An App Service web app (App1) in subscription Sub1 uses Azure AD single-tenant authentication and currently accepts users from contoso.com. You must enable users from fabrikam.com to authenticate to App1. Which of the following should you recommend to manage these external users?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Azure AD entitlement management to govern external users.
Why this is the answer
Azure AD entitlement management is the correct solution because it allows organizations to manage identity and access lifecycle at scale by automating access requests, approvals, and reviews for internal and external users. This is ideal for granting users from fabrikam.com access to App1, as it provides a structured way to onboard and manage their access. Configuring the Azure AD provisioning service is incorrect because it's primarily used for automating identity lifecycle management between Azure AD and other applications, not for managing external user access to a single-tenant application. Azure AD Privileged Identity Management (PIM) is incorrect because it focuses on managing, controlling, and monitoring access to important resources within an organization, particularly for privileged roles, not for general external user access. Azure AD Identity Protection is incorrect as it's designed to detect potential vulnerabilities affecting identities, configure policies to respond to suspicious actions, and take action to resolve them, which is a security feature, not an access management solution for external users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed