An App Service web app (App1) in subscription Sub1 is configured to use Azure AD as a single-tenant application; users in contoso.com can sign in. What should you recommend to allow users from the fabrikam.com tenant to authenticate to App1?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Supported account types in the application registration and update the sign-in endpoint..
Why this is the answer
To allow users from fabrikam.com to authenticate to App1, you need to modify the application registration. Changing the "Supported account types" to "Accounts in any organizational directory (Any Azure AD directory - Multitenant)" enables users from other Azure AD tenants to sign in. Additionally, updating the sign-in endpoint in your application to the common endpoint (e.g., https://login.microsoftonline.com/common/oauth2/v2.0/authorize) ensures that the authentication request is routed correctly across tenants. Azure AD join is for device management, not multi-tenant application access. Azure AD Identity Protection focuses on detecting and remediating identity-based risks. Conditional Access policies control access based on conditions but don't inherently enable multi-tenant authentication for an application configured as single-tenant.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed