What to do first for certificate-based authentication in Entra ID?

Plan, implement, and manage Microsoft Entra user authentication
Answer Correct answer: B — Add CA1 as a Certificate Authority to the Microsoft Entra ID tenant so certificates it issues are trusted for sign-in.

Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a certification authority (CA) named CA1. You have an Azure AD tenant. You need to implement certificate-based authentication in Azure AD. The solution must ensure that users can sign in by using certificates issued by CA1. What should you do first?

  1. Deploy an Azure key vault.
  2. Add CA1 as a Certificate Authority to the Microsoft Entra ID tenant. Correct Answer
  3. Enable auto-enrollment for CA1.
  4. Deploy Windows Hello for Business.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prerequisite order for Entra ID certificate-based authentication (CBA), and the common trap is confusing CA trust onboarding with certificate issuance or storage tasks such as auto-enrollment or Azure Key Vault.

Implementing certificate-based authentication in Microsoft Entra ID requires the tenant to trust the issuing certification authority before users can sign in with certificates. The first action is to add CA1 as a certificate authority in Entra ID, which is option B and the confirmed answer.

Learners often choose Azure Key Vault (A) or auto-enrollment (C), assuming certificates or user enrollment must be prepared first, but Entra ID cannot validate CA1-issued certificates until CA1 is registered as a trusted certificate authority in the tenant.

Community Discussion (3 comments)

Panama469 👍 1 Selected: B
Yes that's the first step in Azure Portal... Entra ID... Security... Certificate Authorities.
Sozo 👍 2 Selected: B
This is the first step to configure and use certificate-based authentication in Azure AD. You need to upload the root certificate and the certificate revocation list (CRL) of CA1 to Azure AD and specify the CRL distribution point. This allows Azure AD to validate the certificates issued by CA1 and check their revocation status.
cpaljchc4 👍 4 Selected: B
I think answer is correct Ref: https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-authentication Prerequisites Make sure that the following prerequisites are in place: Configure at least one certification authority (CA) and any intermediate CAs in Microsoft Entra ID. The user must have access to a user certificate (issued from a trusted Public Key Infrastructure configured on the tenant) intended for client authentication to authenticate against Microsoft Entra ID. Each CA should have a certificate revocation list (CRL) that can be referenced from internet-facing URLs. If the trusted CA doesn't have a CRL configured, Microsoft Entra ID won't perform any CRL checking, revocation of user certificates won't work, and authentication won't be blocked.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Certificate-based authentication in Microsoft Entra ID works only when the tenant trusts the certification authority that issued the user certificate. Before any authentication policy, sign-in method, or user certificate mapping can function, you must add CA1 as a certificate authority in Entra ID by uploading its root certificate and certificate revocation list (CRL) and specifying the CRL distribution point. Option B is exactly that first step: adding CA1 as a Certificate Authority to the Microsoft Entra ID tenant. Once CA1 is trusted, Entra ID can validate certificates it issues and check their revocation status during sign-in. The question asks what to do first, and CA trust onboarding is the prerequisite for every later CBA configuration task.

Why the Other Options Are Wrong

Option A, deploying an Azure Key Vault, is useful for storing and managing secrets or certificates used by applications, but it does not make Entra ID trust CA1 for user authentication. Option C, enabling auto-enrollment for CA1, is a certificate-issuance and lifecycle activity on the on-premises or hybrid side, and it does not register CA1 as a trusted issuer in the Entra ID tenant. Option D, deploying Windows Hello for Business, is a separate passwordless authentication method based on key pairs, not a step for accepting CA1-issued certificates in Entra ID. None of these options establishes the required certificate authority trust relationship in Entra ID.

Community Comment Notes

Community voters unanimously selected B, and the reasoning aligns with the official prerequisite. As cpaljchc4 noted, Microsoft documentation requires you to "Configure at least one certification authority (CA) and any intermediate CAs in Microsoft Entra ID." Sozo explained that you need to upload the root certificate and the certificate revocation list of CA1 to Entra ID and specify the CRL distribution point so Entra ID can validate CA1-issued certificates and check revocation status. Panama469 also pointed to the Azure portal path: Entra ID, Security, Certificate Authorities, confirming that adding the CA is the first practical step.

Official Reference

Exam Strategy

When an SC-300 question asks for the first step in certificate-based authentication, look for the action that establishes trust between Entra ID and the issuing CA, not the step that issues certificates to users. The tenant must trust the CA before any authentication policy or user certificate mapping can work.

Frequently Asked Questions

Why is Azure Key Vault not the first step for Entra ID certificate-based authentication?

Azure Key Vault stores and manages secrets or certificates, but it does not make Entra ID trust CA1 as an issuer. Entra ID needs CA1 registered as a certificate authority before it can validate user certificates.

Where do you add CA1 as a trusted certificate authority in Entra ID?

In the Azure portal, go to Microsoft Entra ID > Security > Certificate Authorities, then upload CA1's root certificate and CRL and configure the CRL distribution point.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide