Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company plans to deploy a new SaaS application that will be used by employees and external users. The application requires single sign-on (SSO) and must support conditional access policies that enforce MFA for external users. Additionally, the application must be able to read user profile attributes from Microsoft Entra ID. You need to design an identity solution that meets these requirements. What should you include in the design?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Entra application proxy (for on-premises apps) or Entra B2C (for customer identities) with the correct solution for a SaaS app requiring employee and external user access with conditional access and Graph API reads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Register the application in Microsoft Entra ID (App Registration) and configure it to use OpenID Connect for authentication; apply conditional access policies to the app.

Registering the application in Microsoft Entra ID (App Registration) and configuring OpenID Connect (OIDC) enables SSO and allows the application to read user profile attributes via the Microsoft Graph API. Conditional access policies can be applied directly to the enterprise app in Entra ID to enforce MFA for external users, meeting all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Register the application in Microsoft Entra ID (App Registration) and configure it to use OpenID Connect for authentication; apply conditional access policies to the app.

    Why this is correct

    Registering the SaaS app as an App Registration in Microsoft Entra ID and using OpenID Connect (OIDC) is the correct approach because OIDC is the modern, standards-based authentication protocol that Microsoft Entra ID fully supports for SSO. The app registration generates service principles, enabling Entra ID to issue ID and access tokens, which the SaaS app can validate. OIDC also exposes the application to conditional access policies in the same tenant, allowing you to enforce MFA, device compliance, and sign-in risk controls. Additionally, the Microsoft Graph API can be consented to read user profile data seamlessly, a capability not available through the alternatives.

  • ✗

    Use Microsoft Entra application proxy to publish the SaaS app and configure pre-authentication with Entra ID.

    Why it's wrong here

    Microsoft Entra application proxy is designed specifically to publish on-premises web applications that are not already internet-facing, not for externally hosted SaaS applications. It requires installing Application Proxy Connectors on your internal network to securely route traffic from Entra ID to the on-premises app. For a SaaS app, there is no internal connector or private endpoint to reach, and the service is already publicly accessible. Pre-authentication with Entra ID via Application Proxy only applies to the proxy-published app, and it cannot enforce conditional access on a third-party SaaS app that is not routed through the proxy, making this option fundamentally incompatible.

  • ✗

    Use Microsoft Entra Domain Services to authenticate the application via LDAP.

    Why it's wrong here

    Microsoft Entra Domain Services (Microsoft Entra Domain Services) provides legacy managed domain services such as LDAP, Kerberos, and NTLM authentication, primarily for lifting and shifting on-premises workloads to Azure. LDAP is a directory access protocol, not an identity authentication protocol for modern cloud SaaS applications, and it does not support SSO, OIDC, or SAML flows. Modern SaaS apps expect to authenticate via federation standards like OIDC or SAML, and using LDAP would require exposing a directory service, which is a security risk. Even if LDAP could work, Entra Domain Services does not allow applying conditional access policies, which are core to your zero-trust requirements.

  • ✗

    Register the application in Microsoft Entra B2C and configure federation with your Entra ID tenant.

    Why it's wrong here

    Azure AD B2C is an identity service designed for customer-facing applications, allowing you to manage external consumer identities with customizable sign-up and sign-in flows. While B2C can federate with your Entra ID tenant, doing so creates a separate identity boundary that is not the same as your corporate directory. Enterprise conditional access policies—such as device-based access or risk policies—are applied to applications in your primary Entra ID tenant, not to B2C-federated apps, so this approach cannot meet the SSO and conditional access requirements. For employee access to a SaaS app, you must register the app in the same Entra ID tenant used for your employees, not in a B2C tenant, making this option architecturally wrong.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.