MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You need to configure Microsoft Entra ID to allow users to authenticate using their existing social media accounts. Which identity provider type should you add?
⚠ Common exam trap
It's easy for candidates to confuse the generic 'OpenID Connect identity provider' option with the pre-configured social providers, not realizing that Microsoft provides dedicated Google and Facebook identity providers for social authentication, while OpenID Connect is for custom OIDC-compliant IdPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google identity provider
To allow users to authenticate using their existing social media accounts, you need to add a Google identity provider in Microsoft Entra ID. Google is explicitly supported as a social identity provider (IdP) for B2B guest user scenarios, enabling users to sign in with their Gmail accounts. This is configured under External Identities > All identity providers, where you select Google and configure the OAuth 2.0 client ID and secret from the Google API Console.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OpenID Connect identity provider
Why it's wrong here
The OpenID Connect option in the Microsoft Entra ID 'Add identity provider' pane is designed for custom OIDC-based enterprise identity providers such as Okta or Auth0, which you connect using a metadata endpoint, client ID, and client secret. It does not provide a pre-canned social login for Google, and manually wiring Google would require a conformant OIDC discovery document and custom claims mapping, which Google's consumer endpoints do not fully support. Thus it is not the correct method for allowing users to sign in with a Google personal account.
- ✓
Google identity provider
Why this is correct
Google identity provider is a first-class social identity provider in Microsoft Entra External Identities. You add it by navigating to External Identities > All identity providers > Google, supplying a client ID and client secret from the Google API Console, and then enabling it for B2B guest invitations or self-service sign-up user flows. This is the correct option because it directly configures Microsoft Entra ID to accept Google accounts for authentication.
- ✗
Microsoft account identity provider
Why it's wrong here
Microsoft account (MSA) is a built-in consumer identity provider in Microsoft Entra ID and appears as a default option in External Identities, but it is not something you manually 'add' through the Add identity provider blade. When using that blade, you only create new custom providers; built-in providers like Microsoft account and Microsoft Entra ID are already present and cannot be created or duplicated. Therefore, choosing 'Microsoft account' as the provider to add is incorrect because it is not a newly added provider, and it would not bring in Google sign-in.
- ✗
SAML/WS-Fed identity provider
Why it's wrong here
The SAML/WS-Fed identity provider option is for federating with an enterprise identity provider that supports SAML 2.0 or WS-Federation, such as ADFS or a third-party corporate SSO solution, using an explicit federation metadata URL. It is not a social identity provider and cannot be used to let external users authenticate with Google personal accounts. Additionally, SAML/WS-Fed providers are used for B2B direct federation with organizations, not for consumer-facing social sign-in.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Application Proxy
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.