Your Azure AD tenant is synchronized with an on-premises Active Directory. A custom line-of-business application requires SAML single sign-on and must enforce multi-factor authentication when users sign in from an unknown location. Which two Azure features should you include to meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Azure AD enterprise applications, Conditional Access policies.
Why this is the answer
Azure AD enterprise applications allow you to integrate custom line-of-business applications with Azure AD for single sign-on (SSO) using protocols like SAML. This enables users to access the application with their existing Azure AD credentials. Conditional Access policies are essential for enforcing multi-factor authentication (MFA) based on specific conditions, such as an unknown location. You can configure a policy that targets the specific enterprise application and requires MFA when the sign-in risk (determined by Azure AD Identity Protection) is medium or high, or when the user is signing in from an unapproved location. Azure AD Privileged Identity Management (PIM) is for managing, controlling, and monitoring access to important resources, not for enforcing MFA on standard user sign-ins to line-of-business apps. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, but it doesn't handle identity or MFA enforcement. Azure AD Identity Protection detects potential vulnerabilities affecting your organization’s identities and provides risk-based policies, but it doesn't directly configure the application integration or the MFA enforcement itself; it feeds into Conditional Access policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed