AZ-500 Secure identity and access Practice Question
You are designing a secure access solution for an Azure App Service web application. The application uses Microsoft Entra ID for authentication. You need to ensure that only users from specific partner organizations can access the app. Which configuration should you use?
⚠ Common exam trap
Many candidates confuse 'external identity providers' with 'blocking external users' or 'MFA', not realizing that the correct approach is to explicitly allow specific partner tenants as identity providers rather than applying a blanket security policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the app to accept tokens from the partner tenants as external identity providers
Azure App Service can be configured to accept tokens from multiple Microsoft Entra ID tenants as external identity providers. This allows users from specific partner organizations to authenticate using their own Entra ID tenant, while the app validates the tokens and grants access only to those partner tenants you explicitly trust.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a custom domain for the app
Why it's wrong here
A custom domain only rebrands the app's URL and TLS certificate; it does not affect how Microsoft Entra ID issues or validates tokens. Partner access is governed by the app's identity provider settings and tenant-level trust, not by the domain name users type in the browser. Thus, changing the domain neither grants nor restricts access for partner tenants.
- ✓
Configure the app to accept tokens from the partner tenants as external identity providers
Why this is correct
Configuring the app to accept tokens from partner tenants as external identity providers is the core of Microsoft Entra B2B collaboration. You register the app as a multi-tenant application or add partner tenants as trusted identity providers; users authenticate in their home tenant and receive tokens that your app validates. This allows you to grant specific partner users access while keeping your own tenant as the authority for the application.
- ✗
Block all external users
Why it's wrong here
Blocking all external users is a blanket denial that prevents any user from outside your tenant from signing in, including legitimate partner users. The requirement is to securely allow partner tenants, not to lock them out, so this approach fails the access requirement. You need a more granular mechanism that selectively trusts specific external identity providers.
- ✗
Require multi-factor authentication for all users
Why it's wrong here
Requiring MFA for all users adds a second authentication factor but does nothing to control which external tenants can access the app. Partner users would still be able to sign in if they satisfy the MFA policy, so it does not restrict access to only approved partners. MFA is a security control layered on top of identity-based access, not a substitute for configuring trust with partner tenants.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.