Sub1 contains an Azure App Service web app named App1. App1 is configured for single-tenant Azure AD authentication and currently accepts sign-ins from users in contoso.com. You need to enable users from the fabrikam.com tenant to authenticate to App1. Which solution should you recommend to govern and enable external user access?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Azure AD entitlement management to govern and invite external users and grant them access..
Why this is the answer
Azure AD entitlement management is the correct solution because it allows you to manage identity and access lifecycle at scale by automating access requests, approvals, and reviews for external users. It enables you to invite users from fabrikam.com as guest users and grant them access to App1, while providing governance over their access. Configuring a Conditional Access policy would control how users sign in, but not who can sign in from an external tenant. Azure AD provisioning service is used for synchronizing identities between identity stores, not for granting external user access to an application. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on enabling or governing external user access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed