AZ-120 · Question #310
You have a Microsoft Entra tenant named contoso.com. You are designing an authentication and authorization solution for SAP Business Technology Platform (BTP) software as a service (SaaS)…
The correct answer is A. From IAS, enable the Use Identity Authentication user store option. Using Microsoft Entra ID to secure access to SAP platforms and applications Use Federated Authentication in SAP Business Technology Platform and SAP SaaS applications through SAP Identity Authentication Service When using federation, you can choose to define the trust…
Question
You have a Microsoft Entra tenant named contoso.com. You are designing an authentication and authorization solution for SAP Business Technology Platform (BTP) software as a service (SaaS) applications. SAP BTP subaccounts trust the SAP Cloud Identity Services - Identity Authentication Service (IAS) tenant of your company. You plan to establish a trust between the IAS tenant and contoso.com. You need to ensure that authorization decisions in the SAP BTP applications are based exclusively on claims issued by contoso.com. What should you do?
Options
- AFrom IAS, enable the Use Identity Authentication user store option.
- BFrom SAP BTP, enable the use of default attributes.
- CFrom SAP BTP, disable the use of default attributes.
- DFrom IAS, disable the Use Identity Authentication user store option.
How the community answered
(43 responses)- A44% (19)
- B14% (6)
- C33% (14)
- D9% (4)
Explanation
Using Microsoft Entra ID to secure access to SAP platforms and applications Use Federated Authentication in SAP Business Technology Platform and SAP SaaS applications through SAP Identity Authentication Service When using federation, you can choose to define the trust configuration at the BTP Subaccount level. In that case, you must repeat the configuration for each other Subaccount you're using. By using IAS as an intermediate trust configuration, you benefit from centralized configuration across multiple Subaccounts and you can use IAS features such as risk-based authentication and centralized enrichment of assertion attributes. * To safeguard the user experience, these advanced security features should only be enforced at a single location. This could either be IAS or when keeping Microsoft Entra ID as the single authoritative user store (as is the premise of this paper), this would centrally be handled by Microsoft Entra Conditional Access Management. *
Topics
Community Discussion
No community discussion yet for this question.