An application used by 6,000 users validates vacation requests and currently maintains its own username/password credential store. The application does not support external identity providers. You plan to enable single sign-on (SSO) by registering the application in Azure Active Directory. Which SSO method is appropriate given the application's constraints?
Choose an answer
Tap an option to check your answer.
Correct answer: Password-based.
Why this is the answer
Password-based single sign-on (SSO) is the appropriate method because the application maintains its own username/password credential store and does not support external identity providers like SAML or OpenID Connect. Password-based SSO allows Azure AD to securely store the application's credentials and automatically "replay" them to the application on behalf of the user, providing an SSO experience without requiring modifications to the legacy application. Header-based SSO is used for applications that accept identity information in HTTP headers, which is not stated as a capability here. SAML (Security Assertion Markup Language) and OpenID Connect are modern authentication protocols that require the application to be explicitly designed to support them, which this application does not.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed