1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 35 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 35

Select 2

Your organization is expanding its multi-cloud strategy and wants to allow employees to log in to Oracle Cloud Infrastructure (OCI) using their corporate credentials from Microsoft Azure Active Directory (Azure AD). You are tasked with configuring federation between your OCI Identity Domain and Azure AD. Which TWO of the following steps are required to set up the federation securely and grant the correct privileges to Azure AD users in OCI?

  1. A

    Export the Azure AD SAML metadata and import it into your OCI Identity Domain to establish the trust relationship.

  2. B

    Enable the �Multicloud Federations� feature within the OCI console and provide your Azure AD tenant ID.

  3. C

    Configure an OCI IAM policy granting the new identity provider operator-level permissions for all resources in the tenancy.

  4. D

    Map Azure AD groups to corresponding OCI Identity Domain groups to manage user authorizations consistently.

  5. E

    Use Kerberos authentication on the Azure AD side and enable Kerberos pass-through in the OCI Identity Domain configuration.

Show answer and explanation

Correct answers: A, D

Explanation

When federating an external identity provider such as Azure AD with OCI, you must import SAML metadata from Azure AD into the OCI Identity Domain to establish a trust relationship. Then, map IdP groups to OCI groups to manage user privileges in OCI. Refer to Oracle documentation on 'Configuring Federation Between Oracle Cloud and Microsoft Azure Active Directory' for detailed, step-by-step instructions on how to secure and properly configure SAML federation.

  • A. Correct.

    Option 1 is correct. You must export the SAML metadata from Azure AD and import it into the OCI Identity Domain. This process establishes the trust relationship between Azure AD (as the identity provider) and OCI (as the service provider).

  • B. Incorrect.

    Option 2 is incorrect. There is no dedicated 'Multicloud Federations' toggle in the OCI console that you simply enable. Federation must be set up by importing SAML metadata and configuring identity provider settings, not by flipping a single switch.

  • C. Incorrect.

    Option 3 is incorrect. Granting the identity provider operator-level permissions for the entire tenancy is overly broad and not aligned with least-privilege practices. You should create policies and group mappings tailored to required access instead of giving unlimited privileges.

  • D. Correct.

    Option 4 is correct. Mapping Azure AD groups to OCI Identity Domain groups is essential for controlling authorization. After successful authentication via SAML, OCI needs to know which privileges to assign to federated users, which is handled through group mappings.

  • E. Incorrect.

    Option 5 is incorrect. Implementing Kerberos pass-through is not the standard mechanism for federating Azure AD with OCI. OCI relies on SAML-based claims, not Kerberos tickets, for federation.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam