Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A software development company is building a multi-tenant SaaS application that will be consumed by various customer organizations, each with their own Azure AD tenant. The application needs to authenticate users from these customer tenants and access basic user profile information (e.g., user's name, email). The company wants to ensure that the application can be easily onboarded by new customers without requiring manual configuration in each customer's tenant beyond user consent. Which type of application registration is required?

  1. AAzure AD B2C application registration
  2. BPersonal Microsoft account application registration
  3. CSingle-tenant application registration
  4. DMulti-tenant application registration
Show answer & explanation

Correct answer: D. Multi-tenant application registration

A multi-tenant application registration is designed for SaaS applications that need to authenticate users from multiple Azure AD tenants. This allows the application to be registered once in the developer's tenant and then be 'consented' to by users or administrators in other tenants, enabling seamless onboarding for customer organizations.

Why the other options are wrong

  • A. Azure AD B2C is for consumer-facing applications where customers sign up with social accounts or local accounts managed by B2C, not for business-to-business (B2B) SaaS with Azure AD tenants.
  • B. Personal Microsoft account application registrations are for consumer-facing applications that use Microsoft accounts (e.g., Outlook.com, Xbox), not Azure AD organizational accounts.
  • C. Single-tenant application registrations are for applications used only within the developer's Azure AD tenant.

Multi-tenant Application Registration

An Azure AD application registration configured to allow users from any Azure AD tenant to sign in. This is typically used for Software-as-a-Service (SaaS) applications that serve multiple customer organizations.

  • Allows authentication from multiple Azure AD tenants.
  • Registered once in the developer's tenant.
  • Requires user or admin consent in other tenants to access data.

Memory trick: MULTI for MANY customers, ONE registration.

More Implement and manage workload identities questions