Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

You are designing a secure access solution for an Azure App Service web application. The application uses Microsoft Entra ID for authentication. You need to ensure that only users from specific partner organizations can access the app. Which configuration should you use?

⚠ Common exam trap

Many candidates confuse 'external identity providers' with 'blocking external users' or 'MFA', not realizing that the correct approach is to explicitly allow specific partner tenants as identity providers rather than applying a blanket security policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the app to accept tokens from the partner tenants as external identity providers

Azure App Service can be configured to accept tokens from multiple Microsoft Entra ID tenants as external identity providers. This allows users from specific partner organizations to authenticate using their own Entra ID tenant, while the app validates the tokens and grants access only to those partner tenants you explicitly trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a custom domain for the app

    Why it's wrong here

    A custom domain only rebrands the app's URL and TLS certificate; it does not affect how Microsoft Entra ID issues or validates tokens. Partner access is governed by the app's identity provider settings and tenant-level trust, not by the domain name users type in the browser. Thus, changing the domain neither grants nor restricts access for partner tenants.

  • ✓

    Configure the app to accept tokens from the partner tenants as external identity providers

    Why this is correct

    Configuring the app to accept tokens from partner tenants as external identity providers is the core of Microsoft Entra B2B collaboration. You register the app as a multi-tenant application or add partner tenants as trusted identity providers; users authenticate in their home tenant and receive tokens that your app validates. This allows you to grant specific partner users access while keeping your own tenant as the authority for the application.

  • ✗

    Block all external users

    Why it's wrong here

    Blocking all external users is a blanket denial that prevents any user from outside your tenant from signing in, including legitimate partner users. The requirement is to securely allow partner tenants, not to lock them out, so this approach fails the access requirement. You need a more granular mechanism that selectively trusts specific external identity providers.

  • ✗

    Require multi-factor authentication for all users

    Why it's wrong here

    Requiring MFA for all users adds a second authentication factor but does nothing to control which external tenants can access the app. Partner users would still be able to sign in if they satisfy the MFA policy, so it does not restrict access to only approved partners. MFA is a security control layered on top of identity-based access, not a substitute for configuring trust with partner tenants.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.