Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You need to allow external users from a specific partner organization to access a SharePoint Online site using their own Microsoft Entra ID credentials. Which feature should you configure?

⚠ Common exam trap

Many exam-takers confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C, mistakenly thinking B2C is for business partners, when in fact B2C is for consumer-facing identity management, not for granting access to enterprise resources like SharePoint Online.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra B2B collaboration

Microsoft Entra B2B collaboration is the correct feature because it allows you to invite external users from a partner organization to access your SharePoint Online site using their own Microsoft Entra ID (or other identity provider) credentials. B2B collaboration uses cross-tenant trust to authenticate the external user against their home tenant, enabling seamless access without creating local accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Direct Federation

    Why it's wrong here

    Direct federation (also called direct trust federation) is designed for non-Microsoft identity providers, such as SAML 2.0 or WS-Federation IdPs, and creates a trust relationship that routes authentication to that external IdP. However, it only resolves authentication; it does not invite or provision guest user objects in your tenant for a specific partner organization. To use direct federation, your partner users would still need to be represented as B2B guests (or another account type) to receive access to your applications, so it is not a standalone solution for allowing external partner users to access resources.

  • ✗

    Self-service password reset

    Why it's wrong here

    Self-service password reset (SSPR) is an Entra ID feature that lets a user in your own tenant reset their forgotten password using security questions, email validation, or phone verification. It works only for identity objects that already exist in your directory, which means external partner users cannot use it because they have no account in your tenant. Enabling SSPR does not create or invite external identities, nor does it grant any form of inbound access; it is purely a self-service account recovery tool for internal identities.

  • ✗

    Microsoft Entra B2C

    Why it's wrong here

    Microsoft Entra B2C is a customer identity and access management (CIAM) service built for consumer-facing applications, where customers sign up and sign in with social identities or local accounts in a separate, isolated B2C directory. It is not designed for enterprise-to-enterprise collaboration, and it does not integrate with your existing organizational tenant's resource inventory such as Teams, SharePoint, or Microsoft 365 apps. Using B2C for a partner collaboration scenario would require you to build a separate consumer identity platform, which is not the same as granting existing partner users access to your corporate resources.

  • ✓

    Microsoft Entra B2B collaboration

    Why this is correct

    Microsoft Entra B2B collaboration is the correct solution because it enables you to invite external users from a partner organization into your tenant as guest accounts, where they authenticate using their own corporate credentials from their home identity provider. B2B collaboration creates a lightweight guest user object in your directory, then federates authentication back to the partner's Entra tenant or other supported IdP, so you do not need to manage or store their passwords. It allows you to apply conditional access, MFA, and access reviews to those guest accounts, and you can grant granular permissions to specific apps or SharePoint sites, which directly meets the requirement of allowing external users from a specific partner org.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.