Instiq
Chapter 4 · Workload identities and app integration·v1.0.0·Updated 6/28/2026·~14 min

What's changed: Created SC-300 Chapter 4 (Domain 3: workload identity selection/managed identities (system/user-assigned)/service principals/gMSA; enterprise apps (SSO/Application Proxy/app-role assignment/consent policies/admin consent workflow); app registrations (redirect URIs/secret-certificate-federated credentials/delegated-application permissions/app roles); Defender for Cloud Apps (cloud discovery/Cloud app catalog/OAuth app policies/CA app control/access-session policies)).

4.2Integrating enterprise applications

Key points

Understand enterprise-application app/tenant-level settings, SaaS SSO integration, publishing on-prem apps via Microsoft Entra Application Proxy, assigning users/groups/app roles, and managing user and admin consent.

Enterprise applications are SSO-enabled apps registered in Entra (gallery SaaS, custom, on-prem published). The access administrator designs single sign-on, access assignment, and consent governance.

4.2.1SSO integration and Application Proxy

Add SaaS apps from the gallery and configure SSO (SAML/OIDC) for one-time authentication. Control app access via user/group/app-role assignment and apply Conditional Access. Microsoft Entra Application Proxy securely publishes on-prem web apps externally without a VPN, fronting them with Entra authentication + pre-authentication (modernizing internal apps). For "publish a legacy on-prem web app fronted by Entra authentication," use Application Proxy.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.