Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization uses Microsoft Entra ID. You need to allow external users to sign in using their own identity providers (e.g., Google, Facebook) to access a custom application. What should you configure?

⚠ Common exam trap

Many exam-takers confuse Microsoft Entra B2B collaboration (which is for business-to-business guest access using work/school accounts) with Microsoft Entra External ID (which is for consumer-facing social identity providers), leading them to incorrectly select B2B collaboration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra External ID

Microsoft Entra External ID (formerly Azure AD External Identities) is the correct solution because it is specifically designed to allow external users to authenticate using their own social identity providers (e.g., Google, Facebook) via OAuth 2.0 and OpenID Connect protocols. This configuration enables a custom application to accept sign-ins from these external identities without requiring them to have a Microsoft Entra ID account, using a dedicated external tenant or identity experience.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Connect

    Why it's wrong here

    Microsoft Entra Connect is a hybrid identity synchronization tool that replicates object and credential hashes from on-premises Active Directory to Microsoft Entra ID. It does not provide an identity provider interface for external users nor does it support social identity providers such as Google or Facebook. Its sole purpose is to enable single sign-on for existing enterprise internal users by syncing their on-premises attributes, so it cannot fulfill the requirement to allow external social IdP sign-in.

  • ✓

    Microsoft Entra External ID

    Why this is correct

    Microsoft Entra External ID, formerly Azure AD B2C, is a customer identity and access management (CIAM) service specifically built to handle external user authentication. It natively integrates with social identity providers like Google, Facebook, Apple, and Microsoft accounts via OIDC/OAuth2 protocols, and offers configurable user flows for registration, sign-in, and profile management. This makes it the correct solution when the requirement is to allow external identities to authenticate through social IdPs.

  • ✗

    Microsoft Entra B2B collaboration

    Why it's wrong here

    Microsoft Entra B2B collaboration is designed for business-to-business partner access, enabling guest users from other Microsoft Entra ID tenants or Microsoft accounts to access your applications. It does not include native support for social identity providers; while you could theoretically chain an external IdP through SAML/OIDC federation, that requires custom configuration and does not deliver the out-of-the-box social IdP experience like External ID. B2B collaboration is therefore not the appropriate choice for consumer-facing social sign-in scenarios.

  • ✗

    Microsoft Entra ID (tenant)

    Why it's wrong here

    A standard Microsoft Entra ID tenant is the identity provider for your organization's employees and internal applications, using organizational accounts managed within that tenant. It does not natively support social identity providers as identity sources; adding a social IdP would require building custom federation policies and would still lack the CIAM features such as branded user journeys, subscription-based registration, and integrated social token handling. Thus, the plain Entra ID tenant alone is not a valid mechanism to allow social IdP logins for external users.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.