Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A security architect is designing an authentication solution for a new internal web application hosted on Azure App Service. The application needs to authenticate users from the company's Azure AD tenant. The architect wants to leverage Azure AD's built-in authentication capabilities for App Service to minimize development effort and ensure secure token validation. Which authentication provider should be configured directly within the Azure App Service Authentication / Authorization settings?
- AFacebook
- BMicrosoft
- CGoogle
- DOpenID Connect
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft
When configuring Azure App Service Authentication / Authorization (Easy Auth) for users from your Azure AD tenant, the 'Microsoft' provider is used. This integrates directly with your Azure AD for authentication.
Why the other options are wrong
- A. Facebook is a social identity provider, used for external users with Facebook accounts, not for internal Azure AD users.
- C. Google is a social identity provider, used for external users with Google accounts, not for internal Azure AD users.
- D. OpenID Connect is the underlying protocol, but 'Microsoft' is the specific provider option in App Service for Azure AD.
Azure App Service Authentication (Easy Auth)
Azure App Service Authentication/Authorization (often called 'Easy Auth') provides a way to integrate various identity providers directly into your web app or API without writing authentication code. For internal users in your Azure AD, the 'Microsoft' provider is selected.
- Simplifies authentication integration for App Services.
- Supports Azure AD, Microsoft Accounts, social providers (Google, Facebook, Twitter).
- No code changes required in the application for basic scenarios.
- Handles token validation and session management.
Memory trick: Easy Auth: For Microsoft Users, Pick Microsoft.