Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is building a multi-tenant SaaS application on Azure. The application's backend API is secured with Azure Active Directory (AAD). When a new customer signs up, their AAD tenant needs to be able to authenticate users against the application. The application should dynamically discover the necessary AAD endpoints for each customer's tenant. Which Azure AD authentication approach is most suitable for this scenario?
- AGuest user invitations (B2B)
- BSingle-tenant application registration
- CAAD B2C for consumer identities
- DMulti-tenant application registration with common endpoint
Show answer & explanationAnswer & explanation
Correct answer: D. Multi-tenant application registration with common endpoint
Registering the application as multi-tenant in Azure AD and using the common endpoint (e.g., `https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration`) allows the application to dynamically discover the authentication endpoints for any Azure AD tenant. This enables users from different customer tenants to sign in without requiring separate registrations per tenant.
Why the other options are wrong
- A. Guest user invitations (B2B) are for collaborating with external users in your own tenant, not for allowing external tenants to use your application as a SaaS offering.
- B. Single-tenant application registration restricts authentication to users within a specific AAD tenant, which is not suitable for a multi-tenant SaaS application.
- C. AAD B2C is designed for consumer identities (e.g., social logins, local accounts) for customer-facing applications, not for enterprise-to-enterprise (Azure AD) multi-tenancy.
Azure AD Multi-tenant Application
An application registered in Azure AD that can accept sign-ins from users in any Azure AD tenant, enabling SaaS scenarios.
- Uses the `/organizations` or `/common` endpoint for authentication requests.
- Requires administrator consent in each customer's tenant for the application to access their data.
- Allows dynamic discovery of tenant-specific endpoints via OpenID Connect metadata.
Memory trick: Many tenants, one common door for authentication.