Instiq
Chapter 4 · Workload identities and app integration·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created SC-300 Chapter 4 (Domain 3: workload identity selection/managed identities (system/user-assigned)/service principals/gMSA; enterprise apps (SSO/Application Proxy/app-role assignment/consent policies/admin consent workflow); app registrations (redirect URIs/secret-certificate-federated credentials/delegated-application permissions/app roles); Defender for Cloud Apps (cloud discovery/Cloud app catalog/OAuth app policies/CA app control/access-session policies)).

4.2Integrating enterprise applications

Key points

Understand enterprise-application app/tenant-level settings, SaaS SSO integration, publishing on-prem apps via Microsoft Entra Application Proxy, assigning users/groups/app roles, and managing user and admin consent.

Enterprise applications are SSO-enabled apps registered in Entra (gallery SaaS, custom, on-prem published). The access administrator designs single sign-on, access assignment, and consent governance.

4.2.1SSO integration and Application Proxy

Add SaaS apps from the gallery and configure SSO (SAML/OIDC) for one-time authentication. Control app access via user/group/app-role assignment and apply Conditional Access. Microsoft Entra Application Proxy securely publishes on-prem web apps externally without a VPN, fronting them with Entra authentication + pre-authentication (modernizing internal apps). For "publish a legacy on-prem web app fronted by Entra authentication," use Application Proxy.

4.2.2Governing consent

An app needs consent to access a user’s data (e.g., mail/profile). Allowing unrestricted user consent risks consent phishing to malicious apps, so use consent policies to permit user consent only for "verified publishers and low-risk permissions," routing others to admin consent. Enabling the admin consent workflow lets users request and admins review. The principle: do not let users consent to high-risk permissions.

Exam point

Cues: "publish an on-prem web app without VPN, fronted by Entra auth" = Application Proxy. "SSO to gallery SaaS" = enterprise app + SSO. "control app access by role" = app role/user-group assignment. "curb consent to risky permissions" = consent policies + admin consent workflow.

Warning

Watch the mix-ups: (1) Application Proxy (publishing on-prem web apps) is close to but distinct from Global Secure Access Private Access (ZTNA, broader protocols)—Private Access is the evolution. (2) Enterprise applications (using/SSO of existing apps) differ from app registrations (defining your own developed app, next section). (3) Unrestricted user consent breeds consent phishing.

Diagram of SaaS SSO (SAML/OIDC) with access assignment (user/group/app role), Application Proxy publishing on-prem web apps VPN-less, and consent policies + admin consent workflow curbing consent phishing.
Govern use and consent

4.2.3Section summary

  • Enterprise apps = SSO for SaaS/custom/on-prem-published; access via user/group/app-role assignment + CA
  • Application Proxy = publish on-prem web apps without VPN, fronted by Entra authentication
  • Consent policies + admin consent workflow curb consent phishing (do not let users consent to risky permissions)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to publish a legacy on-prem web app externally—without a VPN—fronted by Entra authentication and pre-authentication. Which is best?

Q2. You want to prevent "consent phishing," where employees consent to mail-read permissions for a malicious app. Which is best?

Q3. You want single sign-on to a gallery SaaS app for one-time authentication. Which is best?

Q4. For a specific enterprise app, you want to allow only certain users/groups and separate functions by app role. Which is best?

Q5. Which correctly distinguishes enterprise applications from app registrations?

Check your understandingPractice questions for Chapter 4: Workload identities and app integration

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.