nerdexam
Microsoft

SC-300 · Question #318

You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named App1. A contractor uses the credentials of [email protected]. You need to ensure that you can…

The correct answer is C. Create a guest user account in contoso.com. Explanation Creating a guest user account (Option C) allows you to invite the contractor's existing [email protected] identity into your Entra tenant as a B2B guest, enabling them to authenticate with their own Microsoft/Outlook credentials while still being granted access to…

Submitted by femi9· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named App1. A contractor uses the credentials of [email protected]. You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as [email protected]. What should you do?

Options

  • AAdd a custom domain name to contoso.com.
  • BConfigure the External collaboration settings.
  • CCreate a guest user account in contoso.com.
  • DAdd a WS-Fed identity provider.

How the community answered

(19 responses)
  • A
    11% (2)
  • C
    84% (16)
  • D
    5% (1)

Explanation

Explanation

Creating a guest user account (Option C) allows you to invite the contractor's existing [email protected] identity into your Entra tenant as a B2B guest, enabling them to authenticate with their own Microsoft/Outlook credentials while still being granted access to App1 - no new credentials are required.

Why the distractors are wrong:

  • Option A (custom domain) is used to add your own organization's domain to Entra ID; it doesn't help external users authenticate with a personal Outlook account.
  • Option B (External collaboration settings) controls policies around guest invitations (e.g., who can invite guests), but doesn't itself grant access - you still need to create the guest account.
  • Option D (WS-Fed identity provider) is used to federate with external organizational identity providers, not for individual consumer/personal Microsoft accounts like outlook.com.

Memory Tip: Think of the "Guest = Keep Your Own Identity" rule - whenever an external user needs to access your tenant without changing their credentials, the answer is almost always a B2B Guest User account. If they already have a Microsoft account (like Outlook.com), no extra federation setup is needed.

Topics

#Microsoft Entra B2B#Guest users#External collaboration#Application access

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice