An App Service web app (App1) is registered as a single-tenant Azure AD application and currently accepts sign-ins from contoso.com users only. What configuration change should you recommend to permit users from fabrikam.com to sign in to App1?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Supported account types in the application registration and update the sign-in endpoint..
Why this is the answer
To allow users from fabrikam.com to sign in, you must change the application's "Supported account types" in its Azure AD application registration. Currently, it's set to "Accounts in this organizational directory only (single tenant)," which restricts access to contoso.com. Changing this to "Accounts in any organizational directory (Multi-tenant)" or "Accounts in any organizational directory (Any Azure AD directory - Multi-tenant) and personal Microsoft accounts" will enable sign-ins from fabrikam.com. You will also need to update the sign-in endpoint in App1 to reflect this multi-tenant configuration. The Azure AD provisioning service is for synchronizing user identities to applications, not for configuring sign-in tenants. Azure AD pass-through authentication is an identity authentication method for on-premises AD users, not for managing multi-tenant access. Azure AD Join is for joining devices to Azure AD, not for configuring application sign-in behavior.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed