AZ-305 exam dumps

AZ-305 practice question 20 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 20

Single answer

You are designing a new public-facing web application for an online retail company. Internal employees will sign in using the company’s Azure Active Directory tenant, but external customers must use social logins (e.g., Google, Facebook) or create accounts using their personal email. Management wants to minimize administrative overhead, provide a secure authentication experience, and offer a customizable user journey for external customers. Which authentication approach should you recommend?

  1. A

    Configure Azure AD B2C using built-in user flows for external customers and maintain corporate accounts in the company’s Azure AD tenant

  2. B

    Enable Azure AD Domain Services and directly manage all external credentials within on-premises Active Directory

  3. C

    Use Azure AD B2B (guest accounts) for all external customers and wrap them in conditional access policies

  4. D

    Authenticate external users by creating managed identities for each user and assigning them app roles

Show answer and explanation

Correct answer: A

Explanation

Azure Active Directory B2C is purpose-built to manage external or customer identities, support social identity providers out of the box, and provide flexible user experiences through customizable flows. For reference, consult Microsoft’s documentation on Azure AD B2C: https://learn.microsoft.com/azure/active-directory-b2c/overview.

  • A. Correct.

    Correct. Azure AD B2C with built-in user flows is designed for customer or public-user scenarios and supports social logins, custom email accounts, and customizable user journeys. Internal employees can still authenticate via the existing corporate Azure AD tenant while external users are handled in B2C.

  • B. Incorrect.

    Incorrect. Azure AD Domain Services extends on-premises functionality to Azure but is not intended to handle large sets of public-facing users or social logins. It would be costly and complex to manage external credentials in this manner.

  • C. Incorrect.

    Incorrect. Azure AD B2B is designed for partner or vendor collaborations using guest accounts, not for large-scale public-facing customers. It would become unwieldy to manage thousands of external customers in this fashion.

  • D. Incorrect.

    Incorrect. Managed identities in Azure are intended for services and applications, not individual external users. They do not provide a user-facing login experience or social identity federation.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam