AZ-500 Manage identity and access Practice Question
A company wants to allow external business partners to access specific SharePoint Online sites using their own corporate credentials. They do not want to manage partner accounts in their own Microsoft Entra ID tenant. Which Microsoft Entra ID feature should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Azure AD B2C (customer-facing) with Microsoft Entra ID External Identities B2B (business-to-business), as both involve 'external' users but serve fundamentally different scenarios and identity providers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID External Identities
Microsoft Entra ID External Identities (specifically B2B collaboration) allows you to invite external business partners to access your SharePoint Online sites using their own corporate credentials (their home Microsoft Entra ID or identity provider). This eliminates the need to manage partner accounts in your tenant, as identities remain in their home directory and are authenticated via federation or SAML/WS-Fed protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD B2C
Why it's wrong here
Azure AD B2C is an identity management solution designed for consumer-facing applications, where customers use local accounts (email/password) or social identities like Google or Facebook. It is not intended for enterprise-to-enterprise collaboration; B2C tenants are separate directories from your organization's Microsoft Entra ID, so external business partners cannot be invited as guests into SharePoint Online using their existing work accounts. B2C lacks the B2B invitation and redemption flow that SharePoint external sharing depends on, and forcing partners to register in a B2C tenant would create a poor, non-federated experience.
- ✓
Microsoft Entra ID External Identities
Why this is correct
Microsoft Entra ID External Identities (B2B collaboration) is the correct mechanism to allow external business partners access to specific SharePoint resources. It lets you invite partners who authenticate with their own organization's identity (Microsoft Entra ID, SAML/WS-Fed IdP, or social identity), and they are represented as guest users in your directory. These guest accounts can be added to SharePoint sites, document libraries, or individual items through SharePoint's external sharing capabilities, with optional Conditional Access policies applied. This approach maintains your partner's home identity without requiring duplicate credentials in your tenant.
- ✗
Conditional Access
Why it's wrong here
Conditional Access is a policy evaluation engine that analyzes signals such as user identity, device compliance, location, and risk level to allow or block access to applications including SharePoint Online. It does not provision or invite external users; it only enforces access control after an account already exists and attempts to authenticate. While you can apply Conditional Access policies to guest users (e.g., require MFA or restrict IP ranges), it cannot create the guest accounts or generate sharing invitations needed to initially grant business partners access.
- ✗
Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) is a service for managing just-in-time, time-bound assignments to Microsoft Entra ID roles, Azure resource roles, and privileged access groups. It is about controlling elevated roles for users who already exist in your tenant, not about inviting external business partners into SharePoint. Although PIM can technically grant a guest user a privileged role, it does not provide the SharePoint sharing link or external identity invitation flow required to establish a partner's access, and using it for that purpose would be inappropriate and overly complex.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.