SC-100 Practice Question: Design security solutions for applications and data
You are designing a solution to protect an Azure App Service web app that authenticates users via Microsoft Entra ID. The app needs to ensure that only users from specific external partner organizations can access it. You do not want to create user objects for each partner user in your tenant. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Entra B2B collaboration and configure the application to accept tokens from partner tenants.
Option B is correct because Microsoft Entra B2B collaboration lets partner users authenticate with their own organizational credentials and receive tokens from their home tenant, which the app can accept without creating user objects in your tenant. This directly satisfies the requirement to allow only specific external partner organizations while avoiding per-user objects in your directory. Option A is insufficient because IP-range restrictions do not identify or validate partner organizations and can be bypassed or misapplied. Option C contradicts the requirement by creating guest user objects for each external user. Option D is wrong because Azure AD B2C is intended for customer-facing identity scenarios with local or social accounts, not for federating access with specific partner Microsoft Entra tenants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Conditional Access policy that restricts access to partners' IP ranges.
Why it's wrong here
Configuring a Conditional Access policy to restrict access to partners' IP ranges treats the network location as the security boundary and does not authenticate the user. Partners often use shared or dynamic egress IPs, so the policy becomes either overly restrictive or easily bypassed, and a compromised device inside the approved range would still be trusted. It also fails to verify which tenant the user belongs to, leaving the application exposed when a partner's IP changes. Proper protection requires evaluating identity and token trust, not just the source IP.
- ✓
Enable Microsoft Entra B2B collaboration and configure the application to accept tokens from partner tenants.
Why this is correct
Enabling Microsoft Entra B2B collaboration is the correct approach because it lets external partners authenticate with their own home tenant credentials while the application is configured to accept tokens from those partner tenants. A B2B guest object is created in your directory for authorization, but no full user object or local credential exists, keeping your tenant clean and reducing password management. This supports true federation, single sign-on, and lifecycle management via the partner's identity provider. The application can use tenant allowlists to trust tokens from specific partner tenants, aligning with zero-trust principles.
- ✗
Create guest user accounts for each external user and assign them to a group.
Why it's wrong here
Creating guest user accounts for each external user and assigning them to a group hard-codes the partner identity lifecycle into your directory, forcing manual creation, redemption, and cleanup. This approach inflates your user object count, introduces stale accounts when partner staff leave, and burdens your team with credential/invitation management. It also duplicates identity data that should live in the partner tenant, complicating governance and audit. In contrast, B2B collaboration abstracts the external user to a shadow object, so group assignment is unnecessary for authentication—though groups can be used for role-based authorization.
- ✗
Use Azure AD B2C custom policies to allow partner authentication.
Why it's wrong here
Azure AD B2C custom policies are designed for customer identity and access management (CIAM), not business-to-business collaboration. While B2C can federate with various identity providers via the Identity Experience Framework, using it to authenticate partner organizations would add a second identity platform, require custom SAML/OIDC federation, and force you to manage yet another tenant. It does not natively trust tokens from partner Microsoft Entra tenants the way B2B collaboration does, and it complicates access for enterprise users who already have corporate identities. For partner authentication, Microsoft Entra B2B is the native, supported solution.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.