AZ-500 Secure identity and access Practice Question
You need to ensure that external users who are invited to your Microsoft Entra ID tenant via B2B collaboration can only access a specific SaaS application. What should you configure?
⚠ Common exam trap
Candidates often confuse broad Conditional Access policies (targeting 'All cloud apps') with application-specific policies, mistakenly thinking that including guest users in a blanket policy achieves the same restriction, when in fact it would block or require MFA for guest users across all apps, not just the target SaaS application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy targeting the SaaS application and apply it to 'Guest or external users'.
A Conditional Access policy can be scoped to a specific SaaS application and applied to 'Guest or external users'. This ensures that only invited B2B collaboration users are subject to the access control for that application, while all other users and apps remain unaffected. The policy enforces authentication and authorization rules exclusively for the targeted SaaS app and guest identity type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure SharePoint Online external sharing settings.
Why it's wrong here
SharePoint Online external sharing settings configure whether users can share sites, files, and folders with authenticated or anonymous external users. These settings only apply to SharePoint and OneDrive for Business resources, and they do not affect how the separate SaaS application authenticates or authorizes external identities. Therefore, changing them here will not control guest or external user access to the third-party SaaS app.
- ✗
Create a Conditional Access policy targeting 'All cloud apps' and include guest users.
Why it's wrong here
A Conditional Access policy that targets 'All cloud apps' evaluates the same access requirements for every application registered in the tenant, including Microsoft 365 services and the SaaS app. Because the policy includes guest users but is not scoped to the specific SaaS application, it cannot guarantee that the external-access restrictions are applied only to that app. This approach risks over-restricting or inadvertently bypassing the intended control, so the application must be selected individually under 'Target resources'.
- ✓
Create a Conditional Access policy targeting the SaaS application and apply it to 'Guest or external users'.
Why this is correct
Using a Conditional Access policy that explicitly targets the SaaS application and applies it to 'Guest or external users' scopes both the identity and the resource. Under Target resources you select the specific app, and under Users a particular external user type such as 'B2B collaboration guest' is chosen, allowing the policy to enforce conditions like MFA or session controls. This is the correct pattern because it enforces access decisions at the app boundary for exactly the intended account type without affecting internal users or other applications.
- ✗
Use Microsoft Entra application proxy.
Why it's wrong here
Microsoft Entra application proxy is a reverse proxy used to publish and provide secure remote access to on-premises legacy web applications that do not natively support modern authentication. It cannot change the authorization behavior of an external SaaS application, which lives outside your network and is already accessible through its own identity provider. Since the SaaS app is cloud-hosted, application proxy is irrelevant here and would not enforce guest-user-specific conditional access or restrict external sign-ins to that app.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.