MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their Google Workspace credentials without creating external identities. What should you configure?
⚠ Common exam trap
It's easy for candidates to confuse social identity provider configuration (Option B) with enterprise federation, but social IdPs are designed for consumer scenarios and create external identities, whereas SAML/WS-Fed federation preserves the user's existing identity without creating new objects in the directory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure SAML/WS-Fed identity provider federation with Google Workspace
Configuring SAML/WS-Fed identity provider federation with Google Workspace allows users to sign in using their Google Workspace credentials directly, without creating external identities. This federation establishes a trust relationship between Microsoft Entra ID and Google Workspace as an identity provider, enabling seamless authentication for users who already have Google accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Entra Verified ID for Google Workspace users
Why it's wrong here
Microsoft Entra Verified ID is designed for issuing and verifying verifiable credentials (VCs) in a decentralized identity model, not for establishing federation or SSO between directories. It does not integrate with Google Workspace's identity provider, nor does it provide a way for Google Workspace users to authenticate into Entra ID applications. Attempting to use it here would fail to address the requirement for seamless sign-in because it creates a credential-based trust, not a federation trust.
- ✗
Configure Google as a social identity provider in Microsoft Entra External ID
Why it's wrong here
Microsoft Entra External ID supports social identity providers for customer-facing external tenants, but its built-in catalog does not include Google as a social IdP option. Even if it did, configuring such an IdP would only enable identity for consumer-style sign-ups in External ID, not federate your organization's existing Google Workspace users with your Entra ID tenant. This option does not meet the requirement because it targets a different scenario and lacks the direct federation capability needed.
- ✗
Configure Microsoft Entra B2B collaboration with Google Workspace
Why it's wrong here
Entra B2B collaboration lets you invite external users to access your apps, but each Google Workspace user becomes a discrete guest object in your directory rather than the tenant establishing a federation relationship with the Google Workspace domain. This approach requires individual invitations and manages per-user lifecycle, so it does not provide the desired seamless SSO experience for all Google Workspace users. Because B2B collaboration does not extend your identity provider trust to Google, it is not a direct federation solution.
- ✓
Configure SAML/WS-Fed identity provider federation with Google Workspace
Why this is correct
Configuring SAML/WS-Fed identity provider federation is the correct approach because Microsoft Entra ID supports direct federation with Google Workspace by exchanging metadata and establishing a trust relationship. This allows Google Workspace users to authenticate with their existing corporate credentials and gain SSO access to Entra ID-integrated apps and resources. It provides a true federation experience where Google is treated as an external IdP within the Entra tenant.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Federation
Federation is a system that lets you use one set of login credentials (like your work email and password) to access resources across different organizations or services without needing separate accounts for each one.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.