AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They have a SaaS application that supports SCIM (System for Cross-domain Identity Management). The company wants to automatically create, update, and deactivate user accounts in the SaaS application whenever changes occur in Microsoft Entra ID. They do not want to use custom scripts. Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
Many candidates confuse Microsoft Entra ID Connect (which syncs from on-premises AD) with cloud-to-SaaS provisioning, but the question explicitly targets a cloud-only SaaS application with no on-premises dependency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Provisioning (Automatic User Provisioning)
Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct feature because it natively supports the SCIM (System for Cross-domain Identity Management) protocol to automate the creation, update, and deactivation of user accounts in SaaS applications. This eliminates the need for custom scripts by synchronizing identity changes from Microsoft Entra ID to the target application in near real-time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Application Proxy
Why it's wrong here
Microsoft Entra ID Application Proxy is an HTTP reverse proxy that publishes internal web applications to authenticated external users via the Entra ID application portal and pre-authentication policies. It does not manage user account lifecycle in SaaS applications; it only handles secure remote access to the published apps. Provisioning is a distinct operation that requires SCIM-based endpoints on the target application, which Application Proxy does not provide.
- ✓
Microsoft Entra ID Provisioning (Automatic User Provisioning)
Why this is correct
Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct answer because it enables the Entra ID provisioning service to automatically create, update, and deactivate user accounts in any SaaS application that implements a System for Cross-domain Identity Management (SCIM) 2.0 endpoint, based on user and group assignments in Entra ID. This service continuously remediates identity matches against the tenant directory, ensuring that attribute changes and role changes are propagated and that accounts are disabled when a user loses access. It is exactly the mechanism that automates identity lifecycle in SaaS apps, often replacing manual CSV-based administration.
- ✗
Microsoft Entra ID Connect
Why it's wrong here
Microsoft Entra ID Connect is a hybrid identity synchronization engine that copies on-premises Active Directory objects and password hashes into Microsoft Entra ID, enabling the same corporate credentials for cloud services. Its purpose is to populate the Entra ID directory, not to push identities directly into third-party SaaS applications. Connect has no awareness of a SaaS app's SCIM provisioning endpoint and cannot write user accounts to external identity stores, so it is not the tool for automating user provisioning into SaaS apps.
- ✗
Microsoft Entra ID B2B Collaboration
Why it's wrong here
Microsoft Entra ID B2B Collaboration is a feature for granting external partners or guests access to your organization's own applications by creating guest user objects in Entra ID and allowing them to sign in with their own identity providers or Microsoft account. After authentication, those users are not automatically created as accounts in third-party SaaS applications, since access is still at the Entra ID authorization layer. Automating account creation for external users to SaaS apps would also require a provisioning service; B2B alone does not perform lifecycle provisioning.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.