AZ-305 Design infrastructure solutions Practice Question
You are designing an authentication solution for a mobile application that uses Azure AD B2C (now Microsoft Entra External ID). The application needs to support social logins (Google, Facebook) and also allow users to sign in with their corporate Microsoft Entra ID accounts. Which of the following identity providers should you configure?
⚠ Common exam trap
Many candidates assume Microsoft Entra ID can directly federate with social identity providers, but in reality, social identity provider support requires Microsoft Entra External ID (Azure AD B2C) as the authentication platform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Google and Facebook as social identity providers, and add Microsoft Entra ID as a custom identity provider.
Microsoft Entra External ID (Azure AD B2C) supports social identity providers like Google and Facebook natively, and also allows you to add Microsoft Entra ID as a custom (OpenID Connect) identity provider. This enables corporate users to sign in with their existing Entra ID accounts while external users can use social logins, all within a single B2C tenant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Entra ID as the only identity provider and configure federation with Google and Facebook.
Why it's wrong here
Microsoft Entra ID (formerly Azure AD) is an enterprise identity service that supports federation with other enterprise IdPs via SAML/WS-Fed, but it does not natively integrate consumer social identity providers such as Google or Facebook. Even if you configure external federation policies, Entra ID's standard tenant model is designed for organizational accounts, not for consumer-facing sign-up and social login scenarios. Therefore, using Entra ID as the only identity provider would not allow the mobile app to authenticate users via Google or Facebook identities.
- ✗
Use Microsoft Entra External ID with Google and Facebook only, and advise corporate users to create local accounts.
Why it's wrong here
Microsoft Entra External ID (the evolution of Azure AD B2C) does support Google and Facebook as social identity providers, but limiting the solution to those two and forcing corporate users to create local accounts is poor design. Corporate employees should authenticate with their existing corporate Microsoft Entra ID credentials to maintain single sign-on, centralized lifecycle management, and security policies such as MFA and conditional access. Creating local accounts for corporate users would introduce password management overhead and duplication of identities, and it would bypass the enterprise tenant's governance controls.
- ✓
Configure Google and Facebook as social identity providers, and add Microsoft Entra ID as a custom identity provider.
Why this is correct
Microsoft Entra External ID is specifically built for customer-facing apps and supports multiple identity providers within a single tenant. Google and Facebook can be configured as built-in social identity providers for consumer users, while Microsoft Entra ID can be added as a custom identity provider using OpenID Connect (OIDC) or SAML federation, enabling corporate users to sign in with their existing work accounts. This hybrid configuration cleanly handles both consumer social logins and enterprise corporate identities without requiring local account creation or separate authentication flows.
- ✗
Configure only Google and Facebook as identity providers, and use Microsoft account for corporate users.
Why it's wrong here
Microsoft account (personal outlook.com, live.com, or xbox.com accounts) is a consumer identity service and is not equivalent to a corporate Microsoft Entra ID account. If corporate users authenticate with personal Microsoft accounts, they would bypass organization-specific security controls like conditional access, device compliance, and enterprise MFA policies that are enforced on their work tenant. Configuring only Google and Facebook as identity providers leaves no path for corporate identities, so employees would be forced to use unsupported personal credentials, making the solution incomplete for an enterprise workforce.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.