Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their Google Workspace credentials without creating external identities. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse social identity provider configuration (Option B) with enterprise federation, but social IdPs are designed for consumer scenarios and create external identities, whereas SAML/WS-Fed federation preserves the user's existing identity without creating new objects in the directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure SAML/WS-Fed identity provider federation with Google Workspace

Configuring SAML/WS-Fed identity provider federation with Google Workspace allows users to sign in using their Google Workspace credentials directly, without creating external identities. This federation establishes a trust relationship between Microsoft Entra ID and Google Workspace as an identity provider, enabling seamless authentication for users who already have Google accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Microsoft Entra Verified ID for Google Workspace users

    Why it's wrong here

    Microsoft Entra Verified ID is designed for issuing and verifying verifiable credentials (VCs) in a decentralized identity model, not for establishing federation or SSO between directories. It does not integrate with Google Workspace's identity provider, nor does it provide a way for Google Workspace users to authenticate into Entra ID applications. Attempting to use it here would fail to address the requirement for seamless sign-in because it creates a credential-based trust, not a federation trust.

  • Configure Google as a social identity provider in Microsoft Entra External ID

    Why it's wrong here

    Microsoft Entra External ID supports social identity providers for customer-facing external tenants, but its built-in catalog does not include Google as a social IdP option. Even if it did, configuring such an IdP would only enable identity for consumer-style sign-ups in External ID, not federate your organization's existing Google Workspace users with your Entra ID tenant. This option does not meet the requirement because it targets a different scenario and lacks the direct federation capability needed.

  • Configure Microsoft Entra B2B collaboration with Google Workspace

    Why it's wrong here

    Entra B2B collaboration lets you invite external users to access your apps, but each Google Workspace user becomes a discrete guest object in your directory rather than the tenant establishing a federation relationship with the Google Workspace domain. This approach requires individual invitations and manages per-user lifecycle, so it does not provide the desired seamless SSO experience for all Google Workspace users. Because B2B collaboration does not extend your identity provider trust to Google, it is not a direct federation solution.

  • Configure SAML/WS-Fed identity provider federation with Google Workspace

    Why this is correct

    Configuring SAML/WS-Fed identity provider federation is the correct approach because Microsoft Entra ID supports direct federation with Google Workspace by exchanging metadata and establishing a trust relationship. This allows Google Workspace users to authenticate with their existing corporate credentials and gain SSO access to Entra ID-integrated apps and resources. It provides a true federation experience where Google is treated as an external IdP within the Entra tenant.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.