A global organization needs to configure Microsoft Entra External ID for their AI-powered customer portal. External customers must authenticate using their Google or Facebook identities. The security team requires that all external user sign-ins are subject to risk evaluation. How should this be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Entra External ID supports configuring social identity providers such as Google and Facebook, and Conditional Access policies with Entra ID Protection risk evaluation can be applied to external user sign-ins in External ID tenants, providing risk-based access control for customers. B is incorrect because while custom authentication extensions are supported, the built-in Entra ID Protection and Conditional Access integration is the correct approach without requiring custom development.
Full explanation below image
Full Explanation
A is correct because Microsoft Entra External ID supports configuring social identity providers such as Google and Facebook, and Conditional Access policies with Entra ID Protection risk evaluation can be applied to external user sign-ins in External ID tenants, providing risk-based access control for customers. B is incorrect because while custom authentication extensions are supported, the built-in Entra ID Protection and Conditional Access integration is the correct approach without requiring custom development. C is incorrect because Entra ID Protection does support risk evaluation for external identities in Entra External ID; Azure AD B2C is a separate product. D is incorrect because cross-tenant access settings manage collaboration between Entra ID organizations, not social identity provider federation for customer portals.