Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is building a multi-tenant SaaS application on Azure. The application's backend consists of Azure Functions and Azure App Services. Users from different Azure Active Directory (AAD) tenants will access the application. The application needs to authenticate users and then authorize their access to specific resources based on their tenant and assigned roles within that tenant. The application itself is registered in the developer's AAD tenant. Which authentication and authorization flow should the developer implement to allow users from other AAD tenants to securely sign in and access the application?
- ASAML 2.0 with a federated identity provider configured for each tenant.
- BOpenID Connect with the Authorization Code Flow, configured for multi-tenant access.
- CBasic authentication using username and password stored in a central database.
- DOAuth 2.0 Client Credentials flow directly from the client application to the backend.
Show answer & explanationAnswer & explanation
Correct answer: B. OpenID Connect with the Authorization Code Flow, configured for multi-tenant access.
OpenID Connect (OIDC) built on top of OAuth 2.0 is the standard for modern authentication and authorization, especially for web applications. Configuring it for multi-tenant access in Azure AD allows users from different AAD tenants to authenticate seamlessly, and the Authorization Code Flow is suitable for confidential clients like web applications.
Why the other options are wrong
- A. While SAML can be used for federation, OIDC is generally preferred for new cloud-native applications due to its simplicity and modern API-centric design, especially with Azure AD.
- C. Basic authentication is highly insecure and not suitable for modern cloud applications, especially multi-tenant scenarios.
- D. Client Credentials flow is for machine-to-machine communication, not user authentication.
OpenID Connect Multi-Tenant
An identity layer on OAuth 2.0 that allows applications registered in one Azure AD tenant to accept sign-ins from users in any other Azure AD tenant.
- Uses common endpoints for authentication.
- Requires application registration to be 'multi-tenant'.
- Provides ID tokens for user identity and access tokens for authorization.
- Leverages standard OAuth 2.0 flows like Authorization Code Flow.
Memory trick: OpenID is the key to letting many tenants sign in to one app securely.