220-1101 Question 48
Single answerCorporate applicationsA technician is preparing 25 new Windows laptops for employees in a company that uses Microsoft 365 for email, cloud storage, and collaboration. Management wants users to sign in once with their corporate account and automatically access Outlook, Teams, OneDrive, and SharePoint resources without separate local account setup. Which corporate application service should the technician configure to best meet this requirement?
- A
Active Directory Domain Services (AD DS) on an on-premises domain controller only
- B
Microsoft 365 admin center licensing without identity configuration
- C
Azure Active Directory (Azure AD), now Microsoft Entra ID, for organizational sign-in
- D
A local administrator account with saved credentials for each Microsoft 365 app
Show answer and explanation
Correct answer: C
Explanation
In a Microsoft 365 environment, the core corporate application identity service is Azure AD, now Microsoft Entra ID. It is used to authenticate users to cloud-based corporate applications such as Outlook, Teams, OneDrive, and SharePoint. This question tests practical understanding of how corporate application access is managed in a modern business environment. While on-premises AD DS may still exist in some organizations, Microsoft 365 relies on Entra ID for cloud authentication. Licensing is also required, but licensing alone is not enough without identity configuration. Microsoft documentation for Microsoft 365 and Entra ID describes Entra ID as the identity platform for Microsoft cloud services and supports organizational sign-in and single sign-on for users accessing corporate applications.
- A. Incorrect.
This is incorrect because an on-premises AD DS domain by itself does not provide the cloud identity and authentication experience needed for direct sign-in to Microsoft 365 services on modern devices. AD DS can be part of a hybrid environment, but by itself it does not satisfy the requirement for seamless access to cloud applications like Teams, OneDrive, and SharePoint.
- B. Incorrect.
This is incorrect because assigning licenses in the Microsoft 365 admin center is necessary for service access, but licensing alone does not provide identity, authentication, or single sign-on. Users still need an identity platform to authenticate to Microsoft 365 resources.
- C. Correct.
This is correct because Azure AD, now called Microsoft Entra ID, provides the organizational identity service used for Microsoft 365 sign-in. Joining or registering devices appropriately and having users authenticate with their corporate accounts enables access to Outlook, Teams, OneDrive, and SharePoint using the same organizational identity, which matches the requirement for centralized corporate application access.
- D. Incorrect.
This is incorrect because using a local administrator account with stored credentials is not an appropriate enterprise solution for user productivity applications. It creates security and management problems, does not provide proper single sign-on, and does not align with best practices for corporate identity management.