AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A SaaS application must allow external partner users to sign in with their own organization credentials while the company controls application access. What should be used?
⚠ Common exam trap
Watch out — candidates often confuse Azure DNS private zones (a networking feature) with identity federation, or assume that creating local accounts or sharing accounts is acceptable for external collaboration, ignoring the security and manageability requirements of the scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra External ID/B2B collaboration with Conditional Access
Microsoft Entra External ID (formerly Azure AD B2B) enables external partner users to sign in using their own organization's credentials (their existing Microsoft Entra ID or Microsoft account) while the company retains control over application access. By combining B2B collaboration with Conditional Access policies, the company can enforce MFA, device compliance, or location-based controls on guest users without managing their identities or passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create local cloud-only accounts for every partner user
Why it's wrong here
Creating a local cloud-only account for every partner user forces the resource tenant to own the full identity lifecycle—provisioning, credentials, and revocation—independent of the partner's HR or identity processes. Each external user must then memorize and MFA against a separate password, while the organization must manually monitor and disable accounts upon employee departure. This approach ignores Microsoft Entra's external identity model, incurs significant administrative overhead, and violates the principle of least privilege.
- ✗
Share one account per partner company
Why it's wrong here
Sharing a single account per partner company eliminates user-level traceability: every action—data access, changes, or downloads—maps only to the company, never to an individual, breaking audit and forensics requirements. It also leaves no way to enforce per-user Conditional Access or revoke just one employee's access without locking out the whole partner organization. A shared password represents a standing credential that can spread beyond the intended group, and it thwarts any per-user MFA or sign-in risk evaluation.
- ✗
Use Azure DNS private zones
Why it's wrong here
Azure DNS private zones are purely a DNS resolution service—they map names to IP addresses inside selected virtual networks and have no identity, token, or session logic. They cannot challenge a user's credentials, issue a security token, or enforce authentication policies, so they are completely orthogonal to sign-in traffic. While a private zone might resolve the SaaS application's hostname, the actual HTTP authentication flow would still need an identity provider like Microsoft Entra ID.
- ✓
Microsoft Entra External ID/B2B collaboration with Conditional Access
Why this is correct
Microsoft Entra External ID/B2B collaboration is the correct architecture because partner users authenticate against their own identity provider—be it Microsoft Entra, Google, or a SAML/WS-Fed IdP—while the resource tenant issues a token and applies its own access controls. Conditional Access policies then run at sign-in for each guest, enabling MFA, session risk, and device compliance checks without suddenly locking out valid partners. This design preserves user-level auditability with access reviews and entitlement management, so a partner user's access can be individually granted and revoked. It is the Azure-native way to meet the external-partner expectation, unlike the other options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.