AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Microsoft Entra ID to manage identities for 5,000 employees. You plan to implement Microsoft Entra ID Governance to automate the user provisioning lifecycle for a third-party SaaS application. The application supports SCIM 2.0. You need to ensure that user accounts are automatically created, updated, and disabled in the application based on changes in Entra ID. What should you do?
⚠ Common exam trap
It's easy for candidates to confuse the purpose of Application Proxy (remote access) or B2B collaboration (external identities) with provisioning automation, or assume that a custom Graph API solution is necessary when the built-in SCIM provisioning service is the correct, managed approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure automatic provisioning in Microsoft Entra ID using the SCIM endpoint
Microsoft Entra ID's automatic provisioning feature natively supports SCIM 2.0 endpoints, enabling automated creation, update, and deactivation of user accounts in third-party SaaS applications based on changes in Entra ID. This eliminates the need for custom code and provides a managed, scalable solution for the user provisioning lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Graph API to write a custom provisioning solution
Why it's wrong here
Using Microsoft Graph API to write a custom provisioning solution would require you to build, test, host, and maintain a custom service to handle user sync. This is unnecessary because Microsoft Entra ID natively supports SCIM-based automatic provisioning for applications that expose a SCIM endpoint, including incremental updates, retry logic, and logging. A custom Graph integration would also need to implement handling for idempotency and conflict resolution, which are already built into the provisioning service.
- ✗
Configure Microsoft Entra B2B collaboration for the application
Why it's wrong here
Microsoft Entra B2B collaboration is designed for inviting external guest users from other organizations into your tenant for access to your applications and resources, not for creating or managing accounts inside a third-party SaaS application. It operates at the identity federation level between tenants, so it does not install or maintain any user records in the target application's own user store. Therefore, it cannot address the need to provision and synchronize user lifecycle events for an internal application user base.
- ✗
Publish the application using Microsoft Entra Application Proxy
Why it's wrong here
Microsoft Entra Application Proxy acts as a reverse proxy that provides remote access to on-premises web applications, applying pre-authentication and conditional access policies. It does not communicate with or mutate the user directory of an external SaaS application, and there is no mechanism for it to create or update user records. As such, it is entirely unrelated to identity lifecycle provisioning, which is a distinct workload handled by the provisioning service.
- ✓
Configure automatic provisioning in Microsoft Entra ID using the SCIM endpoint
Why this is correct
Configuring automatic provisioning in Microsoft Entra ID with the application's SCIM endpoint is the correct approach because SCIM is a standardized, cloud-scale protocol for automating user lifecycle management. Microsoft Entra ID will act as the SCIM client and call the app's SCIM 2.0 API to create, update, and deactivate users and groups in sync with changes in your identity source. This is a built-in feature, eliminating custom code and providing attribute mapping, scoping filters, and synchronization logs out of the box.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.