App1 in Sub1 is a single-tenant Azure AD application used by contoso.com users. You need to enable users from fabrikam.com to authenticate to App1 while governing external user access. Which solution should you recommend?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Azure AD entitlement management to govern external users..
Why this is the answer
Azure AD entitlement management allows you to manage identity and access lifecycle at scale by automating access requests, approvals, auditing, and expiration for internal and external users. This is the correct solution because it directly addresses the need to enable external users (fabrikam.com) to authenticate to App1 while providing governance over their access. Azure AD pass-through authentication is an authentication method for internal users and doesn't facilitate external user access. Azure AD Privileged Identity Management (PIM) is used for managing, controlling, and monitoring access to important resources within an organization, primarily for privileged roles, not for governing general external user access to an application. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on managing external user access provisioning and governance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed