SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company, Wingtip Toys, uses Microsoft Entra ID with a Premium P1 license. You have a third-party SaaS application that supports Security Assertion Markup Language (SAML) 2.0. You need to enable single sign-on (SSO) for users to access this application. The app requires attributes like department and employee ID in the SAML token. You also need to ensure that only users from a specific security group can access the app. What should you do?
⚠ Common exam trap
Don't confuse SAML SSO with OpenID Connect, password-based SSO, or Application Proxy. Also remember that custom SAML claims mapping requires Microsoft Entra ID Premium P1 or P2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the app from the gallery as a SAML application, configure claims mapping to include department and employee ID, and assign the app to the security group.
With Microsoft Entra ID Premium P1, you can add the SaaS application from the gallery as a SAML application, configure custom claims to include department and employee ID in the SAML token, and assign the application to the security group. OpenID Connect is not SAML SSO. Password-based SSO cannot provide SAML attributes. Application Proxy is used for on-premises applications, not SaaS apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Register the app using OpenID Connect and assign users to the app.
Why it's wrong here
OpenID Connect (OIDC) is a modern authentication protocol built on OAuth 2.0, primarily used for web and mobile applications to verify user identity and obtain basic profile information. Since the third-party SaaS application explicitly supports SAML, attempting to register it using OIDC would result in a protocol mismatch. This incompatibility would prevent successful single sign-on, as the application would not understand the OIDC tokens issued by Microsoft Entra ID.
- ✗
Add the app from the gallery using password-based SSO and configure group assignment.
Why it's wrong here
Password-based Single Sign-On (SSO), often referred to as password vaulting, functions by securely storing and replaying user credentials directly into the application's login form. While it provides a basic SSO experience, this method does not support the transmission of custom user attributes or claims, such as department and employee ID. Therefore, it cannot fulfill the requirement to send specific SAML attributes to the third-party SaaS application.
- ✗
Use Microsoft Entra Application Proxy to publish the app and configure pre-authentication.
Why it's wrong here
Microsoft Entra Application Proxy is a service designed to provide secure remote access to *on-premises* web applications, making them accessible to external users without requiring a VPN. Its purpose is to publish internal resources, acting as a reverse proxy for applications hosted within a private network. Since the scenario involves a third-party SaaS application that is already externally hosted, using Application Proxy is entirely inappropriate and irrelevant for its integration.
- ✓
Add the app from the gallery as a SAML application, configure claims mapping to include department and employee ID, and assign the app to the security group.
Why this is correct
Adding the application from the Microsoft Entra gallery as a SAML application is the correct approach, as it aligns with the third-party app's supported authentication protocol. Configuring claims mapping allows for the precise inclusion of required attributes like department and employee ID within the SAML assertion sent to the service provider. Finally, assigning the app to a security group ensures efficient and scalable management of user access, meeting all specified requirements for secure and attribute-rich single sign-on.
Go deeper
Related to this question
Learn chapter
Azure NSG and Application Security Groups
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
Key term
Single sign-on
Single sign-on (SSO) is an authentication method that allows a user to log in once and gain access to multiple applications or systems without re-entering credentials.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.