AZ-305 exam dumps

AZ-305 practice question 19 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 19

Select 2

You are designing an authentication and authorization solution for Contoso, which uses Azure Active Directory (Azure AD) for employee authentication. Contoso wants to extend application access to external partner users from multiple Azure AD tenants, while ensuring only internal employees have privileged role assignments. The solution must also simplify administration for external partner accounts. Which two approaches should you recommend to achieve these requirements?

  1. A

    Implement Azure AD B2B collaboration, inviting external partners as guest users and assigning them to relevant application roles.

  2. B

    Enable pass-through authentication for external users to Contoso’s on-premises Active Directory domain controllers.

  3. C

    Configure each partner's Azure AD as a direct identity federation with Contoso's Azure AD tenant.

  4. D

    Use Azure AD Privileged Identity Management (PIM) to manage privileged role assignments and limit them to internal employee accounts.

Show answer and explanation

Correct answers: A, D

Explanation

Azure AD B2B collaboration (Option 1) is the recommended method for granting access to external partner tenants, streamlining the management of guest users without the overhead of multiple federations. Azure AD Privileged Identity Management (Option 4) is essential to protect and control privileged operations, keeping them limited to internal users. This setup aligns with Microsoft best practices for extending secure access beyond organizational boundaries. Reference: https://learn.microsoft.com/azure/active-directory/external-identities and https://learn.microsoft.com/azure/active-directory/privileged-identity-management.

  • A. Correct.

    Option 1 is correct. Azure AD business-to-business (B2B) collaboration simplifies external user management by allowing you to invite partner tenant users as guests and securely assign them permissions. This approach is the recommended best practice for extending application access outside the organization.

  • B. Incorrect.

    Option 2 is incorrect. Pass-through authentication primarily supports internal users by validating credentials against on-premises domain controllers. It doesn’t simplify onboarding multiple external tenants and is not intended as a mechanism for external partner access.

  • C. Incorrect.

    Option 3 is incorrect. Direct federation with every partner can be cumbersome to maintain for multiple Azure AD tenants. Azure AD B2B collaboration is a more streamlined solution for inviting guest users from external organizations without complex federation setups.

  • D. Correct.

    Option 4 is correct. Azure AD Privileged Identity Management (PIM) helps ensure that only authorized, typically internal, users receive elevated privileges, such as administrator or privileged roles. By combining PIM with restricted role assignments, you can effectively limit privileged roles to internal employees.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam