Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization plans to use Microsoft Entra ID as the identity provider for a third-party SaaS application that supports SAML 2.0. You need to configure single sign-on (SSO) for the application. What should you create in Microsoft Entra ID?

⚠ Common exam trap

A common mix-up: candidates confuse app registrations (used for OIDC/OAuth apps) with enterprise applications (used for SAML-based SSO), leading them to choose Option D, even though SAML 2.0 requires the enterprise application gallery or custom enterprise app configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An enterprise application with SAML-based sign-on

To configure SSO for a third-party SaaS application that supports SAML 2.0, you must create an enterprise application in Microsoft Entra ID and configure it with SAML-based sign-on. Enterprise applications are designed for integrating third-party applications, and SAML-based sign-on allows Entra ID to act as the identity provider, exchanging SAML assertions for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An enterprise application with SAML-based sign-on

    Why this is correct

    In Microsoft Entra ID, an enterprise application is a service principal created from a gallery or non-gallery app template, which supports SAML 2.0 federation for SSO. For an on-premises app like the IDE, you register an enterprise application, configure SAML-based sign-on, and assign users/groups. The SAML assertions are exchanged to authenticate users, and this is the designated method for federating an on-premises application with Microsoft Entra ID.

  • ✗

    An Application Proxy connector group

    Why it's wrong here

    Microsoft Entra Application Proxy is designed to provide secure remote access to on-premises web applications by relaying traffic through a connector agent. It does not implement SAML-based federation; instead, it uses pre-authentication with Entra ID and then passes the request to the on-premises app. Since the requirement is SAML SSO for an IDE, a connector group is irrelevant—it would only be used if you were publishing the app for remote access, not for identity federation.

  • ✗

    A service principal for Microsoft Graph

    Why it's wrong here

    A service principal for Microsoft Graph represents the Microsoft Graph application itself, which is used to grant permissions for API access to call Microsoft Graph endpoints. It is not a mechanism for configuring SAML SSO for a third-party application. Creating or using the Microsoft Graph service principal would only allow programmatic access to directory data and APIs, not authenticate users to your IDE via SAML.

  • ✗

    An app registration with OpenID Connect

    Why it's wrong here

    An app registration in Microsoft Entra ID is used for applications that implement modern authentication protocols like OpenID Connect and OAuth 2.0. OpenID Connect is an identity layer built on OAuth 2.0 that uses JSON Web Tokens, not SAML assertions. Because the IDE requires SAML-based sign-on, an OpenID Connect app registration would not meet that requirement, as the protocol and token format are incompatible.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.