Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A company is integrating a new custom-developed web application with Azure AD for single sign-on (SSO). The application requires specific user attributes, including an employee ID (which is stored as an extension attribute in Azure AD Connect) and the user's manager's email address, to be included in the ID token. Which Azure AD feature should be used to configure these additional attributes in the ID token?
- AAzure AD Custom Security Attributes
- BAzure AD Optional Claims
- CAzure AD Application Proxy
- DAzure AD Conditional Access policy
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Optional Claims
Azure AD Optional Claims allow you to configure which standard and extension attributes (including those synced via Azure AD Connect) are included in the tokens (ID tokens, access tokens) issued by Azure AD for an application, directly meeting the requirement.
Why the other options are wrong
- A. Custom Security Attributes are for defining and assigning custom attributes to Azure AD objects, not for including them in tokens for applications.
- C. Application Proxy provides secure remote access to on-premises web applications but does not customize token claims.
- D. Conditional Access policies enforce access controls (e.g., MFA, device compliance) but do not modify the claims within an ID token.
Azure AD Optional Claims
Azure AD Optional Claims allow you to modify the claims emitted in tokens for your applications, including adding standard claims, custom extension attributes, and specific user properties.
- Can add claims to ID tokens, access tokens, and SAML tokens.
- Supports standard claims (e.g., upn, email, given_name) and directory extension attributes.
- Configured per application registration in Azure AD.
Memory trick: Optional Claims: Offer Custom Info, On Linkage.