AZ-305 · Question 15 · Domain 1.4: Design identities and access for applications
A third-party SaaS application needs to read user profiles from your Microsoft Entra ID tenant using the Microsoft Graph API. The application is hosted outside of Azure (on AWS).
You need to design the authentication and authorization solution for this application. The solution must follow security best practices and avoid the use of shared passwords.
Which TWO actions should you perform? (Select TWO)
A third-party SaaS application needs to read user profiles from your Microsoft Entra ID tenant using the Microsoft Graph API. The application is hosted outside of Azure (on AWS).
You need to design the authentication and authorization solution for this application. The solution must follow security best practices and avoid the use of shared passwords.
Which TWO actions should you perform? (Select TWO)
Answer options:
Register an application in Microsoft Entra ID to create a Service Principal.
Configure certificate-based authentication for the application.
Enable a System-assigned managed identity for the application.
Generate a client secret with a 10-year expiration.
Configure Azure AD Application Proxy.
How to approach this question
Full Answer
Common mistakes
Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 1
55 questions · hints · full answers · grading
Expert