entra1-2 Exercise 1: Classify Five Integrations ================================================ Patterns: 1 = OpenID Connect sign-in, 2 = SAML SSO, 3 = API access (client credentials), 4 = SCIM provisioning. Arrangements: A = your multitenant app (registration in your tenant), B = the client creates a single-tenant registration, C = gallery/SAML enterprise app in the client's tenant. (a) A nightly job that reads user records from a client's tenant Pattern: 3, API access with the application's own credentials (no user is present). Application permissions had to be granted by an administrator. Arrangement: A or B. If the job uses your multitenant app and the client's admin consented, it is A (credential in your tenant's registration). If the client built a registration for you, it is B (credential in the client's tenant). Holds the key: your tenant (A) or the client's tenant (B). Check which. (b) Staff sign in through "Sign in with Microsoft"; the client created the registration Pattern: 1, OpenID Connect sign-in (client ID plus a secret or certificate). Arrangement: B. Holds the key: the client's tenant. The client's administrator renews the secret or certificate; you then update your system. (c) A client sends a SAML metadata file and a certificate Pattern: 2, SAML SSO. Arrangement: C. The signing certificate belongs to the enterprise application in the client's tenant (valid for three years by default unless customised). Holds the key: the client's tenant. Renewal means a new certificate that must also be installed on your side. (d) New starters appear automatically in your system Pattern: 4, SCIM provisioning. Arrangement: not one of A/B/C. The direction is reversed: Entra calls your system. Holds the key: your system issued the credential that the client's admin entered in their tenant. If it expires or changes, the client's provisioning job fails (quarantine), so you generate a new one and the client must update it. (e) Your multitenant product's shared sign-in for all customers Pattern: 1, OpenID Connect (SAML cannot be configured on a multitenant app). Arrangement: A. Holds the key: your tenant's registration. One expiry affects every customer at once, and you can renew it yourself. WHY THIS WORKS AS AN ANSWER --------------------------- Each answer names the pattern from the clue (is a person present? what does the configuration ask for?), then the place where the credential lives, which decides who must act. Notice that provisioning is the odd one out: the credential comes from your side.