AKS Azure AD authentication can only be enabled at cluster creation, so you must recreate the cluster to enable Microsoft Entra account access
You have a Microsoft Entra tenant named Contoso.com and an Azure Kubernetes Service (AKS) cluster AKS1. You discover that AKS1 cannot be accessed by using accounts from Contoso.com. You need to ensure AKS1 can be accessed by using accounts from Contoso.com. The solution must minimize administrative effort. What should you do first?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The constraint is creation-time only: you cannot retrofit legacy Azure AD integration onto an already-running AKS cluster. 'Recreate' is the minimal viable path when access via Entra accounts is required and was not set at creation.
AKS Azure AD (Microsoft Entra ID) integration is bound to the cluster at creation time. If an existing cluster was not created with Entra integration, accounts from the Entra tenant cannot authenticate to it; the only way to enable that access is to recreate the cluster with Entra ID authentication configured during creation.
Candidates pick 'configure User settings' or 'add a P2 license', but those do not enable AKS to trust Entra accounts; the cluster itself must be created with Entra ID integration, which requires recreation.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure AD / Microsoft Entra ID integration for AKS is configured when the cluster is created and, on the legacy integration path, cannot be enabled afterward. Because AKS1 was created without it and now must accept Contoso.com accounts, the first step is to recreate AKS1 with Microsoft Entra ID authentication enabled at creation. (Option A)Why the Other Options Are Wrong
- Option B (Upgrade Kubernetes version) does not add Entra ID authentication capability.
- Option C (Add Entra ID P2 license) is unrelated to AKS cluster authentication binding.
- Option D (Configure User settings) changes directory-level user consent, not the cluster's Entra trust.