Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesEasy
A company is integrating a new third-party Software-as-a-Service (SaaS) application into its Azure AD tenant. This application requires users to sign in using their Azure AD credentials. The company wants to ensure that all user access to this application is managed centrally through Azure AD, including single sign-on (SSO) and conditional access policies. Which Azure AD object type should be used to represent this third-party application in the tenant?
- AAzure AD Application Registration
- BAzure AD Enterprise Application
- CAzure AD Managed Identity
- DAzure AD Service Principal
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Enterprise Application
An Azure AD Enterprise Application (also known as a Service Principal in some contexts) is used to represent an application from a third-party vendor within your Azure AD tenant. It enables features like SSO, conditional access, and user provisioning for pre-integrated or custom SaaS applications.
Why the other options are wrong
- A. An Application Registration defines an application's identity and permissions, typically when you are developing the application yourself or integrating a custom app. For pre-built SaaS, Enterprise Application is preferred.
- C. A Managed Identity is for Azure resources to authenticate to other Azure services, not for users to sign into third-party SaaS applications.
- D. A Service Principal is the underlying object that represents an application in a specific tenant. While technically correct, 'Enterprise Application' is the portal-facing term for managing third-party SaaS integrations.
Azure AD Enterprise Application
An instance of an application that is available in your Azure AD tenant. It enables centralized management of access, single sign-on (SSO), and conditional access for pre-integrated SaaS applications or custom applications.
- Often created when integrating third-party SaaS apps.
- Enables SSO, conditional access, and user provisioning.
- Represents a service principal in the tenant.
Memory trick: ENTERPRISE apps are for EXTERNAL use.