy Auth') provides a way to integrate various identity providers directly into your web app or API without writing authentication code. For internal users in your Azure AD, the 'Microsoft' provider is selected.

  • Simplifies authentication integration for App Services.
  • Supports Azure AD, Microsoft Accounts, social providers (Google, Facebook, Twitter).
  • No code changes required in the application for basic scenarios.
  • Handles token validation and session management.

Memory trick: Easy Auth: For Microsoft Users, Pick Microsoft.

More Manage identity and access questions