Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company plans to deploy a new application to Azure. The application will be used by external partners. You need to design an identity solution that allows partners to authenticate using their own corporate credentials while ensuring that the application can enforce conditional access policies based on partner device compliance. What should you include in the design?

⚠ Common exam trap

Many exam-takers confuse Microsoft Entra B2C (for customers) with Microsoft Entra B2B (for partners), leading them to choose Option C, which cannot enforce conditional access policies based on partner device compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra B2B collaboration and enable conditional access policies for guest users.

Microsoft Entra B2B collaboration allows you to invite external partners as guest users who can authenticate with their own corporate credentials. You can then enforce conditional access policies, including device compliance checks, on these guest users by targeting the policy to the 'Guest' user type or specific external users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Federate your Microsoft Entra tenant with each partner's on-premises Active Directory.

    Why it's wrong here

    Federating your Microsoft Entra tenant directly with each partner's on-premises Active Directory is not a practical B2B pattern. It would require establishing an outbound federation trust (for example, AD FS) with every partner, which is complex and doesn't bring partner-owned devices into your tenant's management plane. Because partner devices remain enrolled in their own identity system, your Intune device compliance state cannot be evaluated, so Conditional Access cannot enforce a compliant-device requirement based on your policies.

  • ✗

    Create guest user accounts in your Microsoft Entra tenant and assign them application roles.

    Why it's wrong here

    Creating guest user accounts and assigning application roles performs authorization but omits the access-control layer needed for device compliance. B2B guest users can use their corporate credentials when you invite them, but unless you explicitly configure a Conditional Access policy that targets guest users and requires compliant devices, the default policies may not evaluate device health. Simply having a guest account and a role does not restrict access to managed, compliant devices.

  • ✗

    Configure Microsoft Entra B2C and federate with partner identity providers.

    Why it's wrong here

    Microsoft Entra B2C is a customer identity and access management (CIAM) service designed for consumer-facing applications with identity providers like Google, Facebook, or arbitrary social accounts. While you can federate with any OIDC/SAML IdP, B2C does not provide the same enterprise Conditional Access device-compliance evaluation that B2B collaboration does, and it isn't intended to give employees or partners of another organization a seamless work-account experience. Partner-managed devices would not be subject to your Intune compliance policies in B2C.

  • ✓

    Configure Microsoft Entra B2B collaboration and enable conditional access policies for guest users.

    Why this is correct

    Configuring Microsoft Entra B2B collaboration lets partners access the application using their own corporate identities, avoiding separate username/passwords. When you also enable Conditional Access policies that target guest users, you can require device compliance as an access condition, so only partner devices that are compliant with your (or their) Intune policies are granted access. This is the only option that combines external identity federation with the enforcement of device compliance for external users.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.