App1 is a single-tenant Azure AD application that only allows contoso.com users to sign in. Which action will enable users in the fabrikam.com tenant to authenticate to App1?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Supported account types in the application registration and update the sign-in endpoint..
Why this is the answer
The correct answer is to configure Supported account types in the application registration and update the sign-in endpoint. App1 is currently configured as a single-tenant application, meaning it only trusts users from its home tenant (contoso.com). To allow users from fabrikam.com, you must change the "Supported account types" setting in the application registration to a multi-tenant option (e.g., "Accounts in any organizational directory (Any Azure AD directory - Multitenant)"). This makes the application discoverable by other tenants. Additionally, the sign-in endpoint must be updated to the common endpoint (e.g., https://login.microsoftonline.com/common/oauth2/v2.0/authorize) to allow users from any Azure AD tenant to authenticate. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on enabling cross-tenant authentication. Azure AD Privileged Identity Management (PIM) manages just-in-time access for privileged roles within a tenant, not cross-tenant application access. Conditional Access policies enforce access controls based on conditions but do not inherently enable an application to accept users from other tenants if it's configured as single-tenant.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed