Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your organization uses Microsoft 365 and has enabled Microsoft Entra ID P2 licenses. You need to configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0. What should you do first in the Microsoft Entra admin center?

⚠ Common exam trap

It's easy for candidates to confuse 'App registrations' (for custom app development) with 'Enterprise applications' (for SaaS app provisioning), leading them to choose an option that registers an app instead of adding a gallery application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the application from the gallery, then configure provisioning.

To configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0, you must first add the application from the Microsoft Entra gallery. This action creates an enterprise application object in your tenant, which is required to access the provisioning configuration blade. Only after adding the gallery application can you configure the provisioning settings, including the SCIM endpoint URL and token, to enable automated user lifecycle management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the application from the gallery, then configure provisioning.

    Why this is correct

    This is the only correct sequence for a gallery application that supports SCIM provisioning. You must first add the application from the Microsoft Entra ID gallery, which creates an enterprise application object with the vendor's prebuilt provisioning template. After it is added, you open the app's Provisioning blade, set the provisioning mode to Automatic, enter the SCIM endpoint URL and an authentication token supplied by the SaaS vendor, and then save and test the connection. This is the standard, supported workflow; provisioning settings and attribute mappings are made available only after the gallery app has been installed.

  • ✗

    Configure provisioning in 'App registrations'.

    Why it's wrong here

    The App registrations area in Microsoft Entra ID is reserved for custom applications you develop or own. It manages OAuth 2.0 client credentials, redirect URIs, and API permissions, but it does not contain any provisioning settings or a Provisioning blade. SCIM provisioning for a gallery application is a tenant-level configuration that pertains to the service principal, and it is exposed only under Enterprise applications. Therefore, attempting to configure provisioning from App registrations is both impossible in the UI and conceptually wrong.

  • ✗

    Navigate to 'Enterprise applications' and create a new application.

    Why it's wrong here

    Manually creating a new application from Enterprise applications does not give you the application-specific provisioning connector. When you start with the gallery 'Add an application' flow, Microsoft Entra ID automatically provisions the correct SCIM template, attribute schema, and provisioning agent configuration for that SaaS product. By choosing to create a new application instead, you would end up with a generic enterprise app that lacks the vendor's SCIM endpoint and mappings, making automatic provisioning unavailable or requiring extensive custom configuration.

  • ✗

    Use the 'App registrations' blade to register the app.

    Why it's wrong here

    App Registrations only creates an application registration object, which represents the third-party app's identity. It does not create the service principal/enterprise application object needed for SCIM provisioning. The provisioning engine in Microsoft Entra ID operates on enterprise applications, so if you register a brand-new app, there is no built-in SCIM connector and the Provisioning blade will not be available. For a gallery application, the correct path is to add it from the gallery so that both the service principal and the provisioning template are created for you.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.