For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAzure Solutions Architect Expert (AZ-305)Azure Solutions Architect Expert AZ-305 Practice Exam 4Question 10
    Hard1 markMultiple Choice
    Domain 1.2: Authentication and AuthorizationIdentityB2BMFA

    AZ-305 · Question 10 · Domain 1.2: Authentication and Authorization

    Fabrikam Inc. uses Microsoft Entra ID (Azure AD). They collaborate with external partners who need access to Fabrikam's internal SharePoint Online sites and custom Azure web apps.

    Security policies dictate that external partners must use Multi-Factor Authentication (MFA). However, Fabrikam does not want to manage the MFA registration lifecycle for these external users, preferring that the partners use their own organization's MFA claims if they have already authenticated strongly.

    Which feature should you configure?

    Answer options:

    A.

    Microsoft Entra B2C User Flows

    B.

    Cross-tenant access settings (Inbound trust)

    C.

    Microsoft Entra Identity Protection

    D.

    Conditional Access session controls

    How to approach this question

    Look for the requirement to trust external MFA. This is a B2B scenario requiring cross-tenant trust.

    Full Answer

    B.Cross-tenant access settings (Inbound trust)✓ Correct
    Cross-tenant access settings (Inbound trust)
    In B2B collaboration scenarios, Cross-tenant access settings allow your organization to trust the Multi-Factor Authentication (MFA) and device compliance claims from an external partner's Microsoft Entra tenant. This provides a seamless experience for the partner while meeting your security requirements without administrative overhead.

    Common mistakes

    Assuming Conditional Access alone can do this. While CA enforces MFA, Cross-tenant access settings are required to *trust* the inbound claim from another tenant.
    Question 09All questionsQuestion 11

    Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 4

    55 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ02CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ03CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...HardQ04CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ05CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...Hard
    View all 55 questions →