You are onboarding a new SAML-based SaaS application (AppX) that will use your AD FS farm for authentication. Tokens must include the user’s email address as the Name ID and a custom claim sourced from the employeeType AD attribute. Users must be able to access AppX from outside the corporate network. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a relying party trust for AppX and configure issuance transform rules to send E-Mail Address as Name ID and employeeType as a custom claim., Configure the Web Application Proxy as an AD FS proxy with a public certificate for the federation service name so AD FS endpoints are published externally..
Why this is the answer
To integrate a SAML-based SaaS application with AD FS, you must first establish a relying party trust. This trust defines how AD FS interacts with the application. Issuance transform rules within this trust are essential for mapping Active Directory attributes (like E-Mail Address and employeeType) to the specific claims (Name ID and a custom claim) required by the application. To allow external access, the AD FS endpoints must be published externally, which is achieved by configuring the Web Application Proxy (WAP) as an AD FS proxy. The WAP uses a public certificate for the federation service name to securely expose AD FS to the internet. Adding a new claims provider trust is incorrect because AppX is a relying party, not a claims provider. Publishing AppX through WAP with Azure AD preauthentication is incorrect because the scenario specifies AD FS for authentication, not Azure AD. Enabling device registration is unnecessary as the question only requires user authentication and specific claims, not device-based access policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed