AZ-305 exam dumps

AZ-305 practice question 17 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 17

Single answer

You have an Azure AD tenant that hosts a line-of-business application running on Azure App Service. Your employees use their Azure AD credentials to sign in. Now you need to give external partner organizations secure access to the same application while minimizing management overhead. Which authentication approach should you implement for those partner users?

  1. A

    Invite partner users as guest accounts within your Azure AD tenant using Azure AD B2B collaboration

  2. B

    Configure an on-premises AD FS server to federate login requests for all external partners

  3. C

    Set up an Azure AD B2C tenant specifically for partner identities

  4. D

    Create local accounts in the application for each partner user

Show answer and explanation

Correct answer: A

Explanation

Azure AD B2B is a recommended method for granting external partner access to an existing Azure AD–secured application. By inviting partner user accounts as guests, you leverage existing enterprise security and identity management while providing a straightforward sign-in experience for external organizations. Refer to Microsoft documentation on 'Azure AD B2B collaboration' for more details on best practices and implementation steps.

  • A. Correct.

    Correct. Azure AD B2B collaboration allows you to invite external partner users as guests in your tenant. This approach leverages your existing Azure AD infrastructure, supports secure single sign-on, and simplifies administration for external users.

  • B. Incorrect.

    Incorrect. While AD FS can enable federation with external organizations, it introduces additional complexity and infrastructure overhead. Azure AD B2B is typically preferred for cloud-only scenarios, as it provides straightforward guest account management without requiring on-premises federation services.

  • C. Incorrect.

    Incorrect. Azure AD B2C is tailored for consumer-facing applications and social identity logins rather than business-to-business collaboration. It does not align as well with partner organizations already using their own enterprise identities.

  • D. Incorrect.

    Incorrect. Storing credentials locally within the application would bypass Azure AD’s security capabilities and create significant overhead for user provisioning, deprovisioning, and password management.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam