Contoso has an Azure AD tenant and an Azure subscription. Fabrikam is a partner organization with its own on-premises Active Directory and Microsoft 365 tenant. Ten developers from Fabrikam need Contributor access to a resource group in Contoso's subscription and must use their existing Fabrikam credentials. What should Contoso do to enable this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create guest accounts for the Fabrikam developers in Contoso's Azure AD tenant.
Why this is the answer
Creating guest accounts for the Fabrikam developers in Contoso's Azure AD tenant is the correct solution. Azure AD B2B collaboration allows external users (guests) from other Azure AD tenants or even consumer email accounts to access resources in your tenant using their existing credentials. This avoids the overhead of creating new accounts for them. Creating cloud-only user accounts in Contoso's tenant would require developers to manage new credentials, defeating the purpose of using their existing Fabrikam credentials. Configuring a forest trust is irrelevant as Fabrikam's users are in a Microsoft 365 tenant, not just an on-premises AD, and Azure AD B2B is the cloud-native solution. Configuring an organization relationship between Microsoft 365 tenants is primarily for calendaring and free/busy information exchange, not for granting Azure resource access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed